Automated Analysis Rule Adjustment for Network Malicious Communication Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional techniques for detecting malicious communication using analysis rules face challenges in verifying the validity of these rules and adjusting thresholds, leading to suboptimal settings and requiring manual, time-consuming adjustments in actual network environments.

Innovation Solution

An analysis rule adjustment system that automatically verifies the validity of analysis rules by collecting and analyzing both benign and malignant logs, adjusting parameter thresholds to achieve predetermined detection accuracy, and updating the rules based on optimized tuning values.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual verification and adjustment of analysis rules is performed in actual network environment, then detection accuracy can be improved, but time consumption and operational complexity increase significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary verification of analysis rules using simulated malicious logs before deploying them to the actual network environment. This preliminary action allows detection accuracy to be improved without the time penalty of manual verification in production, as the rules are pre-tested and optimized using automated simulation techniques.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service verification where the analysis rules automatically test and validate themselves against simulated attack patterns. Instead of requiring manual operator intervention for verification, the rules autonomously evaluate their own effectiveness through automated simulation, reducing both time consumption and operational complexity while maintaining detection accuracy.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If manual adjustment of thresholds is performed by operators, then detection precision can be optimized, but operational complexity and processing time increase

Engineering Contradiction:
Improvedetection precisionVSAvoidoperational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system implements self-service threshold optimization where analysis rules automatically adjust their own thresholds based on performance feedback from simulated attacks. Operators no longer need to manually tune thresholds, eliminating operational complexity while maintaining detection precision through automated adaptive optimization.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system establishes a feedback loop where detection results from simulated malicious logs are fed back to automatically adjust thresholds. This feedback mechanism enables continuous optimization of detection precision without manual intervention, reducing operational complexity while maintaining high detection accuracy through automated iterative improvement.

Inventive Principle:
Principle #23Feedback

3Reliability

If analysis rules are verified in actual network environment, then validity can be confirmed, but false detection rate increases due to suboptimal parameter settings

Engineering Contradiction:
Improvevalidity confirmationVSAvoidfalse detection rate
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary validation of analysis rules using simulated malicious logs before actual deployment. This preliminary action confirms rule validity in a controlled environment with optimal parameter settings, preventing suboptimal rules from being deployed to production where they would generate false detections, thus reducing false detection rate while maintaining reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The analysis rules automatically verify their own validity against simulated attack patterns without requiring deployment to actual network environment. This self-service verification confirms rule reliability while preventing false detections by identifying and correcting suboptimal parameter settings before production use, eliminating the need to expose actual networks to potentially flawed rules.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3099024B1Analysis rule adjustment device, analysis rule adjustment system, analysis rule adjustment method, and analysis rule adjustment program
Publication Date: 2019.01.02 NIPPON TELEGRAPH & TELEPHONE CORP
  • EP3099024B1 patent drawingFigure 1
  • EP3099024B1 patent drawingFigure 2
  • EP3099024B1 patent drawingFigure 3

AI summary

There is provided an analysis rule adjustment device that adjusts an analysis rule used in a communication log analysis performed to detect malicious communication through a network. The analysis rule adjustment device includes a log acquisition unit, a log analysis unit, and a first analysis unit. The log acquisition unit acquires a communication log through a network to be defended and a communication log generated by malware. The log analysis unit analyzes the communication log acquired by the log acquisition unit on the basis of predetermined analysis rule and tuning condition. The first analysis unit analyzes an analysis result by the log analysis unit and calculates a recommended tuning value used in an adjustment of the predetermined analysis rule and satisfying the tuning condition.