Unauthorized Intrusion Analysis Using Field-Specific Relevance Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IoT security information management systems fail to accurately classify cyber information by field, leading to potential misclassification due to the use of keywords common across multiple fields, which can result in inappropriate utilization of security information by specialists in specific domains.
Innovation Solution
An unauthorized intrusion analysis support apparatus and method that utilizes field-specific keyword databases and attack case databases to calculate relevance degrees and exclude irrelevant keywords, ensuring that security information is classified and analyzed within the appropriate field context.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If keyword-based classification is used to categorize security information, then classification speed is improved, but classification accuracy deteriorates due to keyword ambiguity across multiple fields
Solution Approach 1:
The patent segments the classification process into multiple stages: initial keyword-based filtering followed by field-specific relevance evaluation. This multi-stage segmentation allows the system to maintain high processing speed while improving accuracy by eliminating ambiguous keywords through field-specific context analysis.
Solution Approach 2:
The patent introduces field-specific dictionaries and relevance evaluation mechanisms as intermediary layers between keyword matching and final classification. These intermediaries resolve keyword ambiguity by evaluating whether matched keywords are actually relevant to the specific field context, thereby improving classification accuracy without sacrificing speed.
2Measurement precision
If field-specific classification is implemented to improve accuracy, then system complexity increases due to multiple field-specific databases and evaluation mechanisms
Solution Approach 1:
The system segments classification functionality into modular field-specific dictionaries and evaluation modules. Each field has its own dictionary and relevance evaluation logic, allowing independent development and maintenance. This modular segmentation manages complexity by organizing field-specific mechanisms as separate, manageable units rather than a monolithic system.
Solution Approach 2:
The patent implements a universal classification framework that handles multiple fields through common infrastructure (keyword extraction, relevance scoring, threshold evaluation). While field-specific dictionaries provide specialized knowledge, the overall system architecture remains universal and reusable across different fields, preventing complexity from scaling linearly with the number of fields.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An unauthorized intrusion analysis support apparatus is configured to receive an input of a field related to an unauthorized intrusion; is configured to extract at least one word in the inputted field relevant to the unauthorized intrusion to an apparatus comnunicably coupled to a predetermined network from a text relevant to the unauthorized intrusion to the apparatus; is configured to calculate a relevance degree between the extracted word and a mode of the unauthorized intrusion based on the extracted word and information on a word of the mode of the unauthorized intrusion in the inputted field and assume that the text is a text about the unauthorized intrusion in the inputted field when the calculated relevance degree is equal to or higher than a predetermined threshold; and is configured to output information indicating that the text is the text about the unauthorized intrusion in a user field.