Data Classification Apparatus Error Determination for Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data classification techniques for intrusion detection systems (IDS) and intrusion prevention systems (IPS) face challenges in accurately classifying a large number of signatures, leading to potential false classifications, and there is a need for improved error determination accuracy.

Innovation Solution

A data classification apparatus that generates a feature vector using classification target data, includes a classification estimation process observation unit to acquire observation information from a classification estimation unit with multiple weak classifiers, and an error determination unit to determine the correctness of the classification result based on the feature vector and classification output.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If classification is performed using a classification estimation module with machine learning, then classification automation is improved, but classification accuracy deteriorates due to false classifications

Engineering Contradiction:
Improveclassification automationVSAvoidclassification accuracy
Core Design Contradiction:
Extent of automationVSMeasurement precision

Solution Approach 1:

The system introduces a feedback mechanism where classification results are evaluated against ground truth labels, and classification processes with high error rates are identified and improved through retraining with augmented data. This closed-loop feedback system continuously improves classification accuracy while maintaining automation.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary actions by generating dummy training data and augmenting the training dataset before final classification. By preparing enhanced training data in advance, the system improves classification accuracy before the actual classification task, reducing false classifications while maintaining automation.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the number of signatures is increased to improve detection coverage, then detection capability is improved, but classification difficulty worsens

Engineering Contradiction:
Improvedetection capabilityVSAvoidclassification difficulty
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the classification task by introducing intermediate classification processes and evaluating each classification step separately. This segmentation allows the system to handle large numbers of signatures by breaking down the complex classification problem into manageable stages, reducing overall classification difficulty while maintaining detection coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary evaluation process that assesses classification results against ground truth labels. This intermediary layer mediates between the classification estimation module and the final results, providing a mechanism to identify and correct errors without requiring manual review of all classifications, thus managing complexity while maintaining reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If manual classification is performed to ensure accuracy, then classification accuracy is improved, but productivity deteriorates

Engineering Contradiction:
Improveclassification accuracyVSAvoidclassification throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system applies partial manual verification by evaluating classification results against ground truth labels and focusing improvement efforts on classification processes with high error rates. Instead of manually verifying all classifications, the system selectively applies enhanced processing where needed, maintaining high accuracy while preserving overall productivity through automated handling of low-risk cases.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11934427B2Data classification apparatus, data classification method and program
Publication Date: 2024.03.19 NIPPON TELEGRAPH & TELEPHONE CORP
  • US11934427B2 patent drawing
  • US11934427B2 patent drawing
  • US11934427B2 patent drawing

AI summary

A data classification apparatus includes a data transformation unit that generates a feature vector by using classification target data, a classification estimation process observation unit that acquires, from a classification estimation unit that estimates classification of the classification target data and including a plurality of weak classifiers, observation information in a classification process based on the feature vector, and generates a classification estimation process feature vector based on the observation information, and an error determination unit that determines, in accordance with an input of the classification estimation process feature vector generated by the classification estimation process observation unit and a classification result output from the classification estimation unit to which the feature vector is input, whether the classification result is correct.