Computer security based on artificial intelligence
By utilizing an AI-based computer security system that incorporates memory, processor, and database modules, the problem of relying on human experts for computer network security in existing technologies has been solved, achieving intelligent real-time defense and risk reduction.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- 赛义德卡姆兰哈桑
- Filing Date
- 2017-01-24
- Publication Date
- 2026-04-28
AI Technical Summary
Current computer network security relies on human experts to solve complex problems, making it difficult to effectively counter malicious exploitation by hackers. Traditional solutions can no longer meet the rapid expansion of computer and network capabilities.
It employs an AI-based computer security system, including memory, processor, and database. Through modules such as cloud & layered information security, prior real-time defense with zero database for logical inference, and critical thinking memory and perception, it provides intelligent analysis and defense mechanisms, simulates human thought processes, and adapts to computer hardware implementation.
It enables intelligent defense of computer networks, capable of analyzing and blocking malicious intents in real time, reducing system risks, and improving security and adaptability.
Smart Images

Figure CN115062297B_ABST
Abstract
Description
[0001] This application is a divisional application of the following application, whose international application number is PCT / US2017 / 014699, national application number is 201780019904.0, national phase entry date is September 20, 2018, and invention title is Computer Security Based on Artificial Intelligence.
[0002] Cross-references to related applications
[0003] This application claims protection for U.S. Provisional Application No. 62286437, filed January 24, 2016, entitled "Clandestine Machine Intelligence Retribution through Covert Operations in Cyberspace"; U.S. Provisional Application No. 62294258, filed February 11, 2016, entitled "Logically Inferred Zero-database A-priori Realtime Defense"; U.S. Provisional Application No. 62307558, filed March 13, 2016, entitled "Critical Infrastructure Protection & Retribution (CIPR) through Cloud & Tiered Information Security (CTIS)"; and U.S. Provisional Application No. 62307558, filed April 16, 2016, entitled "Critical Thinking". U.S. Provisional Application No. 62323657, entitled "Memory & Perception"; U.S. Provisional Application No. 62326723, entitled "Linear Atomic Quantum Information Transfer (LAQIT)" filed April 23, 2016; U.S. Provisional Application No. 62341310, entitled "Objective Debate Machine (ODM)" filed May 25, 2016; and U.S. Provisional Application No. 62439409, entitled "Lexical Objectivity Mining (LOM)" filed December 27, 2016; and U.S. Provisional Application No. 62439409, entitled "METHOD AND DEVICE FOR MANAGING SECURITY IN A COMPUTER" filed May 4, 2016. The priority of U.S. Patent Application No. 15145800, entitled NETWORK (Methods and Apparatus for Managing Security in Computer Networks); and U.S. Patent Application No. 15264744, filed September 14, 2016, entitled SYSTEM OF PERPETUAL GIVING (System for Perpetual Giving), are incorporated herein by reference, as they are set forth herein. Technical Field
[0004] This invention relates to a computer security system based on artificial intelligence. The subsystems include: Critical Infrastructure Protection & Punishment (CIPR) via Cloud & Layered Information Security (CTIS); Machine Secret Intelligence (MACINT) & Punishment via Covert Operations in Cyberspace; Prior Real-Time Defense with a Zero-Database Logical Inference System (LIZARD); Critical Thinking Memory & Perception (CTMP); Lexical Objectivity Mining (LOM); Linear Atom Quantum Information Transfer (LAQIT); and a Universal BCHAIN All Matters Connection (UBEC) system with basic connectivity coordination attachment integration nodes. Background Technology
[0005] Computer network security issues often rely on human experts to solve complex problems. The rapid expansion of computer and network capabilities has led to exploitation by malicious entities, including hackers, overshadowing traditional solutions that ultimately depend on human experts. Artificial intelligence-driven strategies are emerging as a solution to overcome these limitations. However, these new strategies require advanced models that can effectively simulate human thought processes and are adaptable to implementation through computer hardware. Summary of the Invention
[0006] An AI-based computer security system, comprising: a memory storing programming instructions; a processor coupled to the memory and executing the programming instructions; and at least one database, wherein the system includes a computer-implemented system providing specified functions.
[0007] The system implemented by this computer utilizes Cloud & Layered Information Security (CTIS) Critical Infrastructure Protection & Penalty (CIPR), which further includes:
[0008] a) Trusted platforms, which include networks of spies that report hacking activities;
[0009] b) Managed Network & Security Service Providers (MNSPs) that provide managed cryptographic security, connectivity & compliance solutions & services;
[0010] The Virtual Private Network (VPN) connects the MNSP and the trusted platform, providing communication channels to and from the trusted platform. The MNSP is adapted to analyze all services within the enterprise network, which are then routed to the MSNP.
[0011] The MNSP includes:
[0012] a) LIZARD, a priori real-time defense for logical inference zero databases, derives purpose and function from foreign code and thus blocks it in the presence of malicious intent or lack of legitimate cause, and analyzes the threats within and on itself without reference to prior historical data;
[0013] b) Human-induced security threats (AST), which provide hypothetical security scenarios for testing the effectiveness of a set of security rules;
[0014] c) The creative module, which performs the process of intelligently creating new hybrid forms beyond a priori forms;
[0015] d) Conspiracy detection identifies patterns of information collaboration and security-related behaviors, provides routine background checks for multiple conspiracy security incidents, and attempts to determine patterns and correlations between seemingly unrelated security incidents;
[0016] e) Security behaviors, their stored events, and their security responses and characteristics, and indexing them, where the response includes blocking / approval decisions;
[0017] f) Iterative intelligent growth / intelligent evolution (I) 2 GE), which utilizes big data and malware signature identification, and simulates potential future changes in malware by leveraging AST and creative modules; and
[0018] g) Critical Thinking, Memory, and Perception (CTMP), whose critical thinking prevents / approves decision-making and acts as a supplementary layer of security, and utilizes information from I 2 Cross-reference intelligence from GE, LIZARD, and trusted platforms, where CTMP estimates its own ability to form objective decisions about matters and will avoid maintaining decisions made in situations of low internal confidence.
