Security Alert Priority Determination via Traffic Dissimilarity Index

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing priority determination techniques for security alerts in network-type intrusion detection systems require pre-defined events, leading to potential inaccuracies in assessing the importance of unauthorized access.

Innovation Solution

A priority determination apparatus that calculates a dissimilarity index between transmission/reception performance records of current and past security alerts to determine the priority of new alerts, without the need for pre-defined events, using methods such as distribution difference indices and outlier detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If events are defined in advance for priority determination, then the determination process is simplified, but the accuracy of determining the importance of unauthorized access deteriorates

Engineering Contradiction:
Improvedetermination process simplicityVSAvoidpriority determination accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent applies dynamics by transitioning from static pre-defined events to dynamic, adaptive event definitions. The system learns from historical traffic flow data and automatically updates event patterns, allowing the priority determination mechanism to adapt to new attack types and evolve over time without manual reconfiguration, thus maintaining both simplicity and accuracy

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes parameters by using multiple attributes of traffic flow (packet size, frequency, timing patterns, protocol types) instead of relying on a single pre-defined event category. This multi-parameter approach enables more nuanced priority determination that captures the complexity of modern cyber threats while maintaining an automated process

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If no events are defined in advance, then the system is more adaptable to new attack types, but the accuracy of determining the importance of unauthorized access deteriorates

Engineering Contradiction:
Improvesystem adaptability to new attacksVSAvoidpriority determination accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent applies preliminary action by pre-processing and storing historical traffic flow data in a structured manner before it is needed for priority determination. The system performs preliminary learning and pattern recognition on historical data, building a knowledge base that enables accurate and adaptive priority assessment when new security alerts occur

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the priority determination results and analyzed traffic patterns are fed back into the system to continuously refine event definitions and improve future determinations. This closed-loop approach enables the system to adapt to new attack types while maintaining and improving accuracy over time through iterative learning

Inventive Principle:
Principle #23Feedback

3Measurement precision

If multiple attributes of traffic flow are analyzed, then the accuracy of priority determination is improved, but the device complexity increases

Engineering Contradiction:
Improvepriority determination accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the complex analysis into distinct functional modules: traffic flow collection, attribute extraction, historical data storage, similarity comparison, and priority determination. Each module handles a specific aspect of the multi-attribute analysis, making the overall complex system manageable and maintainable while achieving high accuracy through comprehensive attribute analysis

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11956256B2Priority determination apparatus, priority determination method, and computer readable medium
Publication Date: 2024.04.09 NEC CORP
  • US11956256B2 patent drawing
  • US11956256B2 patent drawing
  • US11956256B2 patent drawing

AI summary

In a priority determination apparatus (10), a dissimilarity index calculation unit (11) calculates a dissimilarity index between a transmission/reception performance record of a first traffic flow related to a first security alert notified from a network-type intrusion detection apparatus and a transmission/reception performance record of a second traffic flow related to a second security alert notified from the network-type intrusion detection apparatus in the past, the network-type intrusion detection apparatus being configured to detect an attack on an apparatus in a network. A priority determination unit (12) determines a priority of the first security alert based on the dissimilarity index calculated by the dissimilarity index calculation unit (11).