Network Attack Pattern Determination via Timestamp Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional technologies fail to provide real-time updates for filtering lists to prevent network attacks, consume significant computing resources, and cannot predict future attack patterns, leaving vulnerabilities in network security.
Innovation Solution
A network attack pattern determination apparatus and method that retrieves and groups access records by time stamps, creates access relations, and compares them to predefined attack patterns to determine and predict potential future attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dynamic real-time scanning is adopted to shorten the vulnerable window, then information security reliability is improved, but computing resource consumption increases
Solution Approach 1:
The patent segments the attack detection process into two distinct phases: an offline learning phase where the system learns normal access patterns from historical data without consuming real-time resources, and an online detection phase where only simple pattern matching is performed on new access records. This segmentation allows the system to maintain high security reliability through comprehensive learning while keeping real-time computing resource consumption minimal during the detection phase.
2Ease of operation
If conventional filtering lists are used to prevent attacks, then ease of operation is improved, but reliability of information security deteriorates due to inability to update in real time
Solution Approach 1:
The system implements self-service by automatically learning normal access patterns from historical data and updating its detection models without requiring manual intervention. The offline learning phase automatically captures evolving normal behaviors, and the system self-adapts to new patterns, eliminating the need for manual filtering list updates while maintaining ease of operation and improving security reliability through real-time adaptation.
3Measurement precision
If comprehensive attack detection is performed on all access records, then measurement precision of attack detection is improved, but productivity of system response deteriorates
Solution Approach 1:
The patent applies preliminary action by performing comprehensive analysis and learning on historical access records during an offline phase before real-time detection is needed. This preliminary learning establishes detection models and normal behavior patterns in advance, so that during online detection, the system only needs to perform fast pattern matching against pre-established models, thereby maintaining high measurement precision while achieving rapid response productivity.
Data Source
AI summary
A network attack pattern determination apparatus, method, and non-transitory computer readable storage medium thereof are provided. The apparatus is stored with several attack patterns and access records. Each access record includes a network address, time stamp, and access content. Each attack pattern corresponds to at least one attack access relation. Each attack access relation is defined by a network address and access content. The apparatus retrieves several attack records according to at least one attack address. The network address of each attack record is one of the attack address(s). The apparatus divides the attack records into several groups according to the time stamps and performs the following operations for each group: (a) creating at least one access relation for each attack address included in the group and (b) determining that the group corresponds to one of the attack patterns according to the at least one access relation of the group.


