Network Anomaly Detection Using Individual and Association Rules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting abnormal behavior in networks are limited by the need for extensive learning data in anomaly detection and fail to effectively handle complex and diversified network behaviors across various analysis scenarios, especially when using individual and association rules with hierarchical relationships.
Innovation Solution
A method and apparatus that utilize a combination of individual and association rules to extract output data from input datasets, determining abnormal behavior based on threshold conditions such as attribute values, extraction times, and relevance, specifically addressing behaviors like unauthorized eavesdropping, firmware attacks, and stealth scanning by applying rules for extracting specific data and network session analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If anomaly detection method using statistical data is used to detect unknown behaviors, then detection capability for unknown behaviors is improved, but large amount of learning data is required
Solution Approach 1:
The patent segments the detection process into multiple independent rule modules (individual rules and association rules), each handling specific detection tasks. This segmentation allows the system to detect abnormal behaviors without requiring a single large learning dataset, as each rule can be independently configured and executed based on specific detection needs.
Solution Approach 2:
The patent performs preliminary action by pre-defining individual rules and association rules based on known attack patterns and behavioral characteristics. These rules are prepared in advance and can be directly applied to detect abnormal behaviors without requiring extensive real-time learning data collection and processing.
2Measurement precision
If misuse detection method with known attack patterns is used, then detection accuracy for known attacks is improved, but inability to detect unknown behaviors occurs
Solution Approach 1:
The patent creates a universal detection framework that combines both misuse detection (individual rules matching known patterns) and anomaly detection (association rules detecting behavioral deviations). This multi-functional system can simultaneously detect known attack patterns and unknown abnormal behaviors, achieving both high accuracy for known attacks and broad adaptability for various detection scenarios.
Solution Approach 2:
The patent introduces association rules as an intermediary mechanism that bridges misuse detection and anomaly detection. Association rules analyze relationships between multiple individual rule outputs and detect abnormal behaviors that may not match specific known patterns, thereby extending detection capability to unknown threats while maintaining the precision of pattern-matching approaches.
3Reliability
If multiple individual rules and association rules are combined for detection, then detection comprehensiveness is improved, but system complexity increases
Solution Approach 1:
The patent segments the rule system into hierarchical layers: individual rules that extract specific features from input data, and association rules that analyze relationships between individual rule outputs. This segmentation organizes the complexity into manageable modules with clear interfaces, making the system easier to configure, maintain, and extend while achieving comprehensive detection coverage.
Solution Approach 2:
The patent implements partial action by allowing selective activation of individual rules and association rules based on specific detection scenarios and requirements. Users can configure and enable only the necessary rules for each detection task, avoiding the need to deploy and manage all possible rules simultaneously, thereby reducing operational complexity while maintaining comprehensive detection capability when needed.
Data Source
AI summary
Provided is a method performed by a computing device for detecting abnormal behavior in a network. The method comprises obtaining a plurality of individual rules, wherein an individual rule of the plurality of individual rules is for extracting first output data from at least one input data set among a plurality of input data sets, the first output data satisfying a first extraction condition, obtaining a plurality of association rules, wherein an association rule of the plurality of association rules is for extracting second output data from at least one of the plurality of input data sets and the first output data, the second output data satisfying a second extraction condition and detecting abnormal behavior in a network based on third output data, the third output data being extracted using one of the plurality of individual rules and the plurality of association rules.


