Log Classification Device with Adaptive Clustering for Intrusion Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies face challenges in detecting advanced persistent threats (APT) and other hacking methods, as they require manual analysis by experienced professionals, which is time-consuming and inefficient for large networks, making real-time detection of system anomalies or intrusion threats difficult.
Innovation Solution
An information security incident diagnosis system that includes an activities record collection device and a suspicious incident determination device, which collects and processes activity records to generate a discrete space metric tree, performs clustering, and creates a hierarchical directed acyclic graph (HDAG) to visually represent similar and differential features, aiding in the detection of intrusions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual analysis by experienced professionals is used, then detection accuracy is improved, but analysis time and productivity deteriorate
Solution Approach 1:
The patent introduces an automated analysis system that acts as an intermediary between raw activity records and expert analysts. The system includes modules for automated clustering, pattern recognition, and anomaly detection that pre-process and organize data before presentation to analysts, thereby maintaining high detection accuracy while significantly reducing manual analysis time
Solution Approach 2:
The analysis system segments the complex detection task into multiple independent modules: data collection, preprocessing, clustering analysis, pattern recognition, and result visualization. Each module handles specific aspects of the analysis, allowing parallel processing and reducing overall analysis time while maintaining comprehensive detection capability
2Reliability
If manual analysis methods are used for large networks, then comprehensive analysis is possible, but time cost becomes unpredictable and real-time detection becomes difficult
Solution Approach 1:
The system performs preliminary automated analysis actions on activity records before they reach human analysts. It pre-clusters data, identifies potential anomalies, and prepares structured reports in advance, so that when analysts review the data, the most time-consuming processing has already been completed automatically
Solution Approach 2:
The patent changes the parameters of data representation and organization to enable faster processing. It transforms raw activity records into structured formats with standardized schemas, applies dimensionality reduction techniques, and uses configurable clustering parameters that can be adjusted based on network size and analysis requirements
Data Source
AI summary
The present invention provides a log classification system configured to perform a hierarchical similarity analysis operation according to a plurality of activities records to generate a discrete space metric tree, and perform a clustering operation on the discrete space metric tree to generate one or more event clusters associated with one or more suspicious event categories. The log classification system includes an output device configured to output the one or more event clusters to an information security incident diagnosis system, and allow the information security incident diagnosis system to calculate similar feature information and differential feature information of a plurality of activities records in the one or more event clusters as auxiliary information for diagnosing whether there are intrusions or abnormalities in a target network system.


