Network Attack Detection Using Dynamic Reception Range Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network attack detection systems face challenges in accurately identifying frames used for attacks, particularly when both periodic and aperiodic messages are transmitted, as they often misidentify messages based on transmission cycles, leading to erroneous detection of attacks.

Innovation Solution

An attack detection device that utilizes a transceiver and processor to calculate reception ranges for periodic messages, updating these ranges based on the reception time of messages with a short interval flag, allowing for accurate differentiation between normal and attack frames by predicting the reception time of subsequent messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a method verifies a specific identifier in a data frame when transmission cycle compliance is checked, then attack detection capability is improved, but false identification of periodic messages as attacks increases

Engineering Contradiction:
Improveattack detection capabilityVSAvoidfalse identification rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments the message stream into periodic and aperiodic components by introducing a short interval flag. This flag distinguishes messages transmitted at intervals shorter than the nominal transmission cycle, allowing the system to separately handle periodic messages (which follow the cycle) and aperiodic messages (which may have short intervals). This segmentation resolves the contradiction by enabling accurate attack detection on aperiodic messages without falsely flagging periodic messages.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent dynamically adjusts the transmission cycle reference based on the short interval flag. When an aperiodic message with a short interval is detected, the system updates the transmission cycle timing reference to accommodate this message. This dynamic adjustment allows the system to adapt to varying message patterns while maintaining accurate attack detection, preventing false identification of subsequent periodic messages as attacks.

Inventive Principle:
Principle #15Dynamics

2Measurement precision

If periodic messages are used as reference for transmission cycle verification, then detection accuracy is improved, but system adaptability to aperiodic messages deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem adaptability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent makes the transmission cycle reference dynamic by allowing it to be updated when aperiodic messages with short intervals are detected. The short interval flag triggers a recalculation of the transmission cycle timing, enabling the system to adapt to changing message patterns while maintaining detection accuracy for both periodic and aperiodic messages.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the timing parameters of the transmission cycle based on the short interval flag. When an aperiodic message is detected, the system adjusts the reference timing for subsequent messages, effectively changing the parameter used for cycle verification. This allows the system to maintain high detection accuracy while being adaptable to different message transmission patterns.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If attack detection is performed on all received frames, then security monitoring is improved, but computational overhead and false positives increase

Engineering Contradiction:
Improvesecurity monitoringVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments messages into periodic and aperiodic categories using the short interval flag. This segmentation allows the system to apply different detection strategies: periodic messages are monitored for timing compliance, while aperiodic messages are flagged for more intensive inspection. This reduces computational overhead by avoiding unnecessary verification on routine periodic messages while maintaining strong security monitoring on potentially malicious aperiodic messages.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial verification to periodic messages (checking timing against the established cycle) and more thorough verification to aperiodic messages (flagged by the short interval indicator). This differentiated approach reduces overall computational overhead compared to exhaustive verification of all messages, while still maintaining high security monitoring through targeted inspection of suspicious aperiodic messages.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10567401B2Device and method for detecting attack in network
Publication Date: 2020.02.18 FUJITSU LTD
  • US10567401B2 patent drawing
  • US10567401B2 patent drawing
  • US10567401B2 patent drawing

AI summary

An attack detection device includes a transceiver and a processor. The transceiver receives a message from a communication device in a network. The processor calculates, according to a reception time of a first message in periodic messages that are periodically transmitted in a specified transmission cycle in the network, a reception range for a target message in the periodic messages that are received after the first message by the transceiver. When the transceiver receives a second message that is associated with information indicating that the second message is transmitted at a time interval shorter than the transmission cycle outside of the reception range after the reception time of the first message, the processor updates the reception range for a target message in the periodic messages that are received after the second message by the transceiver according to a reception time of the second message and the transmission cycle.