Automated Traffic Variance Finder for Attack Pattern Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Online service providers face challenges in detecting and identifying computing attacks, such as HTTP smuggling and DDoS attacks, due to the complexity of malicious network traffic logs and the difficulty in determining the scale and sources of these attacks, which can lead to increased risk and fraud.

Innovation Solution

A method is introduced to generate a log signature based on variance and spread analysis of malicious network traffic logs, allowing for the identification of similar logs from the same or different sources, using a weighted average of variance and spread values for each data field, and employing machine learning models to adjust weights for improved detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If service providers manually analyze malicious network traffic logs to identify attack patterns, then detection accuracy may be maintained, but the time and resources required increase significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables automated self-analysis of network traffic logs through machine learning models that automatically identify attack patterns, calculate variance metrics, and generate log signatures without requiring manual intervention, thereby maintaining detection accuracy while dramatically reducing analysis time

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical analysis processes with automated computational systems including machine learning models (random forest, gradient boosting, neural networks) that process log data, calculate variance and spread metrics, and generate signatures algorithmically, eliminating the time-consuming manual review process

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If service providers implement comprehensive monitoring of all network traffic logs to identify attack sources, then the scale and sources of attacks can be identified, but the complexity of processing and analyzing all logs increases

Engineering Contradiction:
Improveattack source identificationVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts only the most relevant features from comprehensive log data including IP address variance, geographic location spread, and temporal patterns, rather than processing all log attributes equally. This extraction of key discriminative features maintains attack source identification reliability while reducing processing complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different analysis methods and weighting to different log fields based on their local characteristics - for example, using variance analysis for IP addresses, geographic clustering for location data, and temporal analysis for timing patterns. This localized approach to data quality assessment improves identification reliability without requiring uniform complex processing of all fields

Inventive Principle:
Principle #3Local quality

3Measurement precision

If service providers use traditional signature-based detection methods, then known attack patterns can be identified, but new or variant attacks may go undetected

Engineering Contradiction:
Improvepattern matching accuracyVSAvoiddetection flexibility
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts its detection approach by using machine learning models that can identify both known attack patterns through traditional signature matching and novel attacks through anomaly detection based on variance metrics. The model weights and thresholds are dynamically adjusted based on learned patterns, enabling flexibility to detect both established and emerging threats

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal log signature generation system that works across multiple attack types (DDoS, HTTP smuggling, fraud) and multiple machine learning algorithms (random forest, gradient boosting, neural networks). This multi-functional approach allows the same core methodology to detect diverse attack patterns, enhancing both precision and adaptability

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Measurement precision

If service providers analyze detailed variance and spread metrics for each log field, then more accurate attack identification is achieved, but the computational resources and processing time increase

Engineering Contradiction:
Improveattack identification accuracyVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system performs variance and spread analysis selectively on the most critical log fields (IP address, geographic location, user agent) rather than uniformly analyzing all fields. This partial action approach focuses computational resources on high-impact metrics that provide the greatest discrimination power, achieving accurate attack identification with reduced resource consumption

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent transforms detailed continuous variance and spread metrics into discrete log signature components with optimized weightings. By changing the parameter representation from fine-grained continuous values to weighted categorical signatures, the system maintains identification accuracy while reducing the computational burden of storing and comparing detailed metrics

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11582251B2Identifying patterns in computing attacks through an automated traffic variance finder
Publication Date: 2023.02.14 PAYPAL INC
  • US11582251B2 patent drawing
  • US11582251B2 patent drawing
  • US11582251B2 patent drawing

AI summary

There are provided systems and methods for identifying patterns in computing attacks through an automated traffic variance finder. A service provider, such as an electronic transaction processor for digital transactions, may determine network traffic logs caused or generated by malicious web traffic and network communications, such as during a computing attack by a bad actor. The service provider may generate a log signature for the network traffic log based on a variance or uniqueness of the network traffic logs IP address from other network traffic logs for each field in the network traffic log over a time period, and a spread in the commonality of the network traffic log with other network traffic logs. An aggregate score for each field may be determined based on the variance and the spread. Once determined, the log signature may be used to identify other network traffic logs through a search function.