Network Standpoint Feature Value Analysis for Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods face challenges in distinguishing between attack communication and normal communication, particularly in detecting vulnerability scans from limited information, as they resemble normal crawler activities.

Innovation Solution

An analysis method and device that classify access data into network and point standpoint feature values, detecting access sources performing continuous activities by comparing similarity values, allowing for accurate differentiation between attack and normal communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a honeypot system is set up to collect attacks, then attack collection capability is improved, but it becomes difficult to distinguish attack communication from normal communication

Engineering Contradiction:
Improveattack collection capabilityVSAvoiddetection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments the detection process into two distinct perspectives: network standpoint feature values (aggregated across multiple observation points) and point standpoint feature values (from individual observation points). This segmentation allows the system to maintain comprehensive attack collection while improving detection precision by analyzing patterns at different levels of aggregation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of analysis by creating feature values from multiple observation points in the network, not just from a single point. This multi-dimensional approach enables the system to distinguish attacks from normal communication by comparing patterns across different network vantage points, thereby resolving the contradiction between comprehensive collection and accurate detection.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Device complexity

If limited information is used for detection, then system complexity is reduced, but detection accuracy deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoiddetection accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent creates feature values that serve multiple functions: they can be generated from limited information (reducing complexity requirements) while simultaneously enabling accurate detection by capturing essential patterns in communication behavior. The feature values act as a universal representation that works for both simple implementation and accurate detection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent transforms raw access data into feature values by changing the parameters of representation. Instead of analyzing raw communication data directly (which would require complex systems), the system extracts key features such as access frequency, timing patterns, and source characteristics, thereby achieving accurate detection with reduced system complexity.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If single observation point data is used, then data processing simplicity is improved, but ability to detect continuous access deteriorates

Engineering Contradiction:
Improvedata processing simplicityVSAvoidcontinuous access detection capability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the observation network into multiple points, each generating feature values independently. This segmentation maintains the simplicity of individual point processing while enabling reliable detection of continuous access patterns through aggregation and comparison across multiple segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges feature values from multiple observation points to detect continuous access patterns. By combining information from different vantage points, the system achieves reliable detection of persistent attacks while maintaining the operational simplicity of processing data from individual points before aggregation.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11159548B2Analysis method, analysis device, and analysis program
Publication Date: 2021.10.26 NIPPON TELEGRAPH & TELEPHONE CORP
  • US11159548B2 patent drawing
  • US11159548B2 patent drawing
  • US11159548B2 patent drawing

AI summary

A network standpoint feature value creating unit classifies access data collected at observation points into each detection target access source and creates network standpoint feature values for each of the detection target access sources. An access source detection unit detects, based on the network standpoint feature value, an access source performs a predetermined continuous access. A point standpoint feature value creating unit creates detection target standpoint feature values that are feature values for each access data collected at an observation point and training standpoint feature values that are feature values for each access data of the access source detected by the access source detection unit. An access detection unit detects access data in which the similarity between the detection target standpoint feature value and the training standpoint feature value is not less than a predetermined value as access data by the predetermined continuous access.