Communication Destination Determination Device for Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication destination determination methods fail to effectively detect suspicious communication destinations due to limitations in identifying various attack methods, leading to incomplete vulnerability diagnosis of servers.
Innovation Solution
A communication destination determination device and method that transmits a second signal in response to a first signal from a communication destination and determines if a third signal is received within a certain time period, classifying the destination as suspicious based on this response.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If vulnerability diagnosis is performed using existing methods, then some vulnerabilities can be detected, but suspicious communication destinations using various attack methods cannot be fully detected
Solution Approach 1:
Instead of analyzing incoming requests to detect attacks, the invention inverts the approach by analyzing outgoing responses. The system determines whether a communication destination is suspicious by checking if it sends a third signal within a predetermined time period after receiving a second signal, thereby detecting malicious behavior patterns that existing methods miss
2Reliability
If the server processes all incoming requests, then complete vulnerability diagnosis can be attempted, but processing load increases and security risks from malicious destinations increase
Solution Approach 1:
The system performs preliminary security assessment by analyzing the response behavior of communication destinations before processing their requests. By determining whether a destination is suspicious based on its signal response timing, the server can preemptively identify and handle malicious sources, reducing overall processing load and security risks
Solution Approach 2:
The invention introduces feedback mechanisms where the server monitors and analyzes the response behavior of communication destinations. By examining whether destinations send signals within predetermined time periods, the system creates a feedback loop that continuously assesses security threats and adjusts processing accordingly, improving both reliability and efficiency
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
Provided are a communication destination determination device and the like in which a communication destination that is highly likely to pose a threat can be detected. A communication destination determination device 101 is provided with: a signal transmission unit 102 which transmits, when a first signal transmitted from a communication destination 104 is received via a communication network, a second signal in response to the first signal to the communication destination 104; and a communication destination determination unit 103 which classifies whether the communication destination 104 is highly likely to pose a threat or not, on the basis of whether or not a third signal transmitted from the communication destination 104 is received within a certain time period from the timing of transmission of the second signal.