Polymorphic Intrusion Detection via Grammar-Based Compression
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Power plants face challenges in rapidly detecting and repelling cyber attacks, particularly polymorphic attacks that can disable or weaponize the plants, leading to power outages and data compromise, despite firewall protection.
Innovation Solution
A system comprising a pre-processor, grammar applicator using a grammar-based compression and learning algorithm, and an emulator for polymorphic transformation, which filters and analyzes network data to detect unauthorized intrusions and recommends appropriate actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewall protection is used, then basic network security is maintained, but polymorphic attacks can still breach the network and cause damage
Solution Approach 1:
The system performs preliminary analysis of network data packets using grammar-based compression algorithms before threats can execute. By pre-processing and evaluating data patterns, the system identifies malicious content in advance, preventing polymorphic attacks from breaching the network firewall and causing damage.
Solution Approach 2:
The patent introduces an intermediary detection system between the external network and the power plant's internal network. This intermediary layer uses grammar-based compression analysis to inspect and filter traffic, acting as a mediator that blocks malicious polymorphic code while allowing legitimate traffic to pass through the firewall.
2Measurement precision
If comprehensive network monitoring is implemented to detect all attacks, then detection accuracy improves, but processing time increases and rapid response is compromised
Solution Approach 1:
The system extracts only the essential features and patterns from network data packets using grammar-based compression algorithms. By taking out and analyzing only the critical components of data packets rather than processing entire packets, the system achieves high detection accuracy while significantly reducing processing time for rapid threat response.
Solution Approach 2:
The patent transforms network data into compressed grammatical representations, changing the parameter space from raw packet data to structured grammar rules. This parameter transformation enables efficient pattern matching and anomaly detection, improving both detection precision and processing speed by working with compressed feature sets rather than full packet data.
3Difficulty of detecting and measuring
If advanced detection algorithms are used to identify polymorphic attacks, then detection capability improves, but system complexity increases
Solution Approach 1:
The system creates compressed grammatical copies of legitimate network traffic patterns and compares incoming data against these copies. By using grammar-based compression to generate representative models of normal traffic, the system achieves advanced detection capability for polymorphic attacks while maintaining relatively simple implementation through pattern matching rather than complex analysis.
Data Source
AI summary
An intrusion detection system for detecting and defeating unauthorized intrusion within a computer network of an infrastructure element of a high value target, the system including a pre-processor configured to receive data from a computer network of an infrastructure element of a high value target and to output filtered data, a grammar applicator configured to apply grammars produced using a grammar based compression and learning algorithm to the filtered data, a decision making device configured to provide a recommendation based on an input from the grammar applicator as to whether the data in the computer network constitutes an unauthorized intrusion, and an emulator in communication with the decision making device configured to expand a sampling of the filtered data using a polymorphic transformation to allow the decision making device to further analyze the sampled data to determine an unauthorized intrusion. A method and a computer software code are also disclosed.


