Polymorphic Intrusion Detection via Grammar-Based Compression

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Power plants face challenges in rapidly detecting and repelling cyber attacks, particularly polymorphic attacks that can disable or weaponize the plants, leading to power outages and data compromise, despite firewall protection.

Innovation Solution

A system comprising a pre-processor, grammar applicator using a grammar-based compression and learning algorithm, and an emulator for polymorphic transformation, which filters and analyzes network data to detect unauthorized intrusions and recommends appropriate actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewall protection is used, then basic network security is maintained, but polymorphic attacks can still breach the network and cause damage

Engineering Contradiction:
Improvenetwork securityVSAvoidpolymorphic attack penetration
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary analysis of network data packets using grammar-based compression algorithms before threats can execute. By pre-processing and evaluating data patterns, the system identifies malicious content in advance, preventing polymorphic attacks from breaching the network firewall and causing damage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary detection system between the external network and the power plant's internal network. This intermediary layer uses grammar-based compression analysis to inspect and filter traffic, acting as a mediator that blocks malicious polymorphic code while allowing legitimate traffic to pass through the firewall.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive network monitoring is implemented to detect all attacks, then detection accuracy improves, but processing time increases and rapid response is compromised

Engineering Contradiction:
Improveintrusion detection accuracyVSAvoidattack detection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system extracts only the essential features and patterns from network data packets using grammar-based compression algorithms. By taking out and analyzing only the critical components of data packets rather than processing entire packets, the system achieves high detection accuracy while significantly reducing processing time for rapid threat response.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transforms network data into compressed grammatical representations, changing the parameter space from raw packet data to structured grammar rules. This parameter transformation enables efficient pattern matching and anomaly detection, improving both detection precision and processing speed by working with compressed feature sets rather than full packet data.

Inventive Principle:
Principle #35Parameter changes

3Difficulty of detecting and measuring

If advanced detection algorithms are used to identify polymorphic attacks, then detection capability improves, but system complexity increases

Engineering Contradiction:
Improvepolymorphic attack detection capabilityVSAvoiddetection system complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The system creates compressed grammatical copies of legitimate network traffic patterns and compares incoming data against these copies. By using grammar-based compression to generate representative models of normal traffic, the system achieves advanced detection capability for polymorphic attacks while maintaining relatively simple implementation through pattern matching rather than complex analysis.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8621629B2System, method, and computer software code for detecting a computer network intrusion in an infrastructure element of a high value target
Publication Date: 2013.12.31 GE DIGITAL HLDG LLC
  • US8621629B2 patent drawing
  • US8621629B2 patent drawing
  • US8621629B2 patent drawing

AI summary

An intrusion detection system for detecting and defeating unauthorized intrusion within a computer network of an infrastructure element of a high value target, the system including a pre-processor configured to receive data from a computer network of an infrastructure element of a high value target and to output filtered data, a grammar applicator configured to apply grammars produced using a grammar based compression and learning algorithm to the filtered data, a decision making device configured to provide a recommendation based on an input from the grammar applicator as to whether the data in the computer network constitutes an unauthorized intrusion, and an emulator in communication with the decision making device configured to expand a sampling of the filtered data using a polymorphic transformation to allow the decision making device to further analyze the sampled data to determine an unauthorized intrusion. A method and a computer software code are also disclosed.