Network Attack Detection via Symbolic Behavior Patterns

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions for medical devices in hospitals are inefficient in preventing ransomware attacks, which can spread from medical devices to hospital networks, compromising medical data and device availability.

Innovation Solution

An attack detection apparatus based on measurement of networking behavior abnormalities in symbolic spaces, which creates profiles from network flows, measures behavior abnormalities, maps them to symbolic spaces, generates behavior symbol sequence patterns, and uses an abnormal behavior prediction model to detect attacks and identify affected devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If antivirus software or security functions are installed on medical devices to detect ransomware attacks, then security detection capability is improved, but device availability and operational reliability deteriorate

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoiddevice availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a network-level intermediary detection system that monitors medical devices without installing software on them. The detection apparatus acts as a mediator between multiple medical devices and the network, analyzing traffic patterns and behavioral characteristics to identify ransomware attacks. This approach maintains device availability while improving security detection capability through external monitoring rather than internal software installation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If traditional security measures are applied to medical devices, then attack detection accuracy is improved, but device complexity and operational difficulty increase

Engineering Contradiction:
Improveattack detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts the security detection function from the medical devices themselves and relocates it to a separate network-level detection apparatus. By taking out the complex security analysis functionality from the medical devices, the system achieves high detection accuracy while keeping the medical devices simple and easy to operate. The detection apparatus independently performs behavioral analysis and attack identification without adding complexity to the medical device ecosystem.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If network-level monitoring is implemented to detect ransomware spread, then security coverage is improved, but data processing requirements and system resources increase

Engineering Contradiction:
Improvesecurity coverageVSAvoiddata processing load
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies local quality analysis by focusing monitoring efforts on specific behavioral characteristics and traffic patterns relevant to ransomware attacks rather than analyzing all network data uniformly. The detection apparatus identifies and monitors key indicators such as abnormal communication patterns, unauthorized data access attempts, and suspicious traffic flows. This targeted approach improves security coverage while reducing overall data processing requirements by concentrating resources on high-risk behaviors.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12309183B2Attack detection apparatus and method based on measurement of networking behavior abnormalities in symbolic spaces
Publication Date: 2025.05.20 ELECTRONICS & TELECOMM RES INST
  • US12309183B2 patent drawing
  • US12309183B2 patent drawing
  • US12309183B2 patent drawing

AI summary

Disclosed herein are an attack detection apparatus and method based on measurement of networking behavior abnormalities in symbolic spaces. The attack detection method based on measurement of networking behavior abnormalities in symbolic spaces includes creating profiles based on a transmission address of a flow received from a network, measuring a behavior abnormality of a device corresponding to the transmission address of the flow on the network, and mapping the measured behavior abnormality to behavior symbols in symbolic spaces, generating a behavior symbol sequence pattern, in which the behavior symbols are sequentially connected, for each profile, and detecting presence or non-presence of an attack and a device associated with the attack based on an output of the abnormal behavior prediction model that receives the behavior symbol sequence pattern as input.