Network Security Threat Forecasting Using Time Series Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems, such as IDS and IPS, primarily detect and report on present cyber threats, failing to effectively forecast future security threat levels or provide proactive measures against cyber attacks, leaving users vulnerable to network attacks.

Innovation Solution

A network security threat level forecasting apparatus and method that collects traffic and malicious code data, transforms it into time series data, and uses prediction models like ARIMA or Markov chains to forecast attack probabilities, traffic rates, and intrusion origins, providing users with actionable threat data akin to weather forecasts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If current network security systems (IDS, IPS) are used to detect present attacks, then detection capability is improved, but the ability to forecast future threats deteriorates

Engineering Contradiction:
Improvedetection capabilityVSAvoidforecast capability
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by collecting and analyzing historical traffic data and intrusion detection data before attacks occur. The system uses time series prediction models and Markov chain models to forecast future security threat levels, attack probabilities, and intrusion frequencies in advance, enabling proactive security measures rather than reactive detection only

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by continuously collecting real-time traffic data and intrusion detection data, comparing actual security events with forecasted predictions, and using this feedback to refine and update the prediction models. This closed-loop approach improves forecast accuracy over time while maintaining detection capabilities

Inventive Principle:
Principle #23Feedback

2Measurement precision

If more security data is collected and analyzed, then forecast accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveforecast accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the security forecasting system into distinct functional modules: a data collection unit for gathering traffic and intrusion data, a time series data transformation unit for processing raw data, a network traffic analysis unit for analyzing traffic patterns, and a security forecast engine for generating predictions. This modular segmentation manages complexity while enabling comprehensive data analysis for accurate forecasting

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The time series data transformation unit acts as an intermediary between raw security data and the prediction models. It transforms unstructured security data into standardized time series format, bridging the gap between diverse data sources and the analytical engines, thereby simplifying the overall system architecture while maintaining forecast accuracy

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8839440B2Apparatus and method for forecasting security threat level of network
Publication Date: 2014.09.16 ELECTRONICS & TELECOMM RES INST
  • US8839440B2 patent drawing
  • US8839440B2 patent drawing
  • US8839440B2 patent drawing

AI summary

Provided are an apparatus and method for forecasting the security threat level of a network. The apparatus includes: a security data collection unit for collecting traffic data and intrusion detection data transmitted from an external network to a managed network; a malicious code data collection unit for collecting malicious code data transmitted from a security enterprise network; a time series data transformation unit for transforming the data collected by the security data collection unit into time series data; a network traffic analysis unit for analyzing traffic distribution of the managed network using the data collected by the security data collection unit; and a security forecast engine for forecasting security data of the managed network using the time series data obtained by the time data transformation unit, the data analyzed by the network traffic analysis unit, and the data collected by the malicious code data collection unit.