Network Monitoring Apparatus for Rapid Attack Source Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network monitoring systems face challenges in quickly determining and notifying attack source and destination networks when a device managed by another network provider is attacked, leading to delayed defense measures due to interconnectivity complexities in modern internet infrastructure.

Innovation Solution

A network monitoring apparatus and method that includes a network-information storage unit, administrator-information storage unit, attack-source-network identifying unit, attack-destination-network identifying unit, and attack notifying unit to quickly identify and notify attack source and destination networks through analysis of abnormal traffic, enabling immediate defense actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a device managed by another network provider is attacked, then the attack detection capability is improved, but the response time deteriorates due to communication delays between network providers

Engineering Contradiction:
Improveattack detection accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The network monitoring apparatus pre-stores network information (IP address ranges, network identifiers) and administrator contact information for multiple network providers in its memory. When an attack is detected, the system can immediately query the stored information to identify the attack source network and retrieve administrator contact details, eliminating the need for real-time communication to gather this information and enabling instant notification.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If network providers communicate to determine attack status, then the accuracy of attack determination is improved, but the defense speed deteriorates

Engineering Contradiction:
Improveattack determination accuracyVSAvoiddefense speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The network monitoring apparatus autonomously determines whether detected abnormal traffic constitutes an attack by comparing source IP addresses and traffic patterns against pre-stored network information for multiple providers. The system independently identifies the attack source network and directly notifies relevant administrators without requiring consultation or determination by other network providers, thereby maintaining accuracy while dramatically speeding up the defense response.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If multiple networks are interconnected to expand service coverage, then the network versatility is improved, but the complexity of attack source identification deteriorates

Engineering Contradiction:
Improvenetwork interconnectivityVSAvoidattack source identification complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments the complex interconnected network space into manageable units by maintaining pre-stored network information that divides the internet into distinct network provider domains with specific IP address ranges and identifiers. When an attack is detected, the system queries this segmented information to quickly determine which specific network provider's domain the attack source belongs to, transforming the complexity of identifying attack sources across multiple interconnected networks into a simple database lookup process.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8347383B2Network monitoring apparatus, network monitoring method, and network monitoring program
Publication Date: 2013.01.01 NIPPON TELEGRAPH & TELEPHONE CORP
  • US8347383B2 patent drawing
  • US8347383B2 patent drawing
  • US8347383B2 patent drawing

AI summary

A traffic monitoring system (10) monitors traffics flowing through a network (100); when an abnormal traffic is detected, identifies an attack source network, a source of an attack, on the basis of attack source information indicating a source device from which the abnormal traffic is transmitted, which is obtained by an analysis of the abnormal traffic, and also identifies an attack destination network, a destination of the attack, on the basis of attack destination information indicating a destination device to which the abnormal traffic is to be transmitted, which is obtained by the analysis of the abnormal traffic; notifies an administrator of the attack source network of the attack source information by acquiring administrator information corresponding to the identified attack source network; and notifies an administrator of the attack destination network of the attack destination information by acquiring administrator information corresponding to the identified attack destination network.