Cyber Attack Detection Device Using Hybrid Anomaly and Signature Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber attack detection techniques in 5G mobile networks face challenges in accurately distinguishing between known and unknown attacks, often resulting in high false positive rates and vulnerability to attacks targeting detection modules themselves.

Innovation Solution

A method that combines decisions from multiple detection techniques, updating confidence levels based on cross-validation, and dynamically adapting rules using a trusted third detection technique, potentially reinforced through machine learning, to enhance detection accuracy and reliability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If signature-based detection is used to detect known attacks, then false positive rate is reduced, but only known attacks can be detected

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection coverage
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent combines signature-based detection and anomaly-based detection into a unified hybrid detection framework. The system integrates both approaches by having anomaly detection identify potential threats and signature detection verify them, thereby maintaining high detection accuracy for known attacks while improving detection coverage for unknown attacks through the anomaly detection component.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a decision module as an intermediary that coordinates between anomaly detection and signature detection. This mediator evaluates outputs from both detection methods, resolves conflicts, and makes final detection decisions, allowing the system to leverage the strengths of both approaches while mitigating their individual weaknesses.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If anomaly detection is used to detect new attacks, then new attacks can be detected, but false positive rate increases

Engineering Contradiction:
Improvedetection coverageVSAvoidfalse positive rate
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent merges anomaly detection with signature detection in a hybrid framework where anomaly detection serves as a screening mechanism. By combining both approaches, the system maintains the ability to detect new attacks through anomaly detection while using signature detection to verify suspicious patterns, thereby reducing false positives.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements feedback mechanisms where detection results from both anomaly and signature detection are fed into a decision module. This feedback loop allows the system to learn from detection outcomes, adjust detection thresholds, and refine the anomaly detection model over time, progressively reducing false positive rates while maintaining detection coverage.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If hybrid detection technique combining anomaly and signature detection is used, then detection rate and accuracy improve, but vulnerability to attacks on detection modules increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidrobustness to attacks
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent segments the detection system into multiple independent detection modules (anomaly detection, signature detection, decision module) that operate semi-independently. This segmentation ensures that an attack targeting one module does not compromise the entire system, as other modules can continue functioning and provide redundant detection capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The decision module acts as an intermediary layer that protects the detection system from attacks. It validates and coordinates outputs from anomaly and signature detection modules, implementing consistency checks and confidence threshold validations that prevent malicious inputs from triggering false detections or bypassing security measures.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If multiple detection techniques are combined with confidence level updating, then detection reliability improves, but system complexity increases

Engineering Contradiction:
Improvedetection reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs feedback mechanisms where detection results and confidence levels are continuously updated based on outcomes from multiple detection techniques. This feedback loop allows the system to dynamically adjust confidence levels and detection thresholds, improving reliability through adaptive learning while using automated algorithms to manage complexity rather than manual configuration.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent dynamically changes parameters such as confidence levels and detection thresholds based on system state and detection outcomes. By automatically adjusting these parameters through mathematical models and learning algorithms, the system improves reliability through adaptability while avoiding the complexity of manual parameter tuning and system configuration.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11936665B2Method for monitoring data transiting via a user equipment
Publication Date: 2024.03.19 ORANGE SA
  • US11936665B2 patent drawing
  • US11936665B2 patent drawing

AI summary

A method for monitoring data transiting via a user equipment is described, as well as a cyber attack detection device, The method includes obtaining a first decision from a first cyber attack detection technique and a second decision from a second cyber attack detection technique, indicating whether the data are associated with attack traffic, obtaining a third decision from a third cyber attack detection technique indicating whether the data are associated with attack traffic, the third technique the first and second decisions and confidence levels assigned to the first and second detection techniques, updating the confidence levels on the basis of the first, second and third decisions, and adapting, triggered on the basis of the obtained first, second and third decisions and of the updated confidence levels, at least one rule applied by the first and/or the second technique.