Hybrid Intrusion Detection System for Cyber Threat Intelligence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intrusion detection and prevention systems (IDS/IPS) generate excessive false alarms, require costly and time-consuming rule updates, and lack real-time protection, with no commercially available hybrid packet and flow-based approaches, limiting their effectiveness in detecting and preventing cyber threats.

Innovation Solution

A hybrid IDS/IPS apparatus and method integrating flow-based and packet-based machine learning techniques, featuring a network interface, feature extraction and selection models, intrusion detection modules, and an intrusion prevention module (IPM) for near real-time rule generation and optimization, enabling robust network threat detection and prevention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If traditional packet-based IDS/IPS is used for real-time intrusion detection, then real-time protection is provided, but certain cyber-attacks cannot be detected

Engineering Contradiction:
Improvereal-time detection speedVSAvoiddetection accuracy
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent combines packet-based IDS/IPS for real-time detection with flow-based IDS/IPS for comprehensive attack detection. The hybrid architecture merges the speed advantages of packet-based systems with the detection capabilities of flow-based systems, allowing both real-time protection and accurate identification of complex cyber-attacks that require flow analysis

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If flow-based IDS/IPS is used for comprehensive attack detection, then all types of attacks can be detected, but real-time protection cannot be provided

Engineering Contradiction:
Improvedetection accuracyVSAvoidreal-time detection speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The system integrates flow-based detection capabilities with packet-based real-time processing. Flow-based analysis is used to detect complex attacks requiring comprehensive traffic patterns, while packet-based processing handles real-time threats, creating a balanced hybrid system that achieves both comprehensive detection and real-time protection

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If more rules are added to IPS to improve detection coverage, then detection performance improves initially, but detection performance degrades over time due to rule complexity

Engineering Contradiction:
Improvedetection coverageVSAvoidrule complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional rule-based IPS mechanisms with machine learning models. Instead of manually adding and managing complex security rules, the system uses trained ML models that automatically learn attack patterns from data, eliminating the need for continuous rule updates and manual assessment while maintaining high detection coverage

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The machine learning models perform self-training and self-optimization by automatically learning from new attack patterns and traffic data. The system self-adjusts its detection capabilities without requiring external rule updates or manual intervention, maintaining optimal performance over time without accumulating complexity

Inventive Principle:
Principle #25Self-service

4Reliability

If IDS/IPS is deployed as network gateway for single network environment, then protection is provided for that specific network, but the system lacks adaptability to different network environments

Engineering Contradiction:
Improveprotection effectivenessVSAvoidnetwork environment adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The machine learning-based IDS/IPS is designed to be environment-agnostic, training models on diverse network traffic data that encompasses multiple network types and configurations. This allows the same system to be deployed across different network environments (enterprise, cloud, IoT, etc.) without requiring environment-specific customization, achieving universal applicability while maintaining effective protection

Inventive Principle:
Principle #6Universality (Multi-functionality)

5Extent of automation

If machine learning models are used for intrusion detection, then intelligent detection and near real-time processing are achieved, but system complexity increases

Engineering Contradiction:
Improveintelligent detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The patent replaces complex manual rule management and expert assessment with automated machine learning models. The ML models automatically perform feature extraction, pattern recognition, and threat classification, eliminating the need for security analysts to manually assess and update detection rules, thereby achieving intelligent automation while managing system complexity through algorithmic efficiency

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250106185A1Apparatus and method for intrusion detection and prevention of cyber threat intelligence
Publication Date: 2025.03.27 HONG KONG APPLIED SCI & TECH RES INST
  • US20250106185A1 patent drawing
  • US20250106185A1 patent drawing
  • US20250106185A1 patent drawing

AI summary

An apparatus for intrusion detection and prevention of cyber threat intelligence is provided. The apparatus includes a feature extraction model, a feature selection model, a flow-based intrusion detection module, a packet-based intrusion detection module, and an IPM. The feature extraction model is configured to parse packets from network raw packet data into sessions as a network flow dataset. The feature selection model is configured to select flow-based features from the network flow dataset to generate network flow meta. The flow-based intrusion detection module is configured to generate flow-based labels. The packet-based intrusion detection module is configured to generate packet-based labels. The IPM is configured to perform intrusion analysis according to the flow-based labels and the packet-based labels so as to generate IPM rules for intrusion detection and prevention, thereby identifying and processing the network raw packet data.