Optimization Apparatus for Dynamic Cyber Attack Dealing Point Selection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional techniques for defending against cyber attacks fail to dynamically select the optimum dealing point and function, especially when network configurations change or resources are depleted, leading to ineffective defense mechanisms.
Innovation Solution
An optimization apparatus that collects cyber attack and system information to identify attack routes and extract dealing point candidates with effective functions, using optimization logic to select the optimal dealing point for executing defense functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If defense measures are concentrated at a particular dealing point, then defense effectiveness against cyber attacks is improved, but resources of the targeted device may be depleted and the dealing function may not operate
Solution Approach 1:
The patent implements dynamic selection of dealing points based on real-time system information including load states and resource availability. The optimization apparatus continuously monitors system conditions and dynamically adjusts which dealing point executes the dealing function, preventing resource depletion at any single device while maintaining effective defense.
Solution Approach 2:
The patent assigns different roles and functions to different dealing points based on their local capabilities and current state. Rather than concentrating all defense functions at one point, the system distributes dealing functions across multiple suitable devices, with each dealing point optimized for its specific role and capacity.
2Speed
If a dedicated firewall near the attacker is selected by tracing IP address, then the dealing point nearer to the attacker is able to be selected, but only dedicated devices are targeted and the optimum dealing point cannot be dynamically selected for network configurations formed of different types of security devices
Solution Approach 1:
The patent creates a universal optimization apparatus that can evaluate and select from multiple types of security devices (firewalls, WAFs, IPS, virtual devices, etc.) based on their dealing functions rather than their specific device types. The system identifies dealing point candidates from any security device type and selects the optimum based on real-time conditions, making the system adaptable to heterogeneous network configurations.
Solution Approach 2:
The patent implements dynamic selection of dealing points based on real-time system information including load states and resource availability. The optimization apparatus continuously monitors system conditions and dynamically adjusts which dealing point executes the dealing function, preventing resource depletion at any single device while maintaining effective defense.
3Device complexity
If static rules are used to determine dealing points, then the dealing point determination process is simple, but the system cannot adapt to dynamic changes in network configuration and load states
Solution Approach 1:
The patent implements a feedback mechanism where the optimization apparatus continuously collects system information about load states, resource availability, and network conditions. This feedback is used to dynamically adjust the selection of dealing points, ensuring the system adapts to changing conditions while maintaining a relatively simple overall architecture.
Solution Approach 2:
The optimization apparatus automatically monitors system conditions and makes decisions about dealing point selection without requiring manual intervention. The system self-adjusts to changing network configurations and load states by autonomously evaluating system information and selecting the most appropriate dealing point.
Data Source
AI summary
An optimization apparatus collects cyber attack information that is information related to a cyber attack, and system information that is information related to an entire system including a device that has received the cyber attack. Based on the collected cyber attack information and system information, the optimization apparatus identifies an attack route of the cyber attack, and extracts, as dealing point candidates, devices that are on the attack route and have an effective dealing function against the cyber attack. Subsequently, the optimization apparatus selects a dealing point from the extracted dealing point candidates by using optimization logic that has been set.


