Infection-Spreading Attack Detection via Partial Address Space Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional infection-spreading attack detection systems are prone to frequent erroneous detections due to noise in address spaces with low traffic, leading to increased security device utilization and false alarms.

Innovation Solution

An infection-spreading attack detection system that narrows down monitoring targets to specific partial address spaces based on derived feature amounts, using a first feature amount derivation unit and a monitoring target determination unit to identify M partial address spaces with low traffic, and a detection unit to evaluate second feature amounts for accurate detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the system monitors all partial address spaces to detect infection-spreading attacks, then detection coverage is improved, but erroneous detections increase due to noise in low-traffic address spaces

Engineering Contradiction:
Improvedetection accuracyVSAvoidfalse alarm rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments the address space into multiple partial address spaces and further classifies them into high-traffic and low-traffic groups. By monitoring only the low-traffic partial address spaces (which are more susceptible to infection-spreading attacks) rather than all address spaces uniformly, the system reduces false alarms from noise while maintaining detection coverage for critical areas.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different monitoring strategies to different parts of the address space based on their traffic characteristics. Low-traffic partial address spaces are prioritized for monitoring because they are more indicative of infection-spreading attacks, while high-traffic spaces are monitored less intensively, optimizing the balance between detection accuracy and false alarm reduction.

Inventive Principle:
Principle #3Local quality

2Reliability

If the system monitors low-traffic address spaces to detect attacks, then detection sensitivity is improved, but noise from normal communications causes false alarms

Engineering Contradiction:
Improveattack detection sensitivityVSAvoidfalse alarm rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent performs preliminary classification of partial address spaces into high-traffic and low-traffic groups before monitoring. By pre-identifying which address spaces are likely to contain infection-spreading attacks based on traffic characteristics, the system can focus monitoring resources appropriately and reduce false alarms from normal communications in high-traffic spaces.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the monitoring parameter from uniform monitoring of all address spaces to selective monitoring based on traffic volume characteristics. By using traffic amount as a classification parameter, the system adjusts its monitoring behavior to focus on low-traffic address spaces where infection-spreading attacks are more likely to manifest as anomalies.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If the system increases monitoring coverage to reduce false alarms, then detection accuracy is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the monitoring task into two stages: first classifying partial address spaces by traffic amount, then monitoring only the low-traffic spaces for infection-spreading attacks. This segmentation reduces the effective monitoring scope while maintaining high detection accuracy, thereby reducing system complexity and resource consumption compared to monitoring all address spaces uniformly.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial monitoring to the most critical areas (low-traffic partial address spaces) rather than attempting to monitor all address spaces with equal intensity. This partial action approach achieves sufficient detection accuracy for infection-spreading attacks while significantly reducing the complexity and resource requirements of the monitoring system.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11895146B2Infection-spreading attack detection system and method, and program
Publication Date: 2024.02.06 NIPPON TELEGRAPH & TELEPHONE CORP
  • US11895146B2 patent drawing
  • US11895146B2 patent drawing
  • US11895146B2 patent drawing

AI summary

Provided is an infection-spreading attack detection system and method, as well as a program enabling an occurrence of an infection-spreading attack to be detected with high accuracy. A first feature amount is calculated based on traffic information on a packet transferred by a transfer device, and M partial address space(s) are identified to be a monitoring target based on the first feature amount. A second feature amount is calculated for each of the M partial address space(s) based on the traffic information related to the M partial address space(s). Abnormality detection determination is performed on each of the M partial address space(s) based on the second feature amount. Whether the infection-spreading attack has occurred is determined by evaluating M determination results.