Feature Knowledge Base for Dynamic Network Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional network security systems rely on static rule bases and manual analysis, which are slow, costly, and ineffective against dynamic network attacks, leading to high false alarm rates and inability to adapt to new detection behaviors.

Innovation Solution

A method for constructing a feature knowledge base using deep learning, incorporating CNN-RNN hybrid models, spatio-temporal feature extraction, and attention mechanisms to automatically generate detection rules and perform dynamic, progressive responses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If static rule base and manual analysis are used for network security detection, then the system is simple to implement, but the response speed is slow and labor cost is high

Engineering Contradiction:
Improveimplementation simplicityVSAvoidresponse speed
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The system employs deep learning models that automatically learn and update detection rules from network traffic data without manual intervention. The model self-trains on historical data and adapts to new attack patterns autonomously, eliminating the need for manual rule creation and updating while maintaining high response speeds.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Manual analysis and static rule matching are replaced with automated deep learning-based dynamic rule generation. The system uses neural networks to process network traffic and generate detection rules automatically, substituting human operators with intelligent algorithms that operate at machine speed.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of manufacture

If static rule base and known attack features are used for detection, then the detection method is easy to implement, but it cannot adapt to dynamic change detection technology and new attack means

Engineering Contradiction:
Improvedetection method simplicityVSAvoidadaptability to new attacks
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The system transitions from static detection rules to dynamic rule generation. The deep learning model continuously learns from new network traffic patterns and automatically updates detection rules to adapt to evolving attack techniques. The rules are not fixed but dynamically adjusted based on real-time data analysis.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary learning on historical attack data to build initial detection capabilities. By training on past attack patterns beforehand, the model is prepared to quickly recognize and adapt to new attack variants, enabling proactive rather than reactive defense.

Inventive Principle:
Principle #10Preliminary action

3Speed

If simple judgment based on single dimension features is used, then the detection process is fast, but the false alarm rate is high

Engineering Contradiction:
Improvedetection speedVSAvoidfalse alarm rate
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system merges multiple feature dimensions including packet characteristics, flow statistics, behavioral patterns, and temporal features into a comprehensive analysis framework. By combining these diverse features through deep learning models, the system achieves accurate multi-dimensional correlation analysis that reduces false alarms while maintaining detection speed.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The detection system uses composite feature representation, combining heterogeneous data types (packet headers, payload characteristics, temporal patterns, spatial relationships) into a unified feature vector. This composite approach enables the model to capture complex attack patterns that single-feature methods miss, improving reliability without sacrificing speed.

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS20250363394A1Method for constructing feature knowledge base of mapping behavior based on deep learning
Publication Date: 2025.11.27 HUANENG INFORMATION TECH CO LTD
  • US20250363394A1 patent drawing

AI summary

The disclosure belongs to the technical field of network security, and provides a method for constructing a feature knowledge base of mapping behavior based on deep learning, which includes: data acquisition and preprocessing: extracting five-tuple information and behavior features from network traffic. The disclosure automatically extracts the spatio-temporal features through the deep learning model, and enhances the sensitivity to abnormal behaviors by combining the attention mechanism, thus significantly improving the detection accuracy. The explanatory AI technology is used to automatically generate detection rules, the maintenance cost of manual rules is greatly reduced and the efficiency of rule generation is significantly improved. The feature knowledge base supports dynamic updating, may integrate third-party threat information in real time, and ensures the continuous defense ability against new attacks and variant detection means.