Network Attack Prediction System Using Regression and Time Series Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methodologies lack systematic frameworks for rigorously analyzing statistical properties of network-attack data from honeypots and network telescopes, hindering accurate prediction of attack rates and strategies.

Innovation Solution

A prediction system combining regression learning and time series analysis, utilizing a Sensor Attack Data Database, Context Filter Module, Configuration Manager Module, Data Aggregator and Feature Extractor Module, Attack Rate Modeler Module, and Attack Rate Prediction Models Database to model and predict attack rates at various resolutions, granularity levels, and horizons.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If honeypots and network telescopes are deployed to collect attack data, then the quantity of attack data is improved, but the difficulty of detecting and measuring statistical properties worsens

Engineering Contradiction:
Improvequantity of attack dataVSAvoiddifficulty of analyzing statistical properties
Core Design Contradiction:
Quantity of substanceVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces an intermediary analysis system that includes a data receiver module to collect attack data from honeypots and network telescopes, a data processor module to process the collected data, and a statistical property calculator module to compute statistical properties. This intermediary system bridges the gap between raw attack data collection and meaningful statistical analysis, making the measurement of statistical properties feasible despite the complexity of the data volume.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If a systematic framework for analyzing attack data is developed, then the measurement precision of attack rates is improved, but the device complexity worsens

Engineering Contradiction:
Improveprecision of attack rate predictionVSAvoidcomplexity of systematic framework
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the systematic framework into distinct functional modules: a data receiver module for collecting attack data, a data processor module for processing the data, and a statistical property calculator module for computing statistical properties. This segmentation allows each module to handle specific tasks independently, improving measurement precision while managing device complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The analysis system is designed with multi-functional capabilities that can handle various types of attack data from different sources (honeypots, network telescopes) and compute multiple statistical properties (attack rates, inter-arrival times, etc.). This universality allows a single framework to serve multiple analysis needs, improving measurement precision without proportionally increasing device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If regression learning and time series analysis are combined for modeling, then the prediction accuracy is improved, but the ease of operation worsens

Engineering Contradiction:
Improveprediction accuracyVSAvoidease of configuring models
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The statistical property calculator module automatically performs regression learning and time series analysis computations based on the collected attack data, without requiring manual intervention for each calculation. The system self-configures the modeling processes, improving prediction accuracy while maintaining ease of operation by automating the complex analytical tasks.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback mechanisms where the results from regression learning and time series analysis are continuously evaluated and used to refine the statistical property calculations. This feedback loop improves prediction accuracy over time while the automated nature of the feedback process maintains ease of operation by eliminating manual tuning requirements.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3346666B1A prediction system configured for modeling the expected number of attacks on a computer or communication network
Publication Date: 2020.08.26 DEUTSCHE TELEKOM AG
  • EP3346666B1 patent drawingFigure 1
  • EP3346666B1 patent drawingFigure 2
  • EP3346666B1 patent drawingFigure 3

AI summary

The present invention provides a prediction system configured for modeling the expected number of attacks on a computer or a communication network using data obtained by sensors of an attack monitoring system. The prediction system is capable of modeling the attack rates and predicts the expected number of attacks at different resolutions, granularity levels and horizons. The core modeling module of the system requires basic and minimal information about the observed attacks which makes the present prediction system applicable for a variety of attack monitoring systems such as low, medium and high interaction honeypot systems or network telescopes.