Infection Spread Attack Detection Using Traffic Clustering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for detecting infection-spreading attacks in networks struggle to accurately identify and specify the source terminal, as they cannot differentiate between normal and infected terminal traffic, leading to high analysis and network loads due to normal communication being bypassed to security devices.

Innovation Solution

An infection-spreading attack detection apparatus that uses feature value derivation, clustering, and terminal specification to identify and classify traffic patterns, limiting monitored address spaces based on initial feature values and performing clustering on secondary feature values to accurately detect and specify infected terminals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If all traffic is monitored and analyzed to detect infection-spreading attacks, then detection accuracy is improved, but network load and analysis processing load increase significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoidnetwork load and analysis processing load
Core Design Contradiction:
Measurement precisionVSPower

Solution Approach 1:

The patent segments the address space into multiple partial address spaces and further divides traffic into normal communication traffic and candidate attack traffic based on feature values. By analyzing only the candidate attack traffic identified through clustering of feature values, the system reduces the analysis processing load while maintaining detection accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts and analyzes only the essential feature values from traffic data (such as packet counts, flow durations, and communication patterns) to identify candidate attack traffic. This extraction approach allows the system to focus analysis resources on the most suspicious traffic patterns rather than processing all traffic equally.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If normal communication traffic is included in security device analysis, then comprehensive monitoring is achieved, but unnecessary analysis processing is performed

Engineering Contradiction:
Improvemonitoring coverageVSAvoidanalysis processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs preliminary analysis of traffic feature values to identify candidate attack traffic before routing to security devices for detailed analysis. By pre-filtering traffic based on clustering of feature values, the system ensures that only traffic requiring security device analysis is forwarded, improving processing efficiency while maintaining monitoring coverage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary analysis layer that processes feature values and identifies candidate attack traffic before the traffic reaches the security device. This intermediary layer acts as a filter that reduces the volume of traffic requiring detailed security analysis while maintaining comprehensive monitoring capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If traffic information is aggregated and vectorized for machine learning processing, then infection-spreading attack detection capability is improved, but computational resources are consumed

Engineering Contradiction:
Improveinfection-spreading attack detection capabilityVSAvoidcomputational resources
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent applies machine learning processing selectively to aggregated and vectorized traffic information from partial address spaces rather than processing all traffic data. By focusing computational resources on the most relevant address spaces identified through feature value analysis, the system improves detection capability while reducing overall computational resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11863584B2Infection spread attack detection device, attack origin specification method, and program
Publication Date: 2024.01.02 NIPPON TELEGRAPH & TELEPHONE CORP
  • US11863584B2 patent drawing
  • US11863584B2 patent drawing
  • US11863584B2 patent drawing

AI summary

An occurrence of an infection-spreading attack and an attack source thereof are detected with high accuracy. A first feature value is calculated based on traffic information regarding a packet forwarded by a forwarding device, and M partial address spaces to be monitored are specified based on the first feature value. A second feature value is calculated for each address of a terminal in a network, based on traffic information regarding the M partial address spaces, the second feature value is learned to classify terminal addresses into a plurality of clusters, and whether or not each of the clusters is an infection-spreading attack is determined to generate cluster information. Whether or not an infection-spreading attack has occurred and an address of a terminal that is an attack source are specified based on the second feature value and the cluster information.