Network Security Apparatus Load-Based Detection Allocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for detecting fraudulent communications in IoT networks, such as list-type detection and machine-learning-type detection, face challenges including high human costs, computational resource requirements, and inconsistent detection results, especially when multiple devices and systems coexist in a network, leading to complex installation and operation costs.

Innovation Solution

A network security system dynamically selects between list-type detection and machine-learning-type detection based on load status, allowing both methods to be used simultaneously without duplicating devices or systems, by employing a filter that allocates communication data to either or both detection types based on load conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If list-type detection is used to accurately detect fraudulent communications by inspecting communication details, then detection precision is improved, but processing time and computational resources increase enormously

Engineering Contradiction:
Improvedetection precisionVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the detection process into two distinct modules: list-type detection for high-precision analysis of specific communication patterns, and machine-learning-type detection for rapid filtering of obvious anomalies. This segmentation allows each method to operate on appropriate subsets of traffic, balancing precision and speed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action by using machine-learning-type detection to handle the majority of traffic with acceptable accuracy, while reserving list-type detection for cases requiring higher precision. This avoids applying the most resource-intensive method to all traffic.

Inventive Principle:
Principle #16Partial or excessive action

2Productivity

If machine-learning-type detection is used to detect fraudulent communications based on statistical information, then detection speed is improved, but computational resources required increase enormously

Engineering Contradiction:
Improvedetection speedVSAvoidcomputational resources
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The patent uses machine-learning-type detection partially, applying it to traffic where rapid processing is prioritized over maximum precision. This allows high-speed detection for common patterns while conserving computational resources.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The detection system is segmented into two modules with different resource requirements. The machine-learning module handles bulk traffic with lower computational overhead per packet, while the list-type module handles specific cases with higher precision requirements.

Inventive Principle:
Principle #1Segmentation

3Reliability

If both list-type detection and machine-learning-type detection are used simultaneously to detect fraudulent communications, then detection effectiveness is improved, but device complexity and installation costs increase

Engineering Contradiction:
Improvedetection effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges list-type detection and machine-learning-type detection into a single integrated system with a unified control unit. This combination leverages the strengths of both methods while managing complexity through centralized coordination rather than separate independent systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The control unit is designed with multi-functionality, capable of dynamically selecting and switching between list-type and machine-learning-type detection based on traffic characteristics. This universal controller manages both detection methods without requiring separate dedicated systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Measurement precision

If list-type detection is used with detailed definition files to accurately identify fraudulent communications, then detection precision is improved, but human costs and operational complexity increase

Engineering Contradiction:
Improvedetection precisionVSAvoidoperational simplicity
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent segments the detection workload so that machine-learning-type detection automatically handles pattern recognition without human intervention, while list-type detection uses pre-defined rules for specific cases. This reduces the need for manual creation and maintenance of detailed definition files.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3989490B1Network security apparatus, network security system, and network security method
Publication Date: 2024.04.17 MITSUBISHI ELECTRIC CORP
  • EP3989490B1 patent drawingFigure 1
  • EP3989490B1 patent drawingFigure 2
  • EP3989490B1 patent drawingFigure 3

AI summary

A list-type detection unit (220) performs list-type detection on communication data so as to detect a fraudulent communication. A machine-learning-type detection unit (230) performs machine-learning-type detection on communication data so as to detect a fraudulent communication. A communication acceptance unit (210) receives communication data from a network, and allocates the received communication data to at least one of the list-type detection unit and the machine-learning-type detection unit, using an allocation filter. A filter setting unit (250) determines a parameter value based on a load status of the list-type detection unit and a load status of the machine-learning-type detection unit, and sets the determined parameter value in the allocation filter.