Network Traffic Apparatus for Automatic Attack Signature Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber-protection techniques are inefficient in detecting and mitigating new attackers without affecting the health of protected sites, often requiring IP information or X-Forwarded-For data, and are time-consuming in behavioral detection.

Innovation Solution

A method and device for automatically detecting attack signatures and generating identifications using a network traffic apparatus with a processor and memory, which collects stable datasets during non-attack times, generates dynamic rules, validates them, and exports persistent rules to a security enforcer mechanism, eliminating the need for IP information or X-Forwarded-For data, and compatible with systems like Snort and Wireshark.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If behavioral detection techniques are used to identify new attackers, then detection capability is improved, but the process becomes time-consuming and affects site health

Engineering Contradiction:
Improvedetection capabilityVSAvoiddetection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system collects and analyzes traffic data during stable periods before attacks occur, pre-establishing baseline behavioral patterns. This preliminary action enables the system to immediately compare attack traffic against known good behavior patterns, eliminating the need for time-consuming detection during actual attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The detection process is divided into distinct phases: data collection during stable periods, analysis to establish baselines, and real-time comparison during attacks. This segmentation allows each phase to be optimized independently, with heavy analysis occurring offline and only lightweight comparisons occurring during attacks.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If IP information or X-Forwarded-For data is used for attack detection, then attacker identification is improved, but the system becomes dependent on specific data types that may not be available in all network configurations

Engineering Contradiction:
Improveattacker identification accuracyVSAvoidnetwork configuration compatibility
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system extracts behavioral features from multiple sources including IP addresses, X-Forwarded-For headers, and general traffic patterns. By implementing multiple extraction methods, the system becomes universally applicable across different network configurations and can fall back to alternative data sources when specific types are unavailable.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically adjusts which parameters are used for detection based on data availability and attack patterns. Instead of relying on fixed parameters like IP addresses, the system can switch to analyzing traffic timing, request patterns, and other behavioral parameters that remain effective across different network configurations.

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If deep post-attack forensic investigations are conducted to understand attack methods, then comprehensive understanding is improved, but the response time is delayed until after attacks occur

Engineering Contradiction:
Improveattack understanding completenessVSAvoidresponse time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system continuously monitors traffic and provides real-time feedback on detected anomalies. When attack patterns are identified, the system immediately generates alerts and can automatically respond, eliminating the delay of post-attack investigation. The feedback loop enables continuous learning and adaptation without waiting for forensic analysis.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system skips the traditional sequential process of detection followed by investigation by implementing real-time detection that identifies and responds to attacks as they occur. The system rushes through the detection and response process by using pre-established behavioral baselines to immediately recognize attack patterns without requiring detailed forensic analysis.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS10855701B2Methods and devices for automatically detecting attack signatures and generating attack signature identifications
Publication Date: 2020.12.01 F5 NETWORKS INC
  • US10855701B2 patent drawing
  • US10855701B2 patent drawing
  • US10855701B2 patent drawing

AI summary

Network traffic management apparatuses, systems, methods, and computer-readable media for automatically detecting attack signatures and generating attack signature identifications, involving: collecting a stable dataset during a stable time; determining whether a cyber-attack is detected; when a cyber-attack is detected, periodically generating attack signatures and updating an enforcer with the attack signatures, the attack signatures representing dynamic rules to be enforced; validating the dynamic rules via a long-time validation mechanism, validating involving considering behavior of each dynamic rule after the cyber-attack and during a new cyber-attack and ranking each dynamic rule using the stable dataset, thereby generating persistent rules having a dynamic rule; exporting the persistent rules to a security enforcer; introducing the persistent rules to a persistent rule revocater; determining whether export of an unrevoked persistent rule is requested; and if requested, exporting the unrevoked persistent rule of the persistent rules through a mitigator and collecting statistics.