Network Attack Detection via Symbolic Behavior Patterns
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security solutions for medical devices in hospitals are inefficient in preventing ransomware attacks, which can spread from medical devices to hospital networks, compromising medical data and device availability.
Innovation Solution
An attack detection apparatus based on measurement of networking behavior abnormalities in symbolic spaces, which creates profiles from network flows, measures behavior abnormalities, maps them to symbolic spaces, generates behavior symbol sequence patterns, and uses an abnormal behavior prediction model to detect attacks and identify affected devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If antivirus software or security functions are installed on medical devices to detect ransomware attacks, then security detection capability is improved, but device availability and operational reliability deteriorate
Solution Approach 1:
The patent introduces a network-level intermediary detection system that monitors medical devices without installing software on them. The detection apparatus acts as a mediator between multiple medical devices and the network, analyzing traffic patterns and behavioral characteristics to identify ransomware attacks. This approach maintains device availability while improving security detection capability through external monitoring rather than internal software installation.
2Measurement precision
If traditional security measures are applied to medical devices, then attack detection accuracy is improved, but device complexity and operational difficulty increase
Solution Approach 1:
The patent extracts the security detection function from the medical devices themselves and relocates it to a separate network-level detection apparatus. By taking out the complex security analysis functionality from the medical devices, the system achieves high detection accuracy while keeping the medical devices simple and easy to operate. The detection apparatus independently performs behavioral analysis and attack identification without adding complexity to the medical device ecosystem.
3Reliability
If network-level monitoring is implemented to detect ransomware spread, then security coverage is improved, but data processing requirements and system resources increase
Solution Approach 1:
The patent applies local quality analysis by focusing monitoring efforts on specific behavioral characteristics and traffic patterns relevant to ransomware attacks rather than analyzing all network data uniformly. The detection apparatus identifies and monitors key indicators such as abnormal communication patterns, unauthorized data access attempts, and suspicious traffic flows. This targeted approach improves security coverage while reducing overall data processing requirements by concentrating resources on high-risk behaviors.
Data Source
AI summary
Disclosed herein are an attack detection apparatus and method based on measurement of networking behavior abnormalities in symbolic spaces. The attack detection method based on measurement of networking behavior abnormalities in symbolic spaces includes creating profiles based on a transmission address of a flow received from a network, measuring a behavior abnormality of a device corresponding to the transmission address of the flow on the network, and mapping the measured behavior abnormality to behavior symbols in symbolic spaces, generating a behavior symbol sequence pattern, in which the behavior symbols are sequentially connected, for each profile, and detecting presence or non-presence of an attack and a device associated with the attack based on an output of the abnormal behavior prediction model that receives the behavior symbol sequence pattern as input.


