Intrusion Detection System Using Keyword Tree Classification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing intrusion detection systems face inefficiencies due to high false positive rates and long analysis times, which deteriorate detection performance and require manual optimization of detection rules, failing to accurately classify true positives and false positives in network environments.
Innovation Solution
An apparatus and method that transform detected data into a standardized format, classify it by attack type, and generate true and false positive keyword trees to identify true positive paths, creating new detection patterns and rules that optimize the true positive rate and reduce false positives.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If detection rules are increased to improve detection rate, then true positive detection improves, but false positive rate increases and analysis time increases
Solution Approach 1:
The patent segments detection events into true positive and false positive categories using keyword trees. By dividing the detection rule set into different keyword trees based on attack types and patterns, the system can selectively analyze only relevant events rather than processing all detection events, thereby reducing analysis time while maintaining high detection rates.
Solution Approach 2:
The patent changes the parameter of detection rule representation by transforming detection rules into keyword trees with specific structures (including attack type, protocol, and pattern information). This transformation enables efficient classification and filtering of detection events, allowing the system to quickly identify true positives without manually analyzing every event.
2Measurement precision
If manual analysis of detection events is performed to improve accuracy, then true positive identification improves, but task efficiency deteriorates
Solution Approach 1:
The patent implements self-service by enabling the system to automatically classify and identify true positive events through keyword tree matching. The detection system serves itself by using the structured keyword trees to automatically distinguish true positives from false positives without requiring manual analyst intervention for each event, thereby maintaining high accuracy while improving efficiency.
Solution Approach 2:
The patent uses feedback mechanisms where the results of keyword tree matching and event classification are fed back to continuously optimize detection rules. The system learns from classified events and automatically adjusts detection parameters, reducing the need for manual analysis while maintaining or improving identification accuracy over time.
3Reliability
If detection rules are optimized to reduce false positives, then false positive rate decreases, but detection rule complexity increases
Solution Approach 1:
The patent adds another dimension to detection rule organization by introducing keyword trees that incorporate multiple attributes (attack type, protocol, pattern) beyond traditional detection rules. This dimensional expansion allows the system to reduce false positives through multi-criteria matching while managing complexity through hierarchical organization rather than increasing individual rule complexity.
Solution Approach 2:
The patent performs preliminary action by pre-processing detection rules into keyword tree structures before actual detection operations. This preliminary organization of detection rules into hierarchical trees with attack types and patterns enables efficient false positive reduction during runtime without increasing the complexity of individual detection rules, as the complexity is managed in the pre-processed structure.
Data Source
AI summary
An apparatus for improving detection performance of an intrusion detection system includes a transformed detected data generation unit for changing original detected data, detected based on current detection rules, to transformed detected data complying with transformed detected data standard. A transformed detected data classification unit classifies the transformed detected data by attack type, classifies transformed detected data for attack types by current detection rule, and classifies transformed detected data for detection rules into true positives/false positives. A transformed keyword tree generation unit generates a true positive transformed keyword tree and a false positive transformed keyword tree. A true positive path identification unit generates a true positive node, and identifies a true positive path connecting a base node to the true positive node in the true positive transformed keyword tree. A true positive detection pattern generation unit generates a true positive detection pattern based on the true positive path.