[0019] The LIZARD Lite client is adapted to operate on devices within an enterprise network and to communicate securely with LIZARD in the MNSP.
[0020] The Demilitarized Zone (DMZ) includes subnets that contain HTTP servers with a higher level of security responsibility than normal computers, so that the rest of the corporate network does not bear such security responsibility.
[0021] I 2 GE includes iterative evolution, in which parallel evolutionary paths mature and are selected, iterative generations are applicable to the same human-induced security threats (AST), and the path with the best personality traits is ultimately the most resistant to security threats.
[0022] The LIZARD includes:
[0023] a) The syntax module provides a framework for reading and writing computer code;
[0024] b) The destination module, which uses the syntax module to derive the destination from the code and outputs the destination in its complex destination format;
[0025] c) Virtual obfuscation, in which the enterprise network and database are cloned in a virtual environment and sensitive data is replaced with fake (false) data, where the environment can be dynamically changed in real time to include more fake elements or more real elements of the entire system, depending on the target’s behavior.
[0026] d) Signal simulation, which provides a form of penalty when a virtual confusion analysis conclusion has been reached;
[0027] e) Internal consistency check, which examines all internal functions containing meaningful external code;
[0028] f) Foreign code rewriting, which uses syntax modules and target modules to reduce foreign code to complex target formats;
[0029] g) Hidden code detection, which detects code hidden in data and transmission packets;
[0030] h) Mapping matching is required, which is a hierarchy of mappings for the required and intended purposes and is referenced to determine whether foreign code fits the overall goals of the system;
[0031] For writing, the syntax module receives complex-formatted targets from the target module, then writes code using arbitrary code syntax, and the help function translates this arbitrary code into actual executable code; for reading, the syntax module provides the target module with a syntactic interpretation of the code so as to derive the target's functionality for such code.
[0032] The signal simulation uses a syntax module to understand the communication syntax between the malware and its hacker, and then hijacks such communication to give the malware the false impression that it has successfully sent sensitive data back to the hacker, while the hacker also sends the malware's error code through LIZARD, making it appear as if it came from the malware.
[0033] Foreign code rewriting uses the exported purpose to build the code set, thereby ensuring that only the expected and understood purpose of the foreign code is executed within the enterprise, and that no unintended function execution can gain access to the system.
[0034] To enable foreign code rewriting to syntactically reproduce the foreign code and mitigate potential undetected malicious exploitation, the composition method compares and matches the declared purpose with the exported purpose, where the purpose module is used to manipulate complex purpose formats. In the case of an exported purpose, the mapping match needs to maintain the hierarchy to maintain jurisdiction over all enterprise needs, so that the purpose of the code block is defined and proven reasonable, depending on the gaps in the need mapping oriented by jurisdiction, where the input purpose is the introduction of a recursive debugging process.
[0035] The recursive debugging loop tests for errors and applies error fixes through code segments. If an error persists, the entire code segment is replaced with the original foreign code segment, which is then tagged for virtual obfuscation and behavioral analysis. In the case of foreign code, the original state of the code is interpreted by the target module and syntax module used for code rewriting. In the case where the original foreign code segment needs to be installed due to a permanent error in the rewritten version, the debugger directly references the foreign code. At the rewritten code location, the segment is tested by the virtual runtime environment to check for coding errors. The virtual runtime environment executes the code segment and checks for runtime errors. In the case of coding errors, the errors generated in the virtual runtime environment are defined in terms of scope and type. In the case of target alignment, potential solutions to coding errors are formulated by re-deriving code from the stated target. The scope of the coding error is rewritten in an alternative format to avoid such errors. Potential solutions are output. If no solution is retained, the code rewrite for that segment is lost, and the original code segment directly from the foreign code is used in the final code set.
[0036] For operations requiring mapping matching, LIZARD Cloud and LIZARD Lite reference the hierarchical mapping of enterprise jurisdiction branches. Regardless of whether the input purpose is declared or exported via a destination module, the mapping matching verifies the legitimacy of executing code / functions within the enterprise system. The master copy of the hierarchical mapping is stored on LIZARD Cloud in MNSP. The requirement index within the requirement mapping matching is calculated by referencing the master copy. The pre-optimized requirement index is distributed across all accessible endpoint clients. The requirement mapping matching receives the requirement request that best suits the needs of the entire system, and the corresponding output is a complex destination format representing the appropriate requirement.
[0037] Essentially, the entire LAN infrastructure of an enterprise is rebuilt within the MNSP, whereby hackers are exposed to elements of both the real LAN infrastructure and the virtual clone version when performing behavioral analysis on the system. If the results of such analysis indicate a risk, the hacker's exposure to the virtual clone infrastructure increases to reduce the risk of real data and / or equipment being compromised.
[0038] Provide the malware root signature to the AST to enable the formation of iterations / variants of the malware root signature, where polymorphic variants of the malware are provided as originating from I. 2 GE's output is then transferred to malware detection.
[0039] Malware detection is deployed across all three levels of the computer's composition, including user space, kernel space, and firmware / hardware space, all of which are monitored by Lizard Lite spyware.
[0040] The system implemented by this computer utilizes Machine Secret Intelligence (MACINT) and punishment through covert operations in cyberspace, further including:
[0041] a) Intelligent Information and Configuration Management (I) 2 CM), which provides intelligent information management, viewing, and control; and
[0042] b) Management console (MC), which provides input / output channels for users:
[0043] Where I 2 CM includes:
[0044] i) Aggregation, which uses general-level criteria to filter out unimportant and redundant information, and merges and tags information streams from multiple platforms;
[0045] ii) Configuration and deployment services, including interfaces for deploying new enterprise network devices with predetermined security configurations and connectivity settings, and for managing the deployment of new user accounts;
[0046] iii) Separate by jurisdiction, in which the information pool of tags is specifically separated according to the relevant jurisdiction of the user in the management console;
[0047] iv) Separate by threat, which organizes information based on individual threats;
[0048] as well as
[0049] v) Automated control, which accesses the MNSP cloud, trusted platform, or additional third-party services.
