Attack Traffic Distribution Mapping for Security Alert Prioritization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network-based intrusion detection systems provide insufficient information for analyzing attacks, relying solely on alert information and importance, which limits effective analysis and response.
Innovation Solution
A processing device and method that form first and second attacked distribution information using transmission performance indices in a coordinate plane, allowing for the identification of failed and successful attack areas, and a priority degree determination based on these distributions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If only alert information and importance are presented by the intrusion detection system, then the device complexity is reduced, but the information completeness for attack analysis becomes insufficient
Solution Approach 1:
The patent applies dimensionality change by transitioning from one-dimensional alert information presentation to two-dimensional coordinate plane visualization. Transmission performance indices are plotted on coordinate axes, creating a visual space that simultaneously displays multiple attack characteristics. This allows comprehensive attack analysis while maintaining manageable system complexity through graphical representation rather than complex data structures.
Solution Approach 2:
The patent segments attack information into distinct transmission performance indices that can be independently measured and plotted. By dividing the complex attack data into separate dimensional metrics (first kind and second kind transmission performance indices), the system enables detailed analysis of different attack aspects while keeping the overall system structure organized and manageable.
2Measurement precision
If transmission performance indices are analyzed for both failed and successful attack traffics, then the measurement precision of attack patterns is improved, but the loss of time for data processing increases
Solution Approach 1:
The patent implements preliminary action by pre-calculating and storing transmission performance indices for both successful and failed attack traffics before analysis is needed. The distribution information is prepared in advance by plotting these indices on coordinate planes, so when actual attack analysis is required, the system can quickly reference pre-computed distributions rather than processing raw data from scratch, thereby reducing analysis time while maintaining precision.
3Productivity
If distribution information is formed in a coordinate plane with multiple transmission performance indices, then the productivity of attack analysis is improved, but the device complexity increases
Solution Approach 1:
The patent uses copying by creating visual representations (graphs and coordinate planes) that replicate attack distribution patterns. Instead of complex computational analysis, the system generates graphical copies of attack data distributions that can be visually interpreted. This allows analysts to quickly understand attack patterns through visual copies rather than processing complex numerical data, improving productivity while keeping system complexity manageable.
Data Source
AI summary
A processing device acquires a value of a first kind transmission performance index and a value of a second kind transmission performance index of each of a plurality of failed attack traffics being associated with a failed attack on an apparatus in a network, and a value of the first kind transmission performance index and a value of the second kind transmission performance index of each of a plurality of successful attack traffics being associated with a successful attack; and forms first attacked distribution information including information about a plurality of areas including a failed attack area and a successful attack area based on a value of the first kind transmission performance index and a value of the second kind transmission performance index for the plurality of failed attack traffics and the plurality of successful attack traffics.


