Network Flow Analysis Apparatus Attack Route Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network anomaly detection technologies can sense attacks but fail to identify the route of the attack, making it difficult to handle effectively.

Innovation Solution

An information processing apparatus and method that acquires and organizes flow information and conversion information in a monitored system, generating route information to identify the route of an attack by acknowledging alert information and associating it with flow and conversion data, enabling proper handling of anomalies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network anomaly detection technology is used to sense attacks, then attack detection capability is improved, but the ability to identify attack routes deteriorates

Engineering Contradiction:
Improveattack detection capabilityVSAvoidattack route identification
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent segments the network traffic analysis into multiple flow types (packet flows, connection flows, TCP flows) and analyzes each segment separately to reconstruct the complete attack route. This segmentation allows detailed examination of specific traffic patterns while maintaining overall route visibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces flow information as an intermediary element that connects attack detection with route identification. By using flow information generated by network devices as a mediator, the system can trace attack routes without directly modifying the core detection mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If flow information is collected and analyzed to identify attack routes, then route identification capability is improved, but system complexity increases

Engineering Contradiction:
Improveattack route identificationVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent creates a multi-functional analysis system that handles multiple flow types (packet, connection, TCP flows) and performs multiple analysis functions (route identification, attack detection, traffic pattern recognition) within a unified framework, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system automatically generates flow information from network device data and uses this information to identify attack routes without requiring manual configuration or intervention, making the complex analysis process self-service and reducing operational complexity.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If multiple types of flow information are analyzed, then attack route identification accuracy is improved, but data processing requirements increase

Engineering Contradiction:
Improveroute identification accuracyVSAvoiddata processing volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent segments data processing into hierarchical levels, analyzing different flow types at appropriate granularities. By segmenting the analysis process, the system processes only necessary data at each level, reducing overall data processing volume while maintaining high identification accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial analysis by focusing on specific flow types and characteristics relevant to attack detection, rather than processing all network data in detail. This selective approach reduces data processing requirements while maintaining sufficient accuracy for security purposes.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11252057B2Information processing apparatus, information processing system, information processing method, and computer program
Publication Date: 2022.02.15 PANASONIC AUTOMOTIVE SYST CO LTD
  • US11252057B2 patent drawing
  • US11252057B2 patent drawing
  • US11252057B2 patent drawing

AI summary

An analysis ECU acquires information related to a first flow and information related to a second flow, the first flow and the second flow organizing packets transferred in a monitored system into respective groups. The analysis ECU acquires information related to a conversion that takes the first flow as input and the second flow as output. The analysis ECU acknowledges alert information generated in the monitored system and including information capable of identifying at least one flow. The analysis ECU generates, when the second flow is identified by the alert information, route information that includes at least one of the information related to the conversion and the information related to the first flow associated with the second flow in the information related to the conversion.