Data Processing Apparatus Using State Estimation for Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems require user input of the current operation state, making it difficult to accurately detect attacks on monitored systems due to potential incorrect recognition of the system's state.

Innovation Solution

A data processing apparatus that includes a communication data acquisition unit, a learning phase operation state value acquisition unit, and a model generation unit to estimate the operation state using machine learning, generating a state estimation model for accurate attack detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user input of operation state is required, then attack detection can be performed, but measurement precision deteriorates due to potential incorrect recognition of system state

Engineering Contradiction:
Improveattack detection accuracyVSAvoidoperation state recognition accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The monitored system automatically generates operation state information through its own operation state notification unit, eliminating the need for manual user input. The system self-monitors and self-reports its operational parameters (CPU usage, memory usage, network traffic, etc.), ensuring accurate and reliable state information without human intervention or potential misrecognition.

Inventive Principle:
Principle #25Self-service

2Device complexity

If manual operation state input is used, then device complexity is reduced, but loss of information occurs when user incorrectly recognizes system state

Engineering Contradiction:
Improvesystem configuration simplicityVSAvoidoperation state information accuracy
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

An operation state notification unit acts as an intermediary between the monitored system and the attack detection apparatus. This intermediary automatically extracts and transmits accurate operation state information (CPU usage, memory usage, network traffic, file operations, registry changes, process creation/deletion) from the system, serving as a reliable bridge that eliminates both manual input complexity and information loss from incorrect user recognition.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If user input of operation state is required, then ease of operation deteriorates, but productivity is maintained through manual state reporting

Engineering Contradiction:
Improveuser input requirementVSAvoidattack detection efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system automatically performs operation state monitoring and reporting without requiring user input. The operation state notification unit continuously collects system parameters (CPU usage, memory usage, network traffic, file operations, registry changes, process creation/deletion) and transmits them to the attack detection apparatus, improving ease of operation while maintaining high productivity through automated real-time monitoring.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250301000A1Data processing apparatus, data processing method, and computer readable medium
Publication Date: 2025.09.25 MITSUBISHI ELECTRIC CORP
  • US20250301000A1 patent drawing
  • US20250301000A1 patent drawing
  • US20250301000A1 patent drawing

AI summary

In a learning phase, a communication unit (203) acquires communication data that includes a parameter value from which an operation state of a monitored system can be estimated, and that is to be communicated in the monitored system, as learning phase communication data. In the learning phase, a state input unit (204) acquires a learning phase operation state value that indicates a learning phase operation state which is an operation state of the monitored system. In the learning phase, a learning unit (210) performs learning using the learning phase operation state value and a learning phase parameter value included in the learning phase communication data, and generates a learning model (215) for estimating from an attack detection phase parameter value included in attack detection phase communication data which is communication data that is to be communicated in the monitored system in the attack detection phase, an attack detection phase operation state which is an operation state of the monitored system.