Cyber Attack Detection Device Using Hybrid Anomaly and Signature Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cyber attack detection techniques in 5G mobile networks face challenges in accurately distinguishing between known and unknown attacks, often resulting in high false positive rates and vulnerability to attacks targeting detection modules themselves.
Innovation Solution
A method that combines decisions from multiple detection techniques, updating confidence levels based on cross-validation, and dynamically adapting rules using a trusted third detection technique, potentially reinforced through machine learning, to enhance detection accuracy and reliability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If signature-based detection is used to detect known attacks, then false positive rate is reduced, but only known attacks can be detected
Solution Approach 1:
The patent combines signature-based detection and anomaly-based detection into a unified hybrid detection framework. The system integrates both approaches by having anomaly detection identify potential threats and signature detection verify them, thereby maintaining high detection accuracy for known attacks while improving detection coverage for unknown attacks through the anomaly detection component.
Solution Approach 2:
The patent introduces a decision module as an intermediary that coordinates between anomaly detection and signature detection. This mediator evaluates outputs from both detection methods, resolves conflicts, and makes final detection decisions, allowing the system to leverage the strengths of both approaches while mitigating their individual weaknesses.
2Adaptability or versatility
If anomaly detection is used to detect new attacks, then new attacks can be detected, but false positive rate increases
Solution Approach 1:
The patent merges anomaly detection with signature detection in a hybrid framework where anomaly detection serves as a screening mechanism. By combining both approaches, the system maintains the ability to detect new attacks through anomaly detection while using signature detection to verify suspicious patterns, thereby reducing false positives.
Solution Approach 2:
The patent implements feedback mechanisms where detection results from both anomaly and signature detection are fed into a decision module. This feedback loop allows the system to learn from detection outcomes, adjust detection thresholds, and refine the anomaly detection model over time, progressively reducing false positive rates while maintaining detection coverage.
3Measurement precision
If hybrid detection technique combining anomaly and signature detection is used, then detection rate and accuracy improve, but vulnerability to attacks on detection modules increases
Solution Approach 1:
The patent segments the detection system into multiple independent detection modules (anomaly detection, signature detection, decision module) that operate semi-independently. This segmentation ensures that an attack targeting one module does not compromise the entire system, as other modules can continue functioning and provide redundant detection capabilities.
Solution Approach 2:
The decision module acts as an intermediary layer that protects the detection system from attacks. It validates and coordinates outputs from anomaly and signature detection modules, implementing consistency checks and confidence threshold validations that prevent malicious inputs from triggering false detections or bypassing security measures.
4Reliability
If multiple detection techniques are combined with confidence level updating, then detection reliability improves, but system complexity increases
Solution Approach 1:
The patent employs feedback mechanisms where detection results and confidence levels are continuously updated based on outcomes from multiple detection techniques. This feedback loop allows the system to dynamically adjust confidence levels and detection thresholds, improving reliability through adaptive learning while using automated algorithms to manage complexity rather than manual configuration.
Solution Approach 2:
The patent dynamically changes parameters such as confidence levels and detection thresholds based on system state and detection outcomes. By automatically adjusting these parameters through mathematical models and learning algorithms, the system improves reliability through adaptability while avoiding the complexity of manual parameter tuning and system configuration.
Data Source
AI summary
A method for monitoring data transiting via a user equipment is described, as well as a cyber attack detection device, The method includes obtaining a first decision from a first cyber attack detection technique and a second decision from a second cyber attack detection technique, indicating whether the data are associated with attack traffic, obtaining a third decision from a third cyber attack detection technique indicating whether the data are associated with attack traffic, the third technique the first and second decisions and confidence levels assigned to the first and second detection techniques, updating the confidence levels on the basis of the first, second and third decisions, and adapting, triggered on the basis of the obtained first, second and third decisions and of the updated confidence levels, at least one rule applied by the first and/or the second technique.