[0050] In the MNSP cloud, behavioral analysis observes the state and actions of malware when it is in a fake data environment. When malware attempts to send fake data to a hacker, the emitted signal is rerouted so that it is received by the fake hacker. The hacker interface receives the code structure of the malware and reverse-engineers its internal structure to output the hacker interface. Fake hackers and fake malware are simulated in a virtualized environment. The virtualized fake hacker sends response signals to the real malware to observe the malware's next behavioral pattern, providing the hacker with a fake response code that is not related to the behavior / state of the real malware.
[0051] The ability and characteristics of exploit scanning to identify criminal assets and the resulting scan results are managed by exploits. These exploits are sent by a trusted platform via a punitive exploit database that penetrates the target criminal system. The punitive exploit database contains a means of criminal activity provided by hardware vendors in the form of established backdoors and known vulnerabilities. The unified court evidence database contains compiled court evidence from multiple sources across multiple enterprises.
[0052] When a dormant spy from a criminal system captures files on the corporate network, the firewall generates logs that are forwarded to a log aggregation, which categorizes the data into long-term / deep scans and real-time / surface scans.
[0053] Deep scanning contributes to and participates in big data analytics, while utilizing conspiracy detection and foreign entity management sub-algorithms. Standard logs from security checkpoints are aggregated at the log aggregation point and selected using low-restriction filters. Event indexing and tracking store event details. Anomaly detection uses event indexing and security behaviors based on intermediate data provided by the deep scanning module to identify any potential risk events. Foreign entity management and conspiracy detection are involved in the analysis of events.
[0054] The trusted platform searches for any computer to check whether it or its server relatives / neighbors (other servers connected to it) have previously established double or triple espionage for the trusted platform; where spy search checks are performed at the trusted double spy index + tracking cloud and the trusted triple spy index + tracking cloud; where the double spy trusted by the arbitrary computer pushes an exploit through its trusted channel, where the exploit attempts to find sensitive files, isolate them, send their precise status back to the trusted platform, and then attempt to erase them from the criminal computer.
[0055] ISP API requests are made to arbitrary systems via a trusted platform and in network surveillance logs, and potential files transferred to criminal computers are discovered. Metadata is used to determine the weight of confidence in which computer to send the files. Network surveillance discovers network details of the criminal computers and reroutes this information to the trusted platform, which is used to engage with secure APIs provided by software and hardware vendors to exploit any established backdoors that can aid in judicial investigations.
[0056] A trusted platform pushes software or firmware updates to a criminal computer to create a new backdoor, where a placebo update is pushed to a nearby similar machine to remain stealthy, where the target's identity details are sent to the trusted platform, where the trusted platform communicates with software / firmware maintainers to push placebo updates and backdoor updates to the relevant computers, where the backdoor update introduces a new backdoor into the criminal computer's system by using a pre-built software update system installed on the computer, where the placebo update ignores the backdoor, where the maintainer transfers the backdoor to the target, and to computers with higher than the target's average exposure, where sensitive files are isolated and copied during exploitation via a backdoor update for subsequent analysis of their metadata usage history, where any supplementary forensic data is collected and sent to the exploit contact point at the trusted platform.
[0057] Long-term priority flags are pushed to a trusted platform to monitor any and all changes / updates to the criminal system, where the enterprise system submits targets to an authorization module that scans all subsidiary system inputs to obtain any associations with the defined targets. If any match is found, the information is passed to the enterprise system, which grants authorization and attempts to penetrate the target, where the input is transferred to the desired analysis module, which synchronizes mutually beneficial security information.
[0058] The computer-implemented system is a priori real-time defense against logical inference zero databases (LIZARD), which further includes:
[0059] a) Static kernel (SC), which mainly consists of fixed program modules;
[0060] b) Iterative modules, which modify, create, and destroy modules on a dynamic shell, wherein the iterative modules use an AST for security reference and an iterative kernel to handle automated code writing methods;
[0061] c) Differential Modifier Algorithm, which corrects the basic iteration based on the defects found by AST, in which a new iteration is proposed after applying differential logic, at which point the iteration kernel is recursively called and undergoes the same process tested by AST.
[0062] d) Logical deduction algorithm, which receives known security responses from dynamic shell iterations of AST, where LDA deduces what code set constitutes the known correct response to the security scenario;
[0063] e) Dynamic Shell (DS), which mainly contains dynamic program modules that have been automatically programmed by Iterative Module (IM);
[0064] f) Code isolation, which isolates external code into a constrained virtual environment;
[0065] g) Stealth code detection, which detects codes secretly embedded in data and transmission packets; and
[0066] h) Foreign code rewriting, which rewrites part or all of the code itself after the purpose of exporting foreign code and allows only the rewrite to be executed;
[0067] All enterprise devices are routed through LIZARD, where all software and firmware running the enterprise devices are hardcoded to perform any kind of download / upload via LIZARD, which acts as a permanent agent. LIZARD interacts with three types of data, including data in motion, data in use, and data at rest, and with data media including files, emails, networks, mobile devices, the cloud, and removable media.
[0068] The system further includes:
[0069] a) AST overflow repeater, where data is relayed to the AST for further iterative improvement when the system can only perform low-confidence decisions;
[0070] b) Internal consistency check, which checks whether all internal functions of the external code block are meaningful;
[0071] c) Mirror testing, which checks to ensure that the rewritten input / output dynamics are the same as the original, thus making any hidden exploits in the original code redundant and never executed;
[0072] d) Mapping matching is required, which includes a hierarchy of mappings that are referenced to determine whether the foreign code fits the overall goals and objectives of the system.
[0073] e) A real data synchronizer that selects the data to be given to the merging environment and what priority to give it, thereby preventing suspicious malware from accessing sensitive information.
