Infection Spread Attack Detection Using Traffic Clustering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for detecting infection-spreading attacks in networks struggle to accurately identify and specify the source terminal, as they cannot differentiate between normal and infected terminal traffic, leading to high analysis and network loads due to normal communication being bypassed to security devices.
Innovation Solution
An infection-spreading attack detection apparatus that uses feature value derivation, clustering, and terminal specification to identify and classify traffic patterns, limiting monitored address spaces based on initial feature values and performing clustering on secondary feature values to accurately detect and specify infected terminals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If all traffic is monitored and analyzed to detect infection-spreading attacks, then detection accuracy is improved, but network load and analysis processing load increase significantly
Solution Approach 1:
The patent segments the address space into multiple partial address spaces and further divides traffic into normal communication traffic and candidate attack traffic based on feature values. By analyzing only the candidate attack traffic identified through clustering of feature values, the system reduces the analysis processing load while maintaining detection accuracy.
Solution Approach 2:
The patent extracts and analyzes only the essential feature values from traffic data (such as packet counts, flow durations, and communication patterns) to identify candidate attack traffic. This extraction approach allows the system to focus analysis resources on the most suspicious traffic patterns rather than processing all traffic equally.
2Reliability
If normal communication traffic is included in security device analysis, then comprehensive monitoring is achieved, but unnecessary analysis processing is performed
Solution Approach 1:
The patent performs preliminary analysis of traffic feature values to identify candidate attack traffic before routing to security devices for detailed analysis. By pre-filtering traffic based on clustering of feature values, the system ensures that only traffic requiring security device analysis is forwarded, improving processing efficiency while maintaining monitoring coverage.
Solution Approach 2:
The patent introduces an intermediary analysis layer that processes feature values and identifies candidate attack traffic before the traffic reaches the security device. This intermediary layer acts as a filter that reduces the volume of traffic requiring detailed security analysis while maintaining comprehensive monitoring capability.
3Measurement precision
If traffic information is aggregated and vectorized for machine learning processing, then infection-spreading attack detection capability is improved, but computational resources are consumed
Solution Approach 1:
The patent applies machine learning processing selectively to aggregated and vectorized traffic information from partial address spaces rather than processing all traffic data. By focusing computational resources on the most relevant address spaces identified through feature value analysis, the system improves detection capability while reducing overall computational resource consumption.
Data Source
AI summary
An occurrence of an infection-spreading attack and an attack source thereof are detected with high accuracy. A first feature value is calculated based on traffic information regarding a packet forwarded by a forwarding device, and M partial address spaces to be monitored are specified based on the first feature value. A second feature value is calculated for each address of a terminal in a network, based on traffic information regarding the M partial address spaces, the second feature value is learned to classify terminal addresses into a plurality of clusters, and whether or not each of the clusters is an infection-spreading attack is determined to generate cluster information. Whether or not an infection-spreading attack has occurred and an address of a terminal that is an attack source are specified based on the second feature value and the cluster information.


