Network Attack Detection via Fusion Feature Vector Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for detecting network attacks are inadequate in analyzing the complex characteristics of network traffic, particularly as network environments become more sophisticated and cyberattacks evolve, limiting their ability to utilize abundant network traffic information effectively.

Innovation Solution

Generating three kinds of feature sets for each time window based on network traffic, combining them into a fusion feature vector, and using this vector for training to detect network attacks, incorporating features such as packet, flow, and flow set characteristics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing methods collect and learn features of single flow or statistical features of flow set, then the analysis process is simple, but the detection precision is insufficient due to inadequate utilization of network traffic characteristics

Engineering Contradiction:
Improvedetection precisionVSAvoidanalysis complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments network traffic analysis into three distinct feature levels: packet-level features (size, inter-arrival time, flags), flow-level features (duration, packet count, entropy), and flow-set-level features (number of flows, statistical information). This segmentation allows comprehensive utilization of network traffic characteristics while maintaining organized and manageable analysis processes, thereby improving detection precision without overwhelming complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from traditional single-dimension flow analysis to multi-dimensional analysis by incorporating packet-level, flow-level, and flow-set-level features simultaneously. This dimensional expansion enables the system to capture network traffic characteristics from multiple perspectives, significantly enhancing detection precision for sophisticated cyberattacks while providing a structured approach to manage the increased analytical complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If existing methods analyze network traffic in units of flows with basic features, then the processing complexity is low, but the ability to detect sophisticated cyberattacks is limited

Engineering Contradiction:
Improveattack detection capabilityVSAvoidfeature extraction complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges three types of feature extractions (packet-level, flow-level, and flow-set-level) into a unified analysis framework. By combining these feature sets and generating fusion feature vectors that integrate information from all three levels, the system achieves reliable detection of sophisticated cyberattacks while managing complexity through systematic integration rather than separate processing.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates composite feature representations by fusing packet-level, flow-level, and flow-set-level features into comprehensive fusion feature vectors. This composite approach enables the system to leverage diverse traffic characteristics simultaneously, significantly improving attack detection reliability for complex threats like ransomware and DDoS attacks while maintaining a structured processing pipeline.

Inventive Principle:
Principle #40Composite materials

3Loss of information

If existing methods use basic flow features, then the information utilization is simple, but the abundance of network traffic information is not sufficiently used

Engineering Contradiction:
Improveinformation utilization efficiencyVSAvoidfeature processing complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent segments network traffic information extraction into three hierarchical levels: packet-level features (size, inter-arrival time, direction, flags), flow-level features (duration, packet count, byte count, entropy), and flow-set-level features (number of flows, statistical information). This segmentation enables comprehensive utilization of available network traffic information while organizing the data processing into manageable segments, reducing information loss without overwhelming processing complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds multiple analytical dimensions by simultaneously extracting and analyzing packet-level, flow-level, and flow-set-level features. This multi-dimensional approach ensures that abundant network traffic information is fully utilized across different granularities, maximizing information extraction efficiency while providing a structured framework to handle the increased processing requirements.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20230199005A1Method and apparatus for detecting network attack based on fusion feature vector
Publication Date: 2023.06.22 ELECTRONICS & TELECOMM RES INST
  • US20230199005A1 patent drawing
  • US20230199005A1 patent drawing
  • US20230199005A1 patent drawing

AI summary

Disclosed herein is a method for detecting a network attack based on a fusion feature vector. The method includes extracting feature vectors corresponding to a preset unit time from network traffic, generating fusion feature vectors based on the extracted feature vectors, and performing training using the generated fusion feature vectors.