Historical Network Attack Visualization for Complex Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network detection methods are ineffective in detecting complex attacks, such as webshell attacks, due to their reliance on shallow signature-based approaches and inability to utilize stateful information, leading to high false positives and negatives.
Innovation Solution
A system that maintains and processes historical network activity data to detect complex attacks using machine learning models, generating intermediates and features from sensor logs to identify anomalies and mitigate attacks without significant computational overhead.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If shallow signature-based detection methods are used, then device complexity is reduced, but detection precision deteriorates leading to high false positives and negatives
Solution Approach 1:
The system performs preliminary actions by collecting and storing historical network data, sensor logs, and intermediates in advance. This preparation enables the machine learning model to analyze complex attack patterns effectively when needed, resolving the contradiction by having detection capabilities ready without requiring complex real-time processing during actual detection
Solution Approach 2:
The patent introduces intermediates as a mediating layer between raw sensor logs and the machine learning model. These intermediates pre-process and structure the data, making it more suitable for analysis while reducing the computational complexity required for detection. This intermediary structure enables higher detection precision without proportionally increasing device complexity
2Reliability
If historical data processing is implemented, then detection reliability improves, but computational overhead increases
Solution Approach 1:
The system segments the detection process into distinct stages: data collection, intermediate generation, feature extraction, and model inference. This segmentation allows historical data processing to be distributed and optimized at each stage, improving detection reliability through comprehensive analysis while managing computational overhead through structured processing
Solution Approach 2:
The patent creates copies of historical network data and maintains multiple versions of intermediates for different analysis purposes. This copying approach enables the machine learning model to access comprehensive historical information for reliable detection without requiring the system to continuously process all raw data, thereby managing computational resources more efficiently
3Adaptability or versatility
If machine learning models are deployed, then adaptability to complex attacks improves, but device complexity increases
Solution Approach 1:
The machine learning model operates in a self-service manner by automatically learning from historical data and adapting to new attack patterns without requiring manual configuration or retraining. This self-service capability provides high adaptability to complex and evolving attacks while keeping the system relatively simple in terms of operational complexity, as the model autonomously handles the complexity of pattern recognition
Data Source
AI summary
Various embodiments provide systems and methods for visually displaying an developing attack in a computer network based at least in part on historical information.


