Modular Time Difference Metrics for Security Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in detecting security-related activities, such as malware communication, due to inefficiencies in processing and storage requirements, particularly in identifying regular patterns amidst sporadic traffic and latency gaps.

Innovation Solution

A computing system employs a modulus operation on temporal data to compare time differences, allowing for real-time detection of security activities by analyzing the size of sets associated with modular results, which reduces storage needs and enhances pattern recognition resilience to gaps in activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional methods are used to detect periodic communications, then detection accuracy may be maintained, but processing efficiency decreases and storage requirements increase

Engineering Contradiction:
Improveprocessing efficiencyVSAvoiddetection accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent segments temporal data into discrete time buckets and organizes communications into sets based on time difference metrics. By dividing the detection process into modular components (time bucket selection, set organization, metric calculation), the system achieves both efficient processing and accurate detection of periodic patterns in malware communications.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If all temporal data is stored for analysis, then detection accuracy improves, but storage requirements increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidstorage requirements
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential temporal characteristics needed for detection by organizing communications into sets based on time difference metrics. Instead of storing all raw temporal data, the system extracts and stores only the relevant time-based patterns, significantly reducing storage requirements while maintaining detection accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

3Measurement precision

If complex processing algorithms are used, then detection accuracy improves, but processing efficiency decreases

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent changes the parameters of analysis by using time difference metrics and organizing data into sets based on these metrics. This parameter transformation simplifies the detection process while maintaining accuracy, as the system can efficiently calculate and compare time-based patterns without requiring complex algorithms.

Inventive Principle:
Principle #35Parameter changes

4Loss of time

If real-time detection is implemented, then response time improves, but processing complexity increases

Engineering Contradiction:
Improveresponse timeVSAvoidprocessing complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent performs preliminary organization of communications into sets based on time difference metrics before actual detection occurs. This preliminary action prepares the data in advance, allowing for efficient real-time detection without requiring complex processing during the actual detection event, thus reducing both response time and processing complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11394730B2Activity detection based on time difference metrics
Publication Date: 2022.07.19 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US11394730B2 patent drawing
  • US11394730B2 patent drawing
  • US11394730B2 patent drawing

AI summary

In some examples, a system determines a difference between a received time indication and a previous time indication, performs a modular arithmetic operation with respect to a first integer on the difference, and increments a count related to a first set associated with a first result of the modular arithmetic operation. The system compares respective counts associated with respective sets of a plurality of sets including the first set, wherein each set of the plurality of sets is associated with a different result of the modular arithmetic operation, and detects an occurrence of a security intrusion based on the comparison.