Network Control Apparatus for Malicious Communication Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security measures for networks, especially in home and small-to-medium-sized enterprises, face challenges in effectively detecting malicious communication without excessive bandwidth usage or reducing accuracy, and often fail to protect the user network as they rely on external services for intrusion detection.

Innovation Solution

A network system comprising a communication apparatus and a control apparatus that analyzes partial communication information to determine abnormality, controls communication routes, and restricts malicious communication, reducing bandwidth usage and improving detection accuracy while protecting the user network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If all communication traffic is monitored by outside functions, then detection accuracy is improved, but bandwidth usage is excessively increased

Engineering Contradiction:
Improvedetection accuracyVSAvoidbandwidth usage
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system segments communication traffic into two categories: sampled traffic sent to outside functions for analysis, and non-sampled traffic handled locally by the communication apparatus. This segmentation allows detection accuracy to be maintained for suspicious traffic while avoiding excessive bandwidth usage by not transmitting all traffic externally.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of monitoring all communication traffic, the system applies partial action by selectively sampling only a portion of traffic for external analysis. The communication apparatus independently handles non-sampled traffic, performing basic security checks locally. This partial monitoring approach reduces bandwidth consumption while maintaining effective security detection through targeted analysis of sampled packets.

Inventive Principle:
Principle #16Partial or excessive action

2Quantity of substance

If only sampled traffic is analyzed by outside functions, then bandwidth usage is reduced, but detection accuracy is decreased

Engineering Contradiction:
Improvebandwidth usageVSAvoiddetection accuracy
Core Design Contradiction:
Quantity of substanceVSMeasurement precision

Solution Approach 1:

The communication apparatus performs preliminary security checks and filtering on non-sampled traffic before it leaves the local network. This preliminary action ensures that obviously malicious traffic is caught locally without requiring external analysis, while suspicious traffic is identified and forwarded for deeper external analysis, thereby maintaining detection accuracy while reducing bandwidth usage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The communication apparatus acts as an intermediary between local traffic and external analysis functions. It receives all traffic, performs initial filtering and sampling decisions, forwards only selected traffic externally, and implements control decisions based on external analysis results. This intermediary role enables the system to maintain high detection accuracy through coordinated local and external analysis while minimizing bandwidth consumption.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If IDS processing is performed only for communication to a particular AP server, then processing load is reduced, but network-wide security protection is compromised

Engineering Contradiction:
Improveprocessing loadVSAvoidnetwork security protection
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The communication apparatus is designed with multi-functionality, serving both as a local security filter for all traffic and as a sampler for external IDS analysis. It can identify suspicious traffic patterns across the entire network, not just for specific servers, and forward relevant samples for external analysis. This universal capability ensures network-wide security protection while maintaining reasonable processing loads through intelligent traffic selection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10476901B2Network system, control apparatus, communication apparatus, communication control method, and communication control program
Publication Date: 2019.11.12 NIPPON TELEGRAPH & TELEPHONE CORP
  • US10476901B2 patent drawing
  • US10476901B2 patent drawing
  • US10476901B2 patent drawing

AI summary

A control apparatus performs analysis by using partial information and determines whether or not communication is abnormal. If the communication is determined to be abnormal, the control apparatus controls a communication route for a communication control device such that the communication is transmitted from a communication apparatus to the control apparatus. Further, the control apparatus determines whether or not the communication transmitted by the control of the communication route is malicious communication. As a result, if the communication is determined to be malicious communication, the control apparatus controls the communication control device to restrict the malicious communication.