[0074] f) Data Manager, which is the intermediary interface between entities and data from outside the virtual environment;
[0075] g) Virtual obfuscation, which obfuscates and restricts code by gradually and partially immersing it in a virtualized dummy environment;
[0076] h) A covert delivery module that silently and discretely transfers malware into a fake data environment; and
[0077] i) Data callback tracking, which tracks all information uploaded and downloaded from the suspicious entity to the suspicious entity.
[0078] The system also includes a purpose comparison module, in which four different types of purposes are compared to ensure that the existence and behavior of entities are worthy of and understood by LIZARD in the production toward the overall goal of the system.
[0079] This iterative module uses SC to perform syntax corrections on the DS codebase according to the purpose defined in the Data Return Relay (DRR), where the corrected version of LIZARD is stress-tested in parallel with multiple parallel versions and the security scenario is changed via AST.
[0080] Within SC, logical deduction derives logically necessary functions from the initial, simpler functions, thereby constructing the entire function dependency tree from the complex purpose being explained.
[0081] The code translation will convert any general code that is directly understood by the syntax module into any chosen known computer language, and will also perform the inverse operation of translating a known computer language into any code;
[0082] The logic reduction involves reducing the logic written in code to a simpler form to produce a mapping of interconnected functions;
[0083] The complex destination format is a storage format used to store interconnected sub-destination representations of the overall destination;
[0084] The purpose association refers to a hard-coded reference indicating what kind of purpose the function and type of behavior represent.
[0085] The iterative expansion adds details and complexity by referencing the objective association, thereby evolving a simple objective into a complex one;
[0086] The iterative interpretation traverses all interconnect functions and generates an interpretation target by associating with a reference target;
[0087] The outer kernel consists of syntax and purpose modules that work together to derive logical purposes into unknown foreign code and generate executable code based on the stated function code objectives.
[0088] The foreign code is unknown to LIZARD and its function and intended purpose are unknown. The foreign code is an input to the internal kernel and its derived purpose is an output. The derived purpose is the intent of the given code estimated by the target module. The derived purpose is returned in a complex purpose format.
[0089] IM uses the AST for security performance reference and uses an iterative kernel to handle automated code writing methods. At the DRR, when LIZARD has to resort to making decisions with low confidence, data about malicious attacks and bad actors is relayed to the AST. Inside the iterative kernel, the Differential Modifier Algorithm (DMA) receives syntax / purpose programming capabilities and system goal guidance from the internal kernel and uses such a code set to correct the basic iteration based on the flaws found in AST 17. The security outcome flaws are visually presented to indicate the security threats transferred through the basic iteration when running the virtual execution environment.
[0090] Within the DMA, the current state represents a dynamic set of shell codes with symbolically related shapes, sizes, and positions, where different configurations of these shapes indicate different configurations of security intelligence and responses, and the AST provides any potential responses to the current state that happen to be incorrect as well as what the correct response is.
[0091] The attack vector serves as a symbolic representation of a cybersecurity threat, with its direction, size, and color all related to assumed security attributes (such as the attack vector, the size of the malware, and the type of malware). The attack vector symbolically pops off the code set to represent the code set's security response.
[0092] The correct state represents the final result of the DMA process of generating the desired security response from the code block of the dynamic shell, where the difference between the current state and the correct state leads to different attack vector responses;
[0093] The AST provides known security vulnerabilities along with the correct security response, where the logical deduction algorithm uses previous iterations of the DS to produce a better and more equipped iteration of the dynamic shell known as the correct security response procedure.
[0094] In virtual obfuscation, suspicious code is covertly assigned to an environment where half of the data is intelligently merged with fake data. Any entity operating within the real system can easily and covertly transfer to a partially or completely fake data environment due to virtual isolation. The fake data generator uses a real data synchronizer as a template for creating counterfeit and useless data. The perceived confidence risk of the incoming foreign code will affect the obfuscation level chosen by LIZARD. A high confidence level for malicious code will result in an assignment to an environment containing a large amount of fake data, while a low confidence level for malicious code can result in an assignment to either a real system or a 100% fake data environment.
[0095] Data recall tracking maintains a record of all information uploaded to and downloaded from a suspicious entity; where, in the event that false data has been sent to a legitimate entity, a callback is executed for all false data, and real data is sent in lieu of it; where a callback trigger is implemented so that the legitimate entity does not take action on certain information until there is confirmation that the data is not false.
[0096] Behavioral analysis tracks the download and upload behavior of suspicious entities to identify potential corrective actions. The real system contains raw, genuine data that exists entirely outside the virtualized environment. The real data used to replace fake data is provided unfiltered to the data recall tracking system, allowing for the creation of real data patches to replace fake data on previously suspicious entities. A data manager immersed in a virtual, isolated environment receives real data patches from the data recall tracking system. When behavioral analysis has cleared harmless code as malicious, corrective actions are performed to replace the fake data in previously suspicious entities with the real data it represents. A secret token, a secure string generated and assigned by LIZARD, allows truly harmless entities to refrain from their operations. If the token is lost, this indicates a possible scenario where the legitimate entity may have been occasionally placed in a partially fake data environment due to a risk assessment of it as malware, subsequently activating a delayed session with a delayed interface. If the token is found, this indicates that the server environment is real, and therefore any delayed sessions are disabled.
[0097] Within behavioral analytics, purpose mapping is a hierarchical structure of system goals that assign purpose to the entire enterprise system. It compares declared, activity, and codebase purposes with the inherent system requirements of whatever a suspicious entity is supposedly doing. This includes monitoring the storage, CPU processing, and network activities of suspicious entities in the presence of activity monitoring; interpreting these activities according to desired functions by the syntax module; translating these functions into expected behavioral purposes by the purpose module; forwarding the source code / programming structure of the suspicious entity to the syntax module; understanding the coding syntax and reducing the programming code and code activities to intermediate mappings of interconnected functions; and generating suspicious entity... The output codebase purpose and activity purpose are perceived intentions, where the codebase purpose includes the known purpose, function, jurisdiction, and authority of the entity as derived from LIZARD's syntax programming capabilities, where the activity purpose includes the known purpose, function, jurisdiction, and authority of the entity as understood by LIZARD's understanding of its storage, processing, and network activities, where the declared purpose is the assumed purpose, function, jurisdiction, and authority of the entity as declared by the entity itself, where the required purpose includes the expected purpose, function, jurisdiction, and authority required by the enterprise system, where all purposes are compared in the comparison module, where any inconsistency between purposes will cause a deviation in the purpose scenario, which leads to corrective actions.
