Alert Verification Device Selective Packet Parsing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing alert verification techniques face high processing loads due to parsing all communication packets, leading to delayed determination of attack success or failure, especially in high-traffic environments.

Innovation Solution

An alert verification device that receives alerts from an attack detection apparatus, generates acquisition conditions for specific communication data, and acquires only the necessary data from a packet capture device to determine attack success or failure, reducing parsing processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If all communication packets are parsed to determine attack success or failure, then the accuracy of attack verification is improved, but the processing load increases and determination is delayed

Engineering Contradiction:
Improveattack verification accuracyVSAvoidprocessing speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent extracts and analyzes only the essential features from communication packets that are necessary for determining attack success or failure. Instead of parsing all packets completely, the system selectively extracts relevant information such as specific response features, status codes, or pattern matches that indicate attack outcomes, thereby reducing processing load while maintaining verification accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the attack verification process into distinct stages: initial attack detection, selective feature extraction, and success/failure determination. By dividing the communication packet analysis into these segments, the system processes only the necessary portions of packets at each stage, avoiding complete parsing of all packets and thus improving processing speed without sacrificing verification accuracy.

Inventive Principle:
Principle #1Segmentation

2Reliability

If communication packets are parsed to verify attack success, then verification capability is improved, but the processing load becomes excessive in high-traffic environments

Engineering Contradiction:
Improveattack determination capabilityVSAvoidprocessing load
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies partial action by performing only the minimum necessary parsing and analysis of communication packets to determine attack success or failure. Instead of completely parsing all packets, the system performs selective partial parsing focused on extracting specific features relevant to attack verification, thereby reducing processing load while maintaining reliable determination capability.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent changes the parameter of analysis from complete packet parsing to selective feature extraction. By transforming the verification approach to focus on specific parameters such as response status codes, payload patterns, or timing characteristics, the system reduces processing load while maintaining the reliability needed for accurate attack determination.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240250964A1Alert verification device, alert verification method, and alert verification program
Publication Date: 2024.07.25 NT T INC
  • US20240250964A1 patent drawing
  • US20240250964A1 patent drawing
  • US20240250964A1 patent drawing

AI summary

A reception unit (131) receives an alert transmitted from an attack detection apparatus (3) that detects an attack on a monitoring target device. A generation unit (132) generates an acquisition condition of communication data to be acquired on the basis of the alert received by the reception unit (131). An acquisition unit (133) acquires the communication data matching the acquisition condition generated by the generation unit (132) from a packet capture device (4) holding data transmitted and received by the monitoring target device. A success/failure determination unit (125) determines success or failure of an attack on the basis of the communication data acquired by the acquisition unit (133).