Digital Filter Correlation Engine for SSH Login Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems are inadequate in detecting stealthy login attacks that occur over extended periods, such as days, weeks, or months, as they rely on frequency-based approaches that fail to recognize sporadic or long-duration attacks, leading to missed detections and high false alarm rates.
Innovation Solution
A digital filtering and correlation engine system that automatically detects login attacks by analyzing event occurrences over various time periods, using digital event filters to set thresholds for alarm conditions, reducing manual effort and false alarms, and providing a flexible framework for recognizing long-term attack patterns.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If frequency-based detection approaches are used to detect login attacks, then brute force attacks occurring at high frequency can be detected, but stealthy attacks spaced out over days, weeks, or months cannot be detected
Solution Approach 1:
The system dynamically adjusts the detection time window based on the attack pattern being analyzed. It can switch between short-term frequency-based detection (for brute force attacks) and long-term correlation-based detection (for stealthy attacks), making the detection mechanism adaptable to different attack tempos and patterns.
Solution Approach 2:
The patent introduces a temporal dimension to attack detection by correlating events across multiple time scales (seconds, days, weeks, months). Instead of detecting attacks solely based on frequency within a fixed window, the system analyzes attack patterns across extended time periods, adding a chronological dimension that enables detection of both rapid and slow-paced attacks.
2Productivity
If traditional detection systems monitor attack frequency over short time periods, then high-frequency brute force attacks can be identified, but low-frequency attacks occurring over extended periods remain undetected
Solution Approach 1:
The detection system segments the analysis into multiple time-based layers: short-term frequency analysis for immediate threats, medium-term pattern recognition for ongoing attacks, and long-term correlation for stealthy persistent threats. Each segment handles specific attack patterns, improving both response speed for urgent cases and detection reliability for subtle cases.
Solution Approach 2:
The patent implements nested detection windows where short-term frequency analysis is embedded within medium-term patterns, which are in turn embedded within long-term correlations. This nested structure allows the system to maintain sensitivity to rapid attacks while simultaneously detecting slow-paced threats, achieving both speed and reliability.
3Object-affected harmful factors
If detection thresholds are set to trigger on multiple failed login attempts within a short period, then false alarms increase for legitimate users, but the system can effectively block obvious brute force attacks
Solution Approach 1:
The system performs preliminary correlation analysis on attack patterns before triggering blocking actions. By pre-establishing temporal patterns and correlating events across different time scales, the system can distinguish between coordinated attack attempts (which show characteristic temporal patterns) and legitimate user behavior, reducing false positives while maintaining attack blocking effectiveness.
Solution Approach 2:
The detection system incorporates feedback mechanisms that adjust thresholds and sensitivity based on observed patterns. When the system detects coordinated attack patterns across multiple time scales, it automatically lowers thresholds for those specific sources. When legitimate usage patterns are observed, thresholds are maintained or raised, ensuring both security effectiveness and user accessibility.
Data Source
AI summary
A digital filter correlation engine, wherein the correlation engine combines N arbitrary digital filter states based on the weights and along with a threshold generate a network incident. This network incident in turn can be feedback to another digital filter. This multi-layering capability allows the creation of higher level event detections that are time-based for a cyber security analyst to analyze, thereby reducing the amount of manual work the analyst has to do in inspecting behaviors within the network.


