Automated Analysis Rule Adjustment for Network Malicious Communication Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional techniques for detecting malicious communication using analysis rules face challenges in verifying the validity of these rules and adjusting thresholds, leading to suboptimal settings and requiring manual, time-consuming adjustments in actual network environments.
Innovation Solution
An analysis rule adjustment system that automatically verifies the validity of analysis rules by collecting and analyzing both benign and malignant logs, adjusting parameter thresholds to achieve predetermined detection accuracy, and updating the rules based on optimized tuning values.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual verification and adjustment of analysis rules is performed in actual network environment, then detection accuracy can be improved, but time consumption and operational complexity increase significantly
Solution Approach 1:
The system performs preliminary verification of analysis rules using simulated malicious logs before deploying them to the actual network environment. This preliminary action allows detection accuracy to be improved without the time penalty of manual verification in production, as the rules are pre-tested and optimized using automated simulation techniques.
Solution Approach 2:
The system enables self-service verification where the analysis rules automatically test and validate themselves against simulated attack patterns. Instead of requiring manual operator intervention for verification, the rules autonomously evaluate their own effectiveness through automated simulation, reducing both time consumption and operational complexity while maintaining detection accuracy.
2Measurement precision
If manual adjustment of thresholds is performed by operators, then detection precision can be optimized, but operational complexity and processing time increase
Solution Approach 1:
The system implements self-service threshold optimization where analysis rules automatically adjust their own thresholds based on performance feedback from simulated attacks. Operators no longer need to manually tune thresholds, eliminating operational complexity while maintaining detection precision through automated adaptive optimization.
Solution Approach 2:
The system establishes a feedback loop where detection results from simulated malicious logs are fed back to automatically adjust thresholds. This feedback mechanism enables continuous optimization of detection precision without manual intervention, reducing operational complexity while maintaining high detection accuracy through automated iterative improvement.
3Reliability
If analysis rules are verified in actual network environment, then validity can be confirmed, but false detection rate increases due to suboptimal parameter settings
Solution Approach 1:
The system performs preliminary validation of analysis rules using simulated malicious logs before actual deployment. This preliminary action confirms rule validity in a controlled environment with optimal parameter settings, preventing suboptimal rules from being deployed to production where they would generate false detections, thus reducing false detection rate while maintaining reliability.
Solution Approach 2:
The analysis rules automatically verify their own validity against simulated attack patterns without requiring deployment to actual network environment. This self-service verification confirms rule reliability while preventing false detections by identifying and correcting suboptimal parameter settings before production use, eliminating the need to expose actual networks to potentially flawed rules.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
There is provided an analysis rule adjustment device that adjusts an analysis rule used in a communication log analysis performed to detect malicious communication through a network. The analysis rule adjustment device includes a log acquisition unit, a log analysis unit, and a first analysis unit. The log acquisition unit acquires a communication log through a network to be defended and a communication log generated by malware. The log analysis unit analyzes the communication log acquired by the log acquisition unit on the basis of predetermined analysis rule and tuning condition. The first analysis unit analyzes an analysis result by the log analysis unit and calculates a recommended tuning value used in an adjustment of the predetermined analysis rule and satisfying the tuning condition.