Attacker Temporal Behavior Fingerprinting via Spectral Transformation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems, such as Snort, primarily focus on the content of network traffic and fail to effectively utilize temporal patterns in detecting malicious activities, making it difficult for human analysts to identify and predict attacker behavior due to the massive amount of data and the probabilistic nature of cyber attacks.

Innovation Solution

The implementation of a method that preprocesses Snort event data to extract temporal patterns using spectral transformation and deep learning techniques, generating a unique temporal behavior fingerprint for attackers by transforming time-domain sequences into frequency-domain spectral vectors, which are then denoised and decorrelated to identify periodic behaviors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network security systems focus on content analysis of network traffic, then detection accuracy of malicious activities is improved, but the ability to detect temporal patterns and predict attacker behavior deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoidtemporal pattern detection capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent segments the analysis process into two distinct components: content analysis (traditional Snort event processing) and temporal pattern analysis (spectral transformation of time sequences). This segmentation allows each component to specialize in its strength while the system as a whole gains both content-based detection accuracy and temporal pattern recognition capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces spectral transformation as an intermediary process that converts temporal Snort event data into a different representation domain. This intermediary transformation enables the system to extract temporal patterns without interfering with the existing content-based detection mechanisms, thereby maintaining detection accuracy while adding temporal analysis capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If human analysts review massive amounts of Snort event data, then comprehensive security monitoring is improved, but the time required for analysis and the probability of missing attacks increases

Engineering Contradiction:
Improvecomprehensive security monitoringVSAvoidanalysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements self-service by enabling the system to automatically perform temporal pattern analysis and attacker behavior prediction without requiring human analyst intervention. The spectral transformation and deep learning components autonomously process Snort event data, identify temporal patterns, and generate predictions, significantly reducing the time burden on human analysts while maintaining comprehensive monitoring coverage.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical process of manual data review with an automated computational system using spectral transformation and deep learning. This substitution eliminates the time-consuming nature of human analysis while processing massive amounts of Snort event data, thereby reducing analysis time while maintaining or improving monitoring reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Extent of automation

If spectral transformation and deep learning are applied to Snort event data, then automated identification of temporal patterns is improved, but system complexity increases

Engineering Contradiction:
Improveautomated temporal pattern identificationVSAvoidsystem complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The patent applies universal deep learning models that can handle multiple temporal patterns and attacker behaviors through a single unified framework. The spectral transformation approach and deep learning architecture are designed to be multi-functional, capable of identifying various temporal patterns (periodic, irregular, evolving) and predicting different types of attacker behaviors, thereby achieving high automation without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10645100B1Systems and methods for attacker temporal behavior fingerprinting and grouping with spectrum interpretation and deep learning
Publication Date: 2020.05.05 ALERT LOGIC LLC
  • US10645100B1 patent drawing
  • US10645100B1 patent drawing
  • US10645100B1 patent drawing

AI summary

Attackers may be uniquely identified by their temporal behavior patterns. Time marks and events in a time sequence between a unique pair of a source network address and a destination network address are pre-processed by a network security system to generate a temporal sequence for spectral extraction. The destination network address resides in a computer network monitored by the network security system. The temporal sequence is transformed from the time domain to the frequency domain to capture periodicity in the time sequence in a spectral vector. The spectral vector is denoised and decorrelated through deep learning to produce a spectral fingerprint that is significantly smaller than the spectral vector. The spectral fingerprint represents a temporal behavior fingerprint of an attacker associated with the source network address with respect to the destination network address over a period of time in the time sequence.