Rule Optimizer for Exploit Attack Detection Accuracy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing exploit attack detection systems rely heavily on manual rule setting and optimization by administrators, leading to subjective performance guarantees, high human and time costs, and potential delays in rule updates, which can reduce detection accuracy and speed.

Innovation Solution

An apparatus and method for automatically optimizing detection rules using a rule optimizer that obtains and time-series analyzes log data to update existing rules, improving detection accuracy and speed without relying on administrator expertise.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual rule setting and optimization is performed by administrators, then detection rules can be customized, but detection performance cannot be objectively guaranteed and human/time costs are high

Engineering Contradiction:
Improvedetection performanceVSAvoidmanual rule optimization
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The system performs self-optimization by automatically analyzing log data and updating detection rules without requiring manual intervention from administrators. The rule optimizer module autonomously processes log files, identifies attack patterns, and updates rules based on observed behavior, enabling the system to improve its own detection performance objectively.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring log data, analyzing detection results, and using this information to refine and update detection rules. The rule optimizer receives feedback from actual attack detection outcomes and adjusts rules accordingly, creating a closed-loop system that objectively improves detection performance over time.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If manual rule updates are performed periodically, then rules can be maintained, but detection speed and accuracy are reduced due to delays

Engineering Contradiction:
Improvedetection accuracyVSAvoidrule update delay
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary analysis of log data continuously and proactively identifies new attack patterns before they become prevalent. The rule optimizer prepares and updates detection rules in advance based on emerging trends, ensuring that the system is ready to detect new attacks immediately without waiting for periodic manual updates.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system transitions from periodic manual rule updates to continuous automated optimization. The rule optimizer operates continuously, constantly analyzing log data and updating rules as needed, eliminating the gaps and delays associated with periodic updates while maintaining high detection accuracy.

Inventive Principle:
Principle #20Continuity of useful action

3Productivity

If automated rule optimization is implemented, then detection performance is objectively improved, but system complexity increases

Engineering Contradiction:
Improvedetection speedVSAvoidrule optimization system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system extracts the rule optimization functionality into a separate, dedicated rule optimizer module that operates independently from the main detection system. This extraction allows the optimization process to be isolated and managed separately, reducing the complexity burden on the core detection system while still achieving automated improvement.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The rule optimizer acts as an intermediary component between the detection system and the administrators. It handles the complex tasks of log analysis, pattern recognition, and rule generation automatically, shielding administrators from complexity while enabling objective performance improvement. The intermediary absorbs the computational and analytical overhead.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If rule optimization depends on administrator experience, then rules can be tailored to specific needs, but detection performance varies and human costs are incurred

Engineering Contradiction:
Improverule customizationVSAvoidrule setting process
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system performs self-optimization by automatically analyzing log data and updating detection rules without requiring manual intervention from administrators. The rule optimizer module autonomously processes log files, identifies attack patterns, and updates rules based on observed behavior, enabling the system to improve its own detection performance objectively.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system automatically adjusts rule parameters such as detection thresholds, priority levels, and activation conditions based on analyzed log data and observed attack patterns. This automated parameter optimization eliminates the need for administrators to manually tune rules while maintaining adaptability to specific organizational needs through data-driven adjustments.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11057425B2Apparatuses for optimizing rule to improve detection accuracy for exploit attack and methods thereof
Publication Date: 2021.07.06 KOREA INTERNET & SECURITY AGENCY
  • US11057425B2 patent drawing
  • US11057425B2 patent drawing
  • US11057425B2 patent drawing

AI summary

An apparatus comprising a processor to execute the rule optimizer to perform a number of operations. One operation comprises obtaining 5 log data including a result of detecting an exploit attack based on a rule. Another operation comprises time-series analyzing the obtained log data to update at least some of previously applied detection rules. There is provided an apparatus for automatically optimizing a rule to improve the detection accuracy for an exploit attack in a rule-based attack detection system, and a method performed on the apparatus.