Network Flow Analysis Apparatus Attack Route Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network anomaly detection technologies can sense attacks but fail to identify the route of the attack, making it difficult to handle effectively.
Innovation Solution
An information processing apparatus and method that acquires and organizes flow information and conversion information in a monitored system, generating route information to identify the route of an attack by acknowledging alert information and associating it with flow and conversion data, enabling proper handling of anomalies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If network anomaly detection technology is used to sense attacks, then attack detection capability is improved, but the ability to identify attack routes deteriorates
Solution Approach 1:
The patent segments the network traffic analysis into multiple flow types (packet flows, connection flows, TCP flows) and analyzes each segment separately to reconstruct the complete attack route. This segmentation allows detailed examination of specific traffic patterns while maintaining overall route visibility.
Solution Approach 2:
The patent introduces flow information as an intermediary element that connects attack detection with route identification. By using flow information generated by network devices as a mediator, the system can trace attack routes without directly modifying the core detection mechanisms.
2Loss of information
If flow information is collected and analyzed to identify attack routes, then route identification capability is improved, but system complexity increases
Solution Approach 1:
The patent creates a multi-functional analysis system that handles multiple flow types (packet, connection, TCP flows) and performs multiple analysis functions (route identification, attack detection, traffic pattern recognition) within a unified framework, reducing overall system complexity.
Solution Approach 2:
The system automatically generates flow information from network device data and uses this information to identify attack routes without requiring manual configuration or intervention, making the complex analysis process self-service and reducing operational complexity.
3Measurement precision
If multiple types of flow information are analyzed, then attack route identification accuracy is improved, but data processing requirements increase
Solution Approach 1:
The patent segments data processing into hierarchical levels, analyzing different flow types at appropriate granularities. By segmenting the analysis process, the system processes only necessary data at each level, reducing overall data processing volume while maintaining high identification accuracy.
Solution Approach 2:
The patent applies partial analysis by focusing on specific flow types and characteristics relevant to attack detection, rather than processing all network data in detail. This selective approach reduces data processing requirements while maintaining sufficient accuracy for security purposes.
Data Source
AI summary
An analysis ECU acquires information related to a first flow and information related to a second flow, the first flow and the second flow organizing packets transferred in a monitored system into respective groups. The analysis ECU acquires information related to a conversion that takes the first flow as input and the second flow as output. The analysis ECU acknowledges alert information generated in the monitored system and including information capable of identifying at least one flow. The analysis ECU generates, when the second flow is identified by the alert information, route information that includes at least one of the information related to the conversion and the information related to the first flow associated with the second flow in the information related to the conversion.