[0098] The computer-implemented system is Critical Thinking Memory & Perception (CTMP). This system further includes:
[0099] a) Critical Rules Scope Extender (CRSE), which takes advantage of the known scope of perception and expands it to include the scope of critical thinking.
[0100] b) Correct rules, which indicate correct rules derived through the use of the scope of critical thinking of perception;
[0101] c) Rule execution (RE), which is the execution of rules that have been identified as existing and implemented based on a scan of the chaotic field from memory to produce desired and relevant critical thinking decisions;
[0102] d) Critical decision output, which generates the final logic for determining the overall output of CTMP by comparing the conclusions drawn by the Perceived Observer Simulator (POE) and RE;
[0103] The POE generates a simulation of the observer and tests / compares all potential perceptual points under these changes in the observer simulation.
[0104] The RE includes a chessboard plane used to track the transformation of the rule set, wherein objects on the board represent the complexity of any given security situation, and the movement of these objects across the 'security chessboard' indicates the evolution of the security situation managed by the response of the security rule set.
[0105] The system further includes:
[0106] a) Subjective opinion decision-making, which is the decision provided by the selected pattern matching algorithm (SPMA);
[0107] b) Input system metadata, which includes raw metadata from SPMA that describes the mechanical process of the algorithm and how it reaches these decisions;
[0108] c) Reasoning processing, which uses comparative properties to logically understand assertions;
[0109] d) Rule processing, which uses the derived rules to determine the reference point for the scope of the current problem by their effects;
[0110] e) A memory network that scans market variable logs to obtain implementable rules;
[0111] f) The original perception is generated, which receives metadata logs from SPMA, wherein the logs are parsed and a perception representing the perception of this algorithm is formed, wherein the perception is stored in a perception complexity format (PCF) and simulated by POE; wherein the applied perception angle indicates the perception angle that has been applied and utilized by SPMA.
[0112] g) Automatic Perception Discovery Mechanism (APDM), which utilizes a creative module to generate hybrid perception based on inputs provided by the application's perception perspective, thereby increasing the range of perception.
[0113] h) Self-critical knowledge density (SCKD), which estimates the scope and type of potential unknown knowledge that cannot be obtained from the report log, thereby allowing the subsequent critical thinking characteristics of CTMP to utilize the potential scope of all knowledge involved; where critical thinking indicates the jurisdiction of the outer shell of rule-based thinking.
[0114] i) Implicit inference (ID), which derives the perspective of the perception data that may be implicit from the perspective of the current application;
[0115] SPMA juxtaposes perception and rules with the critical thinking performed by CTMP.
[0116] The system further includes:
[0117] a) Resource Management & Allocation (RMA), in which an adjustable strategy is used to indicate the amount of perception used to perform observer simulation, wherein the priority of the selected perception is chosen according to descending weights, and wherein the strategy then selects a truncation method rather than a percentage, a fixed number, or a more complex algorithm.
[0118] b) Storage Search (SS), which uses CVF derived from the data augmentation log as a criterion in database lookups of Perceptive Storage (PS), where, in addition to its associated weights, Perceptive Storage is also indexed in Comparable Variable Format (CVF).
[0119] c) Metric processing, which enables the reverse engineering of variable assignments from SPMA;
[0120] d) Perceptual deduction (PD), which uses the allocation response and its corresponding system metadata to reproduce the original perception of the allocation response;
[0121] e) Metadata Classification Module (MCM), in which syntax-based information classification is used to categorize debugging and algorithmic tracing into different categories, where the categories are used to organize and generate different allocation responses related to risk and opportunity;
[0122] f) Measurement combination, which categorizes perceptual angles into measurement categories;
[0123] g) Metric transformation, which reverses a single metric back to the entire perceptual perspective;
[0124] h) Metric extension (ME), which stores multiple and varying perception angles of metrics in separate databases by category;
[0125] i) Comparable Variable Format Generator (CVFG), which converts the information stream into a comparable variable format (CVF).
[0126] The system further includes:
[0127] a) Perceptual Match 503, where the CVF is formed from the perception received from the Rule Syntax Derivation (RSD); where the newly formed CVF is used to find the relevant perception in the PS using similar indices, where the potential match is returned to the Rule Syntax Generation (RSG).
[0128] b) Memory recognition (MR), in which a chaotic field 613 is formed from input data;
[0129] c) Memory concept index, in which the entire concept is optimized into an index separately, where the index is used by the letter scanner to interact with the chaotic field;
[0130] d) A rule implementation parser (RFP) receives the parts of a rule with identification tags, each part being identified by memory as either discovered or not discovered in the chaotic field; wherein the RFP logically deduces which overall rules (i.e., combinations of all their parts) should be fully identified in the chaotic field.
[0131] e) Rule Syntax Format Separation (RSFS), in which correct rules are separated and organized by type, thereby all actions, properties, conditions and objects are stacked separately;
[0132] f) Rule syntax derivation, in which logical 'black and white' rules are transformed into metric-based perceptions, thereby transforming the complex arrangement of multiple rules into a single unified perception expressed by multiple metrics via varying gradients.
[0133] g) Rule-based syntax generation (RSG), which receives previously confirmed perceptions, which are stored in a perception format and participate in the internal metric composition of perceptions, wherein such gradient-based measurements of the metrics are converted into a binary and logical rule set that simulates the input / output information flow of the original perceptions.
[0134] h) Rule Syntax Format Separation (RSFS), in which correct rules represent the precise representation of the rule set that conforms to the reality of the observed object. Thus, correct rules are separated and organized by type, and all actions, properties, conditions and objects are stacked separately, enabling the system to identify which parts are found in the chaotic field and which parts are not found.
