Historical Network Attack Visualization for Complex Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network detection methods are ineffective in detecting complex attacks, such as webshell attacks, due to their reliance on shallow signature-based approaches and inability to utilize stateful information, leading to high false positives and negatives.

Innovation Solution

A system that maintains and processes historical network activity data to detect complex attacks using machine learning models, generating intermediates and features from sensor logs to identify anomalies and mitigate attacks without significant computational overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If shallow signature-based detection methods are used, then device complexity is reduced, but detection precision deteriorates leading to high false positives and negatives

Engineering Contradiction:
Improvedetection precisionVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by collecting and storing historical network data, sensor logs, and intermediates in advance. This preparation enables the machine learning model to analyze complex attack patterns effectively when needed, resolving the contradiction by having detection capabilities ready without requiring complex real-time processing during actual detection

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces intermediates as a mediating layer between raw sensor logs and the machine learning model. These intermediates pre-process and structure the data, making it more suitable for analysis while reducing the computational complexity required for detection. This intermediary structure enables higher detection precision without proportionally increasing device complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If historical data processing is implemented, then detection reliability improves, but computational overhead increases

Engineering Contradiction:
Improvedetection reliabilityVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system segments the detection process into distinct stages: data collection, intermediate generation, feature extraction, and model inference. This segmentation allows historical data processing to be distributed and optimized at each stage, improving detection reliability through comprehensive analysis while managing computational overhead through structured processing

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates copies of historical network data and maintains multiple versions of intermediates for different analysis purposes. This copying approach enables the machine learning model to access comprehensive historical information for reliable detection without requiring the system to continuously process all raw data, thereby managing computational resources more efficiently

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If machine learning models are deployed, then adaptability to complex attacks improves, but device complexity increases

Engineering Contradiction:
Improveadaptability to attacksVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The machine learning model operates in a self-service manner by automatically learning from historical data and adapting to new attack patterns without requiring manual configuration or retraining. This self-service capability provides high adaptability to complex and evolving attacks while keeping the system relatively simple in terms of operational complexity, as the model autonomously handles the complexity of pattern recognition

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12432235B2Systems and methods for visualizing detected attacks in a computer network
Publication Date: 2025.09.30 FORTINET INC
  • US12432235B2 patent drawing
  • US12432235B2 patent drawing
  • US12432235B2 patent drawing

AI summary

Various embodiments provide systems and methods for visually displaying an developing attack in a computer network based at least in part on historical information.