Virtual Malicious Traffic Template Generation for IoT Terminal Groups
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the IoT environment, existing machine learning algorithms for detecting malicious code infections in terminal groups are economically inefficient and have low accuracy due to unrefined data models, necessitating a method to generate an optimal learning model for monitoring systems.
Innovation Solution
A method and apparatus for generating a virtual malicious traffic template using traffic data from devices infected or not infected with malicious code, incorporating behavior analysis information to create a malicious traffic template for the terminal group, which can be used to develop an optimal learning model for machine learning-based monitoring systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If machine learning algorithms use unrefined data models for malicious code detection, then the detection system can be implemented quickly, but the detection accuracy is low and resource efficiency is poor
Solution Approach 1:
The patent applies preliminary action by pre-processing traffic data to generate refined data models before machine learning detection. The system collects traffic data from terminal groups, processes it through specific algorithms to create refined data models, and then uses these pre-refined models for detection. This preliminary refinement step ensures high detection accuracy while maintaining reasonable computational efficiency during actual monitoring operations.
2Productivity
If machine learning algorithms use unrefined data models, then the system can operate with simpler processing, but resource waste occurs due to economic inefficiency
Solution Approach 1:
The patent applies parameter changes by transforming traffic data parameters into refined data model parameters through systematic processing. The system changes the state of raw traffic data by applying filtering, aggregation, and transformation operations that convert unrefined data into optimized data models with improved statistical properties, thereby enhancing both detection accuracy and resource efficiency simultaneously.
3Measurement precision
If traffic data from infected devices is collected and analyzed, then accurate malicious traffic templates can be generated, but the system complexity increases
Solution Approach 1:
The patent applies segmentation by dividing the traffic data processing into distinct segments: data collection from terminal groups, malicious traffic identification, template generation, and model training. By segmenting the complex process into manageable stages with specific functions at each stage, the system achieves high template accuracy while controlling overall system complexity through modular architecture.
Solution Approach 2:
The patent introduces an intermediary processing layer that acts as a mediator between raw traffic data and the final detection model. This intermediary layer includes data refinement modules that transform raw traffic data into structured formats suitable for template generation, thereby simplifying the overall system architecture while maintaining high accuracy in malicious traffic detection.
Data Source
AI summary
There is provided a method of generating malicious traffic, the method being performed by a computing apparatus and comprising obtaining traffic data transmitted from a first device infected with first malicious code or received by the first device, generating a traffic template of the first device by analyzing the traffic data, and generating a malicious traffic template of a terminal group, wherein the malicious traffic template of the terminal group comprises the traffic template of the first device.