[0135] i) Intrinsic logical deduction, which uses logical principles to avoid fallacies in deducing what kind of rules will accurately represent the many metric gradients within perception;
[0136] j) Metric context analysis, which analyzes interconnections within metric perception, where some metrics may depend on other metrics with different degrees of magnitude, where this contextualization is used to complement the mirrored interconnections of rules within a 'numerical' rule set format;
[0137] k) Rule Syntax Format Transformation (RSFC), which classifies and separates rules according to the syntax of Rule Syntax Format (RSF);
[0138] Intuitive decision-making involves critical thinking through the use of perception, while cognitive decision-making involves critical thinking through the use of rules. Perception is data received from intuitive decision-making according to a format grammar defined in an internal format, and the rules to be satisfied are data received from cognitive decision-making, which is a set of implementable rules from RE, wherein data is passed according to a format grammar defined in an internal format.
[0139] The action indicates an action that may have been performed, will be performed, or is being considered for activation; the property indicates an attribute of some kind that describes other things, whether it is an action, condition, or object; the condition indicates a logical operation or operator; and the object indicates a target that may have attributes that can be applied to it.
[0140] The separated rule formats are used as the output from Rule Syntax Format Separation (RSFS), which is considered the pre-memory recognition stage, and as the output from Memory Recognition (MR), which is considered the post-memory recognition stage.
[0141] The system further includes:
[0142] a) Chaotic Field Parsing (CFP), which combines the format of the log into a single scannable chaotic field 613;
[0143] b) Additional rules, generated from memory recognition (MR), to supplement the correct rules;
[0144] Within Perceptual Matching (PM), metric statistics provide statistical information from perceptual storage, error management parsing syntax, and / or logical errors originating from any of the individual metrics. Separate metrics isolate each individual metric because they were previously combined in a single unit as input perception. The Node Comparison Algorithm (NCA) receives nodes from two or more CVFs, where each node of the CVF represents the degree of quality value. Similarity comparisons are performed on a per-node basis, and the total variance is calculated, where a smaller variance indicates a closer match.
[0145] The system of the claims further includes:
[0146] a) Primitive perception-intuitive thinking (simulation), which processes perception according to the 'simulation' format, in which the simulation format perception related to decision is stored in the gradient on the orderless smooth curve;
[0147] b) Original rules - logical thinking (numbers), which process rules according to number format, where the original rules of number format related to decision-making are stored in order of magnitude from the smallest to the smallest 'gray area';
[0148] The unimplemented rules are the set of rules that are not sufficiently recognized in the chaotic field based on their logical dependencies, while the implemented rules are the set of rules that are sufficiently usable in the chaotic field 613 based on their logical dependencies.
[0149] Queue Management (QM) utilizes Syntax Relation Reconstruction (SRR) to analyze each individual part in the most logical order and accesses Memory Recognition (MR) results, thereby answering binary yes / no process questions and taking appropriate actions. QM checks each rule segment in stages, and if a single segment is missing in the chaotic field and has no proper relationship with other segments, the rule set is marked as unimplemented.
[0150] Sequential memory organization is an optimized information storage of sequential information "chains," where the width of each node (block) in the memory access points represents the observer's direct accessibility to the remembered object (node), where each letter within the range of accessibility represents its direct memory access point to the observer, where a wider range of accessibility indicates that each sequential node has more accessibility points (where more than one sequence is referenced 'in sequence' rather than from any randomly selected node), and the narrower the range of accessibility (relative to the sequence size), where, in the case of nested subsequence layers, a sequence exhibiting strong non-uniformity consists of a series of interconnected smaller subsequences.
[0151] Non-sequential memory organization processes the storage of information about non-sequential related items, where reversibility indicates non-sequential arrangement and uniformity, where non-sequential relationships are indicated by relatively wide access points for each node, where the same uniformity exists when the order of nodes is reshuffled, where the same series of nodes are repeated but have different cores (central objects) in core topics and associations, where the core represents the main topic and the remaining nodes act as memory neighbors for that main topic, which can be accessed more easily than in the absence of a defined core topic.
[0152] Memory recognition (MR) scans chaotic fields to identify known concepts, where a chaotic field is a 'field' of concepts arbitrarily immersed in 'white noise' information. Memory concepts retain identifiable concepts that are stored and ready for indexing and reference field checking. A 3-letter scanner scans the chaotic field and checks the 3-letter segment corresponding to the target. A 5-letter scanner scans the chaotic field and checks the 5-letter segment corresponding to the target, but this time the segment checked along with each step across the field is the entire word. The chaotic field is segmented for scanning at different scales, where accuracy increases as the scan range decreases. Larger letter scanners are more efficient at performing recognition as the field range of the scanner increases, at the cost of accuracy. The Memory Concept Index (MCI) alternates the size of the scanner in response to the unprocessed memory concepts they leave behind. MCI 500 starts with the largest available scanner and gradually decreases, thus revealing more computational resources to examine the potential presence of smaller memory concept targets.
[0153] Field Interpretation Logic (FIL) operations are used to manage the logic of scanners of different widths, where general range scanning starts with a large letter scan and examines a large range of fields with fewer resources at the cost of small-scale accuracy, where specific range scanning is used when important regions have been located and needs to be 'zoomed in' to ensure that expensive accurate scans are not performed in redundant and non-bent locations, where additional identification instructions for memory concepts are received in chaotic fields, and the field range contains dense saturation of memory concepts.
[0154] In the Automatic Perception Discovery Mechanism (APDM), the perception angle is defined by multiple metrics including range, type, intensity, and consistency. These define multiple aspects of the perception that constitute the overall perception. The creative module generates complex perception variations. The perception weights define how much relative influence perception has on perception when simulated by POE. The weights of the two input perceptions are taken into account, while the weights of the perception in the new iteration are also defined, which include a mixture of metrics influenced by the previous generation of perception.
