Log Classification Device with Adaptive Clustering for Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies face challenges in detecting advanced persistent threats (APT) and other hacking methods, as they require manual analysis by experienced professionals, which is time-consuming and inefficient for large networks, making real-time detection of system anomalies or intrusion threats difficult.

Innovation Solution

An information security incident diagnosis system that includes an activities record collection device and a suspicious incident determination device, which collects and processes activity records to generate a discrete space metric tree, performs clustering, and creates a hierarchical directed acyclic graph (HDAG) to visually represent similar and differential features, aiding in the detection of intrusions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual analysis by experienced professionals is used, then detection accuracy is improved, but analysis time and productivity deteriorate

Engineering Contradiction:
Improvedetection accuracyVSAvoidanalysis efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent introduces an automated analysis system that acts as an intermediary between raw activity records and expert analysts. The system includes modules for automated clustering, pattern recognition, and anomaly detection that pre-process and organize data before presentation to analysts, thereby maintaining high detection accuracy while significantly reducing manual analysis time

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The analysis system segments the complex detection task into multiple independent modules: data collection, preprocessing, clustering analysis, pattern recognition, and result visualization. Each module handles specific aspects of the analysis, allowing parallel processing and reducing overall analysis time while maintaining comprehensive detection capability

Inventive Principle:
Principle #1Segmentation

2Reliability

If manual analysis methods are used for large networks, then comprehensive analysis is possible, but time cost becomes unpredictable and real-time detection becomes difficult

Engineering Contradiction:
Improvecomprehensive analysis capabilityVSAvoidanalysis time cost
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary automated analysis actions on activity records before they reach human analysts. It pre-clusters data, identifies potential anomalies, and prepares structured reports in advance, so that when analysts review the data, the most time-consuming processing has already been completed automatically

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameters of data representation and organization to enable faster processing. It transforms raw activity records into structured formats with standardized schemas, applies dimensionality reduction techniques, and uses configurable clustering parameters that can be adjusted based on network size and analysis requirements

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12081570B2Classification device with adaptive clustering function and related computer program product
Publication Date: 2024.09.03 CYCARRIER TECH CO LTD
  • US12081570B2 patent drawing
  • US12081570B2 patent drawing
  • US12081570B2 patent drawing

AI summary

The present invention provides a log classification system configured to perform a hierarchical similarity analysis operation according to a plurality of activities records to generate a discrete space metric tree, and perform a clustering operation on the discrete space metric tree to generate one or more event clusters associated with one or more suspicious event categories. The log classification system includes an output device configured to output the one or more event clusters to an information security incident diagnosis system, and allow the information security incident diagnosis system to calculate similar feature information and differential feature information of a plurality of activities records in the one or more event clusters as auxiliary information for diagnosing whether there are intrusions or abnormalities in a target network system.