Historical Network Analysis for Complex Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network detection methods are ineffective in detecting complex attacks, particularly webshell attacks, due to their reliance on shallow signature-based approaches and inability to utilize stateful information, leading to high false positives and negatives.

Innovation Solution

A system that maintains and processes historical network activity data to identify complex attacks using machine learning models, allowing for the detection and mitigation of webshell attacks without requiring endpoint management or complete signature coverage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If shallow signature-based detection methods are used, then device complexity is reduced, but detection precision deteriorates leading to high false positives and negatives

Engineering Contradiction:
Improvedetection system complexityVSAvoidattack detection precision
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent transitions from shallow signature-based detection to deep packet inspection that analyzes multiple dimensions of network traffic including payload content, protocol structure, behavioral patterns, and contextual information. This multi-dimensional analysis enables accurate detection of complex attacks like webshells without requiring proportionally increased system complexity

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent replaces traditional mechanical signature-matching mechanisms with machine learning models that automatically learn attack patterns from historical data. These models detect anomalies and malicious behaviors without relying on pre-defined signatures, significantly improving detection precision while managing complexity through automated feature extraction

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If historical network data is collected and analyzed, then detection precision improves, but loss of time increases due to data processing requirements

Engineering Contradiction:
Improvemalicious behavior detection precisionVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements continuous collection and preprocessing of historical network traffic data, organizing it into structured formats with extracted features ready for analysis. This preliminary preparation ensures that when attacks occur, the machine learning models can quickly query and analyze pre-processed data without time-consuming real-time processing

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates simplified representations and features from raw network traffic data, storing these extracted characteristics rather than analyzing complete raw packets during detection. This copying approach maintains detection precision while significantly reducing the time required for real-time analysis

Inventive Principle:
Principle #26Copying

3Measurement precision

If stateful information is utilized for detection, then detection precision improves, but device complexity increases

Engineering Contradiction:
Improvecomplex attack detection precisionVSAvoidsystem architecture complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements a unified machine learning-based detection framework that handles multiple attack types (webshells, SQL injection, XSS, etc.) and multiple data sources (network traffic, endpoint data, threat intelligence) through a single system architecture. This multi-functional approach improves detection precision for complex attacks while avoiding the complexity of separate specialized systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12375513B2Systems and methods for detecting complex attacks in a computer network
Publication Date: 2025.07.29 FORTINET INC
  • US12375513B2 patent drawing
  • US12375513B2 patent drawing
  • US12375513B2 patent drawing

AI summary

Various embodiments provide systems and methods for identifying malicious network behavior based upon historical analysis.