N Grouping Traffic Analysis for Unknown Worm Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional intrusion detection systems are inadequate in detecting newly generated or modified worms, as they rely on pattern-based methods, which fail to recognize unknown or pattern-free attacks, leading to delayed detection and response.

Innovation Solution

The N grouping of traffic method categorizes traffic factors into groups using neural networks, allowing for quantitative analysis and visualization of network damage, enabling early detection and response to new or modified worms by predicting danger levels and implementing corresponding countermeasures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If pattern-based detection is used, then detection simplicity and accuracy for known worms is improved, but detection capability for new or modified worms deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection capability for new worms
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

Instead of detecting worms by their attack patterns (cause-based approach), the invention detects worms by analyzing the results they produce (effect-based approach). The system monitors network traffic and system states for anomalies caused by worm infections, such as unusual connection patterns, resource consumption, or protocol violations, rather than searching for specific worm code signatures.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The invention replaces the mechanical pattern-matching system with an intelligent analysis system using neural networks and machine learning algorithms. The system automatically learns normal network behavior patterns and detects deviations, enabling adaptive detection of new worm variants without requiring predefined signatures.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If pattern-free detection technique is used, then detection capability for unknown attacks is improved, but false detection of normal patterns as attacks increases

Engineering Contradiction:
Improvedetection capability for unknown attacksVSAvoidfalse alarm rate
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system continuously monitors network traffic and compares observed patterns against learned normal behavior models. When anomalies are detected, the system provides feedback to refine the models and adjust detection thresholds, reducing false alarms while maintaining high detection accuracy for actual attacks.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The invention dynamically adjusts detection parameters and anomaly thresholds based on network conditions and learned patterns. The system adapts its sensitivity levels and detection criteria over time, allowing it to distinguish between normal variations and actual attacks more accurately.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If conventional intrusion detection systems are used, then ease of operation is improved, but response time for new worm attacks deteriorates

Engineering Contradiction:
Improvesystem simplicityVSAvoidresponse time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary analysis of network traffic patterns and system states continuously, even before full-scale worm attacks occur. By monitoring for early signs of infection and anomalous behavior, the system can detect and respond to new worm attacks in their initial stages, significantly reducing response time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The intrusion detection system automatically performs analysis, detection, and response actions without requiring manual intervention. The system self-adjusts its detection parameters, automatically updates its models based on observed behavior, and executes countermeasures autonomously, maintaining operational simplicity while enabling rapid response.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7779467B2N grouping of traffic and pattern-free internet worm response system and method using N grouping of traffic
Publication Date: 2010.08.17 ELECTRONICS & TELECOMM RES INST
  • US7779467B2 patent drawing
  • US7779467B2 patent drawing
  • US7779467B2 patent drawing

AI summary

Provided are N grouping of traffic and pattern-free Internet worm response system and method. According to the method, traffic factors generated by respective worms are grouped into N groups so that a great quantity of Information may be effectively understood and a worm generated afterward is involved with characteristics of a relevant group. Damages of a network or a system predictable through already classified N traffic characteristics are defined so that corresponding step-by-step measures are taken. Characteristics of the grouped worms are quantitatively analyzed so that a danger degree of a new worm is predicted when the new worm appears afterward and forecasting and alarming through the prediction are performed. Easiness with which a controlling operator instantly understands an accident using a visualization method having an approximate real-time characteristic is increased, so that detection efficiency for most worms not detected using a conventional rule is increased.