[0155] The input to CVFG is a data batch, which is an arbitrary set of data that must be represented by the nodes of the generated CVF. The data is sequentially processed by each of the individual units defined by the data batch. The data units are converted into node format, which has the same composition as the information referenced by the final CVF. When the existence of the converted nodes is checked in the stage, they are temporarily stored in the node reserve. If they are not found, they are created and updated with statistics including occurrence and usage. All nodes in the reserve are assembled and pushed as the CVF as the module output.
[0156] The node comparison algorithm compares two nodes that have been read from the original CVF. In the case of a partial matching pattern (PMM), if an active node exists in a CVF and is not found in its comparison candidate (the node is latent), the comparison is not penalized. In the case of a whole matching pattern (WMM), if an active node exists in a CVF and is not found in its comparison candidate (the node is latent), the comparison is penalized.
[0157] System Metadata Separation (SMS) separates input system metadata into meaningful security causal relationships. In the case of subject scanning / assimilation, pre-made category containers and raw analysis from the classification module are used to extract the subjects / suspects of security situations from the system metadata, where the subjects are used as the primary reference points for deriving security response / variable relationships. In the case of risk scanning / assimilation, pre-made category containers are used to extract risk factors of security situations from the system metadata and raw analysis from the classification module, where risks are associated with target subjects exhibiting or exposed to such risks. In the case of response scanning / assimilation, pre-made category containers are used to extract the responses of security situations constituted by the input algorithm from the system metadata and raw analysis from the classification module, where responses are associated with security subjects supposedly deserving such responses.
[0158] In MCM, format separation separates and categorizes metadata according to rules and syntax for recognizable formats. Local format rules and syntax contain definitions that enable MCM modules to recognize pre-formatted metadata streams. Debug traces provide a code-level trace of the variables, functions, methods, and types used, as well as their respective input and output variable types / contents. Algorithm traces are software-level traces that provide security data combined with algorithm analysis, including the resulting security decisions (approval / blocking) along with a trace of how those decisions were achieved (justification), and the appropriate weight of each factor in making those security decisions.
[0159] In the metric processing (MP), the security response X represents a set of factors that contribute to the security response selected by SPMA, where the initial weights are determined by SPMA. The perceptual deduction (PD) uses a portion of the security response along with its corresponding system metadata to reproduce the original perception of the security response. The perceptual interpretation of the dimension sequence shows how the PD will accept the security response from SPMA and correlate the relevant input system metadata to recreate the full range of intelligent 'digital perception' as originally used by SPMA, where shape fill, stacking amount, and dimension are the digital perceptions that capture the 'perspective' of the intelligent algorithm.
[0160] In PD, the security response X is forwarded as input to the justification / reasoning computation, which determines the justification of the security response of SPMA by utilizing the intent supply of the Input / Output Reduction (IOR) module, where the IOR module uses the separate inputs and outputs of various function calls listed in the metadata, where metadata separation is performed by the MCM.
[0161] For PoE, the input system metadata is the initial input for raw perception generation (RP2) to generate perceptions in CVF, where, in the case of storage search (SS), CVF derived from the data augmentation log is used as a criterion in the database lookup of perception storage (PS), where perceptions are ordered according to their final weights in the ranking, where the data augmentation log is applied to generate perceptions for blocking / approval recommendations, where SCKD tags the log to limit the expected upper limit range of unknown knowledge, where data parsing provides a basic interpretation of the data augmentation log and input system metadata to output the raw approval or blocking decision as determined by the raw SPMA, where CTMP critiques decisions in PoE based on perceptions and critiques decisions in rule enforcement (RE) based on logically defined rules.
[0162] In the case of metric complexity, the outer circle represents the peak of known knowledge about individual metrics, where the outer edge of the circle represents more metric complexity and the center represents less metric complexity. The light gray center represents the current batch of metric combinations of the applied perceptual angles, while the dark gray outer circle represents the metric complexity that is generally stored and known by the system. The goal of ID is to increase the complexity of the relevant metrics so that the perceptual angles can be multiplied in terms of complexity and quantity. The dark gray surface area represents the total range of the current batch of applied perceptual angles and the number of ranges left beyond the known upper limit. When the enhancement and complexity are rich, the metric is returned as metric complexity, which is passed as input to the metric transformation. It inverts the individual to the entire perceptual angle, thus assembling the final output into the implicit perceptual angle.
[0163] For SCKD, Known Data Classification (KDC) separates known information from the input by category so that appropriate DB analogy queries can be performed, and separates the information into categories, where the separated categories provide input to CVFG, which outputs the classification information in CVF format, which is used by Stored Search (SS) to check the similarity in the known data range DB, where each category is labeled with the relevant range of its known data according to the SS results, and the labeled range of unknown information for each category is reassembled back into the same original input stream of Unknown Data Combiner (UDC).
[0164] The computer-implemented system is a Lexical Object Mining (LOM) system. This system further includes:
[0165] a) Initial Query Reasoning (IQR) transfers the question to it and uses Central Knowledge Retention (CKR) to decipher the missing details that are crucial to understanding and answering the question / responding to the question;
[0166] b) Investigation Clarification (SC) involves transferring questions and supplementary query data to a human subject, receiving input from the human subject and sending the output to the human subject to form a clear question / assertion;
[0167] c) Assertion construct (AC), which takes a proposal in the form of an assertion or question and provides an output of the concept associated with such a proposal;
[0168] d) Response presentation, which is an interface used to present the conclusions drawn from AC to both the human subject and the rational appeal (RA);
[0169] e) Hierarchical mapping (HM), which maps related concepts to discover confirmations or conflicts of consistency of issues / assertions and calculates the benefits and risks of taking a certain position on the topic;
[0170] f) Central Knowledge Reserve (CKR), which is the primary database for referencing knowledge about LOM;
[0171] g) Knowledge Verification (KV), which receives high-confidence and pre-critiqued knowledge that needs to be logically separated for query capabilities and assimilation in CKR;
[0172] h) Accepting a response: This gives the human subject an option to either accept the response of the LOM or to appeal with a critique. If the response is accepted, it is processed by the KV to store it in the CKR as confirmed (high confidence) knowledge. If the human subject does not accept the response, it is forwarded to the RA, which examines and critiques the reasons for the appeal given by the human.
[0173] i) Managed Artificial Intelligence Service Provider (MAISP) runs an Internet Cloud instance of LOM with a CKR master instance and connects the LOM to front-end services, back-end services, third-party application dependencies, information sources, and the MNSP cloud.
[0174] Front-end services include AI personal assistants, communication applications and protocols, home automation, and healthcare applications, while back-end services include online shopping, online delivery, and medical prescription ordering. Both front-end and back-end services interact with the LOM via a documented API infrastructure, which standardizes information delivery and protocols. The LOM retrieves knowledge from external information sources via an Automated Research Mechanism (ARM).
[0175] Language Construction (LC) interprets the original question / assertion input from the human subject and parallel modules to produce a logical separation of language syntax; Concept Discovery (CD) receives points of interest within the clarified question / assertion and derives related concepts using CKR; Concept Prioritization (CP) receives relevant concepts and ranks them in a logical layer representing specificity and generality; Response Separation Logic (RSL) utilizes LC to understand human responses and associates relevant and valid responses with the initial clarification request, thereby achieving the goal of SC; LC is then reused during the output phase to modify the original question / assertion to include supplementary information received by SC; The following construct (CC) uses metadata from the assertion construct (AC) and evidence from the human subject to provide the CTMP with the original facts for critical thinking; the decision comparison (DC) identifies the overlap between pre-criticism and post-criticism decisions; the concept compatibility detection (CCD) compares the conceptual derivations from the original question / assertion to determine the logical compatibility results; the benefit / risk calculator (BRC) receives the compatibility results from the CCD and weighs the benefits and risks to form a unified decision that includes a gradient of variables implicit in the concept construct; and the concept interaction (CI) assigns the attributes related to the AC concept to the parts of the information collected from the human subject via investigation clarification (SC).
[0176] Within IQR, LC receives the original question / assertion; the question is linguistically separate and IQR uses CKR to process one individual word / phrase at a time; by referring to CKR, IQR considers potential options that may take into account the ambiguity of the word / phrase.
[0177] The Investigation Clarification (SC) receives input from the Investigation Quality Rectification (IQR), which contains a series of requested clarifications. The human subject will respond to the series of requested clarifications with an objective answer to the original question / assertion to be obtained. The response provided for the clarification is forwarded to the Response Separation Logic (RSL), which associates the response with the clarification request. In parallel with the requested clarification being processed, a clarification language association is provided to the LC, which contains the internal relationship between the requested clarification and the language structure. This allows the RSL to modify the original question / assertion, so that the LC outputs the clarified question.
[0178] For the assertion construction of a received clarified question / assertion, LC decomposes the question into points of interest, which are passed to concept discovery, where CD derives related concepts using CKR, where concept prioritization (CP) orders concepts into logical layers, with the top layer designated as the most general concept and lower layers assigned increasingly specific concepts, where the top layer is transferred as modular input to the hierarchy map (HM); where in the parallel transfer of information, HM receives points of interest, which are processed by its dependent module concept interaction (CI), where CI assigns attributes to points of interest by accessing index information at CKR, where, as HM completes its internal process, its final output is returned to AC after the derived concepts have been compatibility tested, and the benefits / risks of the position are weighed and returned.
[0179] For HM, CI provides input to CCD, which identifies the compatibility / conflict level between two concepts, where compatibility / conflict data is forwarded to BRC, which translates compatibility and conflict into benefits and risks of taking a holistic, consistent position on the issue, where the position along with its risk / benefit factors is forwarded as a modular output to AC, where the system contains an information flow loop that indicates an intelligent gradient that is progressively supplemented as an objective response to the subjective nature of the issue / assertion; where CI receives points of interest and interprets each point of interest according to the top-level of the prioritized concepts.
[0180] For RA, the kernel logic processes the transformed linguistic text and returns a result. If the result is of high confidence, it is passed to Knowledge Verification (KV) for proper assimilation into CKR. If the result is of low confidence, it is passed to AC to continue the self-criticism loop. The kernel logic receives input from LC in the form of a pre-criticism decision without linguistic elements, which is then forwarded to CTMP as a subjective opinion. The decision is also forwarded to Context Construction (CC), which provides CTMP with metadata from AC and potential evidence from the human subject as input. The original facts of 'objective facts' are processed to output the best attempt to achieve 'objective opinion' given that CTMP has received its two mandatory inputs. Within RA, the opinion is treated as a post-critique decision, where both the pre-critique and post-critique decisions are forwarded to the Decision Comparison (DC), which determines the extent of overlap between the two decisions. The appeal argument is then either admitted to be true or the counter-argument is improved to explain why the appeal is invalid. In the case of indifference to the admission or improvement scenario, the high-confidence result is passed to KV and the low-confidence result is passed to AC 808 for further analysis.
[0181] For CKR, information units are stored in a Unit Knowledge Format (UKF), where the Rule Syntax Format (RSF) is a set of syntactic standards for tracking reference rules. Multiple rule units within an RSF can be used to describe a single object or action. Source attributes are collections of complex data that track the information source requiring protection. A UKF cluster consists of a series of linked UKF variants to define information that is independent of jurisdiction. UKF 2 contains the main target information, while UKF 1 contains timestamp information and therefore omits the timestamp field itself to avoid infinite regression. 3. It includes source attribute information and therefore omits the source fields themselves to avoid infinite regression; each UKF2 must be accompanied by at least one UKF1 and one UKF3, otherwise the cluster (sequence) is considered incomplete and the information therein cannot be processed by the LOM system-wide general logic; between the central UKF2 and its corresponding UKF1 and UKF3 units, there may be UKF2 units that act as linking bridges, where a series of UKF clusters will be processed by KCA to form derived assertions, where Knowledge Confirmation Analysis (KCA) is where UKF cluster information is compared to verify evidence about the position, where after the KCA processing is completed, CKR can output a conclusive assertion on the topic.
[0182] For ARM, where, as indicