Security Alert Priority Determination via Traffic Dissimilarity Index
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing priority determination techniques for security alerts in network-type intrusion detection systems require pre-defined events, leading to potential inaccuracies in assessing the importance of unauthorized access.
Innovation Solution
A priority determination apparatus that calculates a dissimilarity index between transmission/reception performance records of current and past security alerts to determine the priority of new alerts, without the need for pre-defined events, using methods such as distribution difference indices and outlier detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If events are defined in advance for priority determination, then the determination process is simplified, but the accuracy of determining the importance of unauthorized access deteriorates
Solution Approach 1:
The patent applies dynamics by transitioning from static pre-defined events to dynamic, adaptive event definitions. The system learns from historical traffic flow data and automatically updates event patterns, allowing the priority determination mechanism to adapt to new attack types and evolve over time without manual reconfiguration, thus maintaining both simplicity and accuracy
Solution Approach 2:
The patent changes parameters by using multiple attributes of traffic flow (packet size, frequency, timing patterns, protocol types) instead of relying on a single pre-defined event category. This multi-parameter approach enables more nuanced priority determination that captures the complexity of modern cyber threats while maintaining an automated process
2Adaptability or versatility
If no events are defined in advance, then the system is more adaptable to new attack types, but the accuracy of determining the importance of unauthorized access deteriorates
Solution Approach 1:
The patent applies preliminary action by pre-processing and storing historical traffic flow data in a structured manner before it is needed for priority determination. The system performs preliminary learning and pattern recognition on historical data, building a knowledge base that enables accurate and adaptive priority assessment when new security alerts occur
Solution Approach 2:
The patent implements feedback mechanisms where the priority determination results and analyzed traffic patterns are fed back into the system to continuously refine event definitions and improve future determinations. This closed-loop approach enables the system to adapt to new attack types while maintaining and improving accuracy over time through iterative learning
3Measurement precision
If multiple attributes of traffic flow are analyzed, then the accuracy of priority determination is improved, but the device complexity increases
Solution Approach 1:
The patent applies segmentation by dividing the complex analysis into distinct functional modules: traffic flow collection, attribute extraction, historical data storage, similarity comparison, and priority determination. Each module handles a specific aspect of the multi-attribute analysis, making the overall complex system manageable and maintainable while achieving high accuracy through comprehensive attribute analysis
Data Source
AI summary
In a priority determination apparatus (10), a dissimilarity index calculation unit (11) calculates a dissimilarity index between a transmission/reception performance record of a first traffic flow related to a first security alert notified from a network-type intrusion detection apparatus and a transmission/reception performance record of a second traffic flow related to a second security alert notified from the network-type intrusion detection apparatus in the past, the network-type intrusion detection apparatus being configured to detect an attack on an apparatus in a network. A priority determination unit (12) determines a priority of the first security alert based on the dissimilarity index calculated by the dissimilarity index calculation unit (11).


