Network Control Apparatus for Malicious Communication Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security measures for networks, especially in home and small-to-medium-sized enterprises, face challenges in effectively detecting malicious communication without excessive bandwidth usage or reducing accuracy, and often fail to protect the user network as they rely on external services for intrusion detection.
Innovation Solution
A network system comprising a communication apparatus and a control apparatus that analyzes partial communication information to determine abnormality, controls communication routes, and restricts malicious communication, reducing bandwidth usage and improving detection accuracy while protecting the user network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If all communication traffic is monitored by outside functions, then detection accuracy is improved, but bandwidth usage is excessively increased
Solution Approach 1:
The system segments communication traffic into two categories: sampled traffic sent to outside functions for analysis, and non-sampled traffic handled locally by the communication apparatus. This segmentation allows detection accuracy to be maintained for suspicious traffic while avoiding excessive bandwidth usage by not transmitting all traffic externally.
Solution Approach 2:
Instead of monitoring all communication traffic, the system applies partial action by selectively sampling only a portion of traffic for external analysis. The communication apparatus independently handles non-sampled traffic, performing basic security checks locally. This partial monitoring approach reduces bandwidth consumption while maintaining effective security detection through targeted analysis of sampled packets.
2Quantity of substance
If only sampled traffic is analyzed by outside functions, then bandwidth usage is reduced, but detection accuracy is decreased
Solution Approach 1:
The communication apparatus performs preliminary security checks and filtering on non-sampled traffic before it leaves the local network. This preliminary action ensures that obviously malicious traffic is caught locally without requiring external analysis, while suspicious traffic is identified and forwarded for deeper external analysis, thereby maintaining detection accuracy while reducing bandwidth usage.
Solution Approach 2:
The communication apparatus acts as an intermediary between local traffic and external analysis functions. It receives all traffic, performs initial filtering and sampling decisions, forwards only selected traffic externally, and implements control decisions based on external analysis results. This intermediary role enables the system to maintain high detection accuracy through coordinated local and external analysis while minimizing bandwidth consumption.
3Productivity
If IDS processing is performed only for communication to a particular AP server, then processing load is reduced, but network-wide security protection is compromised
Solution Approach 1:
The communication apparatus is designed with multi-functionality, serving both as a local security filter for all traffic and as a sampler for external IDS analysis. It can identify suspicious traffic patterns across the entire network, not just for specific servers, and forward relevant samples for external analysis. This universal capability ensures network-wide security protection while maintaining reasonable processing loads through intelligent traffic selection.
Data Source
AI summary
A control apparatus performs analysis by using partial information and determines whether or not communication is abnormal. If the communication is determined to be abnormal, the control apparatus controls a communication route for a communication control device such that the communication is transmitted from a communication apparatus to the control apparatus. Further, the control apparatus determines whether or not the communication transmitted by the control of the communication route is malicious communication. As a result, if the communication is determined to be malicious communication, the control apparatus controls the communication control device to restrict the malicious communication.


