Cyberattack Information Analysis Identifying Long-Life IP Addresses

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Analyzing cyberattack information is labor-intensive due to the high likelihood of single-use IP addresses being used in cyberattacks, making it difficult for analysts with limited time to identify significant IP addresses amidst a large number of addresses.

Innovation Solution

A cyberattack information analysis program that collects and analyzes cyberattack data, specifies source IP addresses, determines address ranges based on distribution comparisons, and outputs information for monitoring targets, thereby assisting in identifying significant IP addresses for analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If analysts manually analyze a large number of IP addresses from cyberattack information, then they can identify attack sources, but the analysis work becomes extremely time-consuming and labor-intensive

Engineering Contradiction:
Improveaccuracy of attack source identificationVSAvoidtime required for analysis
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent introduces an automated analysis system that acts as an intermediary between raw cyberattack information and human analysts. The system automatically extracts IP addresses, determines their usage patterns, identifies long-life addresses, and prioritizes them for analysis, thereby reducing the time burden on analysts while maintaining identification accuracy

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual mechanical analysis with automated computational processes. The system uses algorithms to automatically parse cyberattack information, extract IP addresses, analyze their temporal patterns, and generate prioritized lists, substituting human labor with automated information processing

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If analysts focus on all IP addresses equally, then they may not miss any potential threats, but they waste effort on single-use IP addresses that are unlikely to be used again

Engineering Contradiction:
Improvecompleteness of threat detectionVSAvoidefficiency of analysis work
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies different analysis strategies to different IP addresses based on their characteristics. Instead of treating all IP addresses uniformly, the system identifies 'long-life' IP addresses (those appearing multiple times across different time periods) and prioritizes them for detailed analysis, while giving less attention to single-use addresses

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent performs preliminary filtering and classification of IP addresses before detailed analysis. By automatically determining which IP addresses are 'long-life' versus single-use addresses in advance, the system prepares a prioritized list that guides analysts' subsequent work, preventing wasted effort on low-priority addresses

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3826242B1Cyber attack information analyzing program, cyber attack information analyzing method, and information processing device
Publication Date: 2022.08.10 FUJITSU LTD
  • EP3826242B1 patent drawingFigure 1
  • EP3826242B1 patent drawingFigure 2
  • EP3826242B1 patent drawingFigure 3

AI summary

A cyberattack information analysis program according to an embodiment causes a computer to execute a collecting process, a specifying process, a determining process, and an outputting process. The collecting process collects a plurality of pieces of cyberattack information. The specifying process analyzes the plurality of pieces of collected cyberattack information, specifies a plurality of addresses of cyberattack sources included in the plurality of pieces of cyberattack information, and specifies a period when each of the specified addresses of the plurality of cyberattack sources is observed. The determining process determines an address range or some addresses included in the address range as monitoring targets according to a result of comparing a first period distribution of an observed period corresponding to the plurality of specified addresses and a second period distribution of an observed period for each address range. The outputting process outputs information regarding the determined address range or some addresses included in the address range.