Infection-Spreading Attack Detection via Partial Address Space Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional infection-spreading attack detection systems are prone to frequent erroneous detections due to noise in address spaces with low traffic, leading to increased security device utilization and false alarms.
Innovation Solution
An infection-spreading attack detection system that narrows down monitoring targets to specific partial address spaces based on derived feature amounts, using a first feature amount derivation unit and a monitoring target determination unit to identify M partial address spaces with low traffic, and a detection unit to evaluate second feature amounts for accurate detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the system monitors all partial address spaces to detect infection-spreading attacks, then detection coverage is improved, but erroneous detections increase due to noise in low-traffic address spaces
Solution Approach 1:
The patent segments the address space into multiple partial address spaces and further classifies them into high-traffic and low-traffic groups. By monitoring only the low-traffic partial address spaces (which are more susceptible to infection-spreading attacks) rather than all address spaces uniformly, the system reduces false alarms from noise while maintaining detection coverage for critical areas.
Solution Approach 2:
The patent applies different monitoring strategies to different parts of the address space based on their traffic characteristics. Low-traffic partial address spaces are prioritized for monitoring because they are more indicative of infection-spreading attacks, while high-traffic spaces are monitored less intensively, optimizing the balance between detection accuracy and false alarm reduction.
2Reliability
If the system monitors low-traffic address spaces to detect attacks, then detection sensitivity is improved, but noise from normal communications causes false alarms
Solution Approach 1:
The patent performs preliminary classification of partial address spaces into high-traffic and low-traffic groups before monitoring. By pre-identifying which address spaces are likely to contain infection-spreading attacks based on traffic characteristics, the system can focus monitoring resources appropriately and reduce false alarms from normal communications in high-traffic spaces.
Solution Approach 2:
The patent changes the monitoring parameter from uniform monitoring of all address spaces to selective monitoring based on traffic volume characteristics. By using traffic amount as a classification parameter, the system adjusts its monitoring behavior to focus on low-traffic address spaces where infection-spreading attacks are more likely to manifest as anomalies.
3Reliability
If the system increases monitoring coverage to reduce false alarms, then detection accuracy is improved, but system complexity and resource consumption increase
Solution Approach 1:
The patent segments the monitoring task into two stages: first classifying partial address spaces by traffic amount, then monitoring only the low-traffic spaces for infection-spreading attacks. This segmentation reduces the effective monitoring scope while maintaining high detection accuracy, thereby reducing system complexity and resource consumption compared to monitoring all address spaces uniformly.
Solution Approach 2:
The patent applies partial monitoring to the most critical areas (low-traffic partial address spaces) rather than attempting to monitor all address spaces with equal intensity. This partial action approach achieves sufficient detection accuracy for infection-spreading attacks while significantly reducing the complexity and resource requirements of the monitoring system.
Data Source
AI summary
Provided is an infection-spreading attack detection system and method, as well as a program enabling an occurrence of an infection-spreading attack to be detected with high accuracy. A first feature amount is calculated based on traffic information on a packet transferred by a transfer device, and M partial address space(s) are identified to be a monitoring target based on the first feature amount. A second feature amount is calculated for each of the M partial address space(s) based on the traffic information related to the M partial address space(s). Abnormality detection determination is performed on each of the M partial address space(s) based on the second feature amount. Whether the infection-spreading attack has occurred is determined by evaluating M determination results.


