Network Attack Prediction System Using Regression and Time Series Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methodologies lack systematic frameworks for rigorously analyzing statistical properties of network-attack data from honeypots and network telescopes, hindering accurate prediction of attack rates and strategies.
Innovation Solution
A prediction system combining regression learning and time series analysis, utilizing a Sensor Attack Data Database, Context Filter Module, Configuration Manager Module, Data Aggregator and Feature Extractor Module, Attack Rate Modeler Module, and Attack Rate Prediction Models Database to model and predict attack rates at various resolutions, granularity levels, and horizons.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If honeypots and network telescopes are deployed to collect attack data, then the quantity of attack data is improved, but the difficulty of detecting and measuring statistical properties worsens
Solution Approach 1:
The patent introduces an intermediary analysis system that includes a data receiver module to collect attack data from honeypots and network telescopes, a data processor module to process the collected data, and a statistical property calculator module to compute statistical properties. This intermediary system bridges the gap between raw attack data collection and meaningful statistical analysis, making the measurement of statistical properties feasible despite the complexity of the data volume.
2Measurement precision
If a systematic framework for analyzing attack data is developed, then the measurement precision of attack rates is improved, but the device complexity worsens
Solution Approach 1:
The patent segments the systematic framework into distinct functional modules: a data receiver module for collecting attack data, a data processor module for processing the data, and a statistical property calculator module for computing statistical properties. This segmentation allows each module to handle specific tasks independently, improving measurement precision while managing device complexity through modular design.
Solution Approach 2:
The analysis system is designed with multi-functional capabilities that can handle various types of attack data from different sources (honeypots, network telescopes) and compute multiple statistical properties (attack rates, inter-arrival times, etc.). This universality allows a single framework to serve multiple analysis needs, improving measurement precision without proportionally increasing device complexity.
3Measurement precision
If regression learning and time series analysis are combined for modeling, then the prediction accuracy is improved, but the ease of operation worsens
Solution Approach 1:
The statistical property calculator module automatically performs regression learning and time series analysis computations based on the collected attack data, without requiring manual intervention for each calculation. The system self-configures the modeling processes, improving prediction accuracy while maintaining ease of operation by automating the complex analytical tasks.
Solution Approach 2:
The system incorporates feedback mechanisms where the results from regression learning and time series analysis are continuously evaluated and used to refine the statistical property calculations. This feedback loop improves prediction accuracy over time while the automated nature of the feedback process maintains ease of operation by eliminating manual tuning requirements.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention provides a prediction system configured for modeling the expected number of attacks on a computer or a communication network using data obtained by sensors of an attack monitoring system. The prediction system is capable of modeling the attack rates and predicts the expected number of attacks at different resolutions, granularity levels and horizons. The core modeling module of the system requires basic and minimal information about the observed attacks which makes the present prediction system applicable for a variety of attack monitoring systems such as low, medium and high interaction honeypot systems or network telescopes.