Network Attack Detection Using Dynamic Reception Range Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network attack detection systems face challenges in accurately identifying frames used for attacks, particularly when both periodic and aperiodic messages are transmitted, as they often misidentify messages based on transmission cycles, leading to erroneous detection of attacks.
Innovation Solution
An attack detection device that utilizes a transceiver and processor to calculate reception ranges for periodic messages, updating these ranges based on the reception time of messages with a short interval flag, allowing for accurate differentiation between normal and attack frames by predicting the reception time of subsequent messages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a method verifies a specific identifier in a data frame when transmission cycle compliance is checked, then attack detection capability is improved, but false identification of periodic messages as attacks increases
Solution Approach 1:
The patent segments the message stream into periodic and aperiodic components by introducing a short interval flag. This flag distinguishes messages transmitted at intervals shorter than the nominal transmission cycle, allowing the system to separately handle periodic messages (which follow the cycle) and aperiodic messages (which may have short intervals). This segmentation resolves the contradiction by enabling accurate attack detection on aperiodic messages without falsely flagging periodic messages.
Solution Approach 2:
The patent dynamically adjusts the transmission cycle reference based on the short interval flag. When an aperiodic message with a short interval is detected, the system updates the transmission cycle timing reference to accommodate this message. This dynamic adjustment allows the system to adapt to varying message patterns while maintaining accurate attack detection, preventing false identification of subsequent periodic messages as attacks.
2Measurement precision
If periodic messages are used as reference for transmission cycle verification, then detection accuracy is improved, but system adaptability to aperiodic messages deteriorates
Solution Approach 1:
The patent makes the transmission cycle reference dynamic by allowing it to be updated when aperiodic messages with short intervals are detected. The short interval flag triggers a recalculation of the transmission cycle timing, enabling the system to adapt to changing message patterns while maintaining detection accuracy for both periodic and aperiodic messages.
Solution Approach 2:
The patent changes the timing parameters of the transmission cycle based on the short interval flag. When an aperiodic message is detected, the system adjusts the reference timing for subsequent messages, effectively changing the parameter used for cycle verification. This allows the system to maintain high detection accuracy while being adaptable to different message transmission patterns.
3Reliability
If attack detection is performed on all received frames, then security monitoring is improved, but computational overhead and false positives increase
Solution Approach 1:
The patent segments messages into periodic and aperiodic categories using the short interval flag. This segmentation allows the system to apply different detection strategies: periodic messages are monitored for timing compliance, while aperiodic messages are flagged for more intensive inspection. This reduces computational overhead by avoiding unnecessary verification on routine periodic messages while maintaining strong security monitoring on potentially malicious aperiodic messages.
Solution Approach 2:
The patent applies partial verification to periodic messages (checking timing against the established cycle) and more thorough verification to aperiodic messages (flagged by the short interval indicator). This differentiated approach reduces overall computational overhead compared to exhaustive verification of all messages, while still maintaining high security monitoring through targeted inspection of suspicious aperiodic messages.
Data Source
AI summary
An attack detection device includes a transceiver and a processor. The transceiver receives a message from a communication device in a network. The processor calculates, according to a reception time of a first message in periodic messages that are periodically transmitted in a specified transmission cycle in the network, a reception range for a target message in the periodic messages that are received after the first message by the transceiver. When the transceiver receives a second message that is associated with information indicating that the second message is transmitted at a time interval shorter than the transmission cycle outside of the reception range after the reception time of the first message, the processor updates the reception range for a target message in the periodic messages that are received after the second message by the transceiver according to a reception time of the second message and the transmission cycle.


