Digital Filter Correlation Engine for SSH Login Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems are inadequate in detecting stealthy login attacks that occur over extended periods, such as days, weeks, or months, as they rely on frequency-based approaches that fail to recognize sporadic or long-duration attacks, leading to missed detections and high false alarm rates.

Innovation Solution

A digital filtering and correlation engine system that automatically detects login attacks by analyzing event occurrences over various time periods, using digital event filters to set thresholds for alarm conditions, reducing manual effort and false alarms, and providing a flexible framework for recognizing long-term attack patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If frequency-based detection approaches are used to detect login attacks, then brute force attacks occurring at high frequency can be detected, but stealthy attacks spaced out over days, weeks, or months cannot be detected

Engineering Contradiction:
Improvedetection capabilityVSAvoiddetection coverage across different attack patterns
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system dynamically adjusts the detection time window based on the attack pattern being analyzed. It can switch between short-term frequency-based detection (for brute force attacks) and long-term correlation-based detection (for stealthy attacks), making the detection mechanism adaptable to different attack tempos and patterns.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a temporal dimension to attack detection by correlating events across multiple time scales (seconds, days, weeks, months). Instead of detecting attacks solely based on frequency within a fixed window, the system analyzes attack patterns across extended time periods, adding a chronological dimension that enables detection of both rapid and slow-paced attacks.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If traditional detection systems monitor attack frequency over short time periods, then high-frequency brute force attacks can be identified, but low-frequency attacks occurring over extended periods remain undetected

Engineering Contradiction:
Improvedetection speedVSAvoiddetection accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The detection system segments the analysis into multiple time-based layers: short-term frequency analysis for immediate threats, medium-term pattern recognition for ongoing attacks, and long-term correlation for stealthy persistent threats. Each segment handles specific attack patterns, improving both response speed for urgent cases and detection reliability for subtle cases.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements nested detection windows where short-term frequency analysis is embedded within medium-term patterns, which are in turn embedded within long-term correlations. This nested structure allows the system to maintain sensitivity to rapid attacks while simultaneously detecting slow-paced threats, achieving both speed and reliability.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Object-affected harmful factors

If detection thresholds are set to trigger on multiple failed login attempts within a short period, then false alarms increase for legitimate users, but the system can effectively block obvious brute force attacks

Engineering Contradiction:
Improveattack blocking effectivenessVSAvoiduser accessibility
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system performs preliminary correlation analysis on attack patterns before triggering blocking actions. By pre-establishing temporal patterns and correlating events across different time scales, the system can distinguish between coordinated attack attempts (which show characteristic temporal patterns) and legitimate user behavior, reducing false positives while maintaining attack blocking effectiveness.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The detection system incorporates feedback mechanisms that adjust thresholds and sensitivity based on observed patterns. When the system detects coordinated attack patterns across multiple time scales, it automatically lowers thresholds for those specific sources. When legitimate usage patterns are observed, thresholds are maintained or raised, ensuring both security effectiveness and user accessibility.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8776226B2Method and apparatus for detecting SSH login attacks
Publication Date: 2014.07.08 BAE SYSTEMS INFORMATION ANDELECTRONIC SYSTEMS INTEGRATION INC
  • US8776226B2 patent drawing
  • US8776226B2 patent drawing
  • US8776226B2 patent drawing

AI summary

A digital filter correlation engine, wherein the correlation engine combines N arbitrary digital filter states based on the weights and along with a threshold generate a network incident. This network incident in turn can be feedback to another digital filter. This multi-layering capability allows the creation of higher level event detections that are time-based for a cyber security analyst to analyze, thereby reducing the amount of manual work the analyst has to do in inspecting behaviors within the network.