Modular Time Difference Metrics for Security Intrusion Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in detecting security-related activities, such as malware communication, due to inefficiencies in processing and storage requirements, particularly in identifying regular patterns amidst sporadic traffic and latency gaps.
Innovation Solution
A computing system employs a modulus operation on temporal data to compare time differences, allowing for real-time detection of security activities by analyzing the size of sets associated with modular results, which reduces storage needs and enhances pattern recognition resilience to gaps in activity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If traditional methods are used to detect periodic communications, then detection accuracy may be maintained, but processing efficiency decreases and storage requirements increase
Solution Approach 1:
The patent segments temporal data into discrete time buckets and organizes communications into sets based on time difference metrics. By dividing the detection process into modular components (time bucket selection, set organization, metric calculation), the system achieves both efficient processing and accurate detection of periodic patterns in malware communications.
2Measurement precision
If all temporal data is stored for analysis, then detection accuracy improves, but storage requirements increase
Solution Approach 1:
The patent extracts only the essential temporal characteristics needed for detection by organizing communications into sets based on time difference metrics. Instead of storing all raw temporal data, the system extracts and stores only the relevant time-based patterns, significantly reducing storage requirements while maintaining detection accuracy.
3Measurement precision
If complex processing algorithms are used, then detection accuracy improves, but processing efficiency decreases
Solution Approach 1:
The patent changes the parameters of analysis by using time difference metrics and organizing data into sets based on these metrics. This parameter transformation simplifies the detection process while maintaining accuracy, as the system can efficiently calculate and compare time-based patterns without requiring complex algorithms.
4Loss of time
If real-time detection is implemented, then response time improves, but processing complexity increases
Solution Approach 1:
The patent performs preliminary organization of communications into sets based on time difference metrics before actual detection occurs. This preliminary action prepares the data in advance, allowing for efficient real-time detection without requiring complex processing during the actual detection event, thus reducing both response time and processing complexity.
Data Source
AI summary
In some examples, a system determines a difference between a received time indication and a previous time indication, performs a modular arithmetic operation with respect to a first integer on the difference, and increments a count related to a first set associated with a first result of the modular arithmetic operation. The system compares respective counts associated with respective sets of a plurality of sets including the first set, wherein each set of the plurality of sets is associated with a different result of the modular arithmetic operation, and detects an occurrence of a security intrusion based on the comparison.


