Virtual Malicious Traffic Template Generation for IoT Terminal Groups

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the IoT environment, existing machine learning algorithms for detecting malicious code infections in terminal groups are economically inefficient and have low accuracy due to unrefined data models, necessitating a method to generate an optimal learning model for monitoring systems.

Innovation Solution

A method and apparatus for generating a virtual malicious traffic template using traffic data from devices infected or not infected with malicious code, incorporating behavior analysis information to create a malicious traffic template for the terminal group, which can be used to develop an optimal learning model for machine learning-based monitoring systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If machine learning algorithms use unrefined data models for malicious code detection, then the detection system can be implemented quickly, but the detection accuracy is low and resource efficiency is poor

Engineering Contradiction:
Improvedetection accuracyVSAvoiddata model complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-processing traffic data to generate refined data models before machine learning detection. The system collects traffic data from terminal groups, processes it through specific algorithms to create refined data models, and then uses these pre-refined models for detection. This preliminary refinement step ensures high detection accuracy while maintaining reasonable computational efficiency during actual monitoring operations.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If machine learning algorithms use unrefined data models, then the system can operate with simpler processing, but resource waste occurs due to economic inefficiency

Engineering Contradiction:
Improveresource efficiencyVSAvoidcomputational resource waste
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent applies parameter changes by transforming traffic data parameters into refined data model parameters through systematic processing. The system changes the state of raw traffic data by applying filtering, aggregation, and transformation operations that convert unrefined data into optimized data models with improved statistical properties, thereby enhancing both detection accuracy and resource efficiency simultaneously.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If traffic data from infected devices is collected and analyzed, then accurate malicious traffic templates can be generated, but the system complexity increases

Engineering Contradiction:
Improvetraffic template accuracyVSAvoidsystem processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the traffic data processing into distinct segments: data collection from terminal groups, malicious traffic identification, template generation, and model training. By segmenting the complex process into manageable stages with specific functions at each stage, the system achieves high template accuracy while controlling overall system complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary processing layer that acts as a mediator between raw traffic data and the final detection model. This intermediary layer includes data refinement modules that transform raw traffic data into structured formats suitable for template generation, thereby simplifying the overall system architecture while maintaining high accuracy in malicious traffic detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11245712B2Method and apparatus for generating virtual malicious traffic template for terminal group including device infected with malicious code
Publication Date: 2022.02.08 KOREA INTERNET & SECURITY AGENCY
  • US11245712B2 patent drawing
  • US11245712B2 patent drawing
  • US11245712B2 patent drawing

AI summary

There is provided a method of generating malicious traffic, the method being performed by a computing apparatus and comprising obtaining traffic data transmitted from a first device infected with first malicious code or received by the first device, generating a traffic template of the first device by analyzing the traffic data, and generating a malicious traffic template of a terminal group, wherein the malicious traffic template of the terminal group comprises the traffic template of the first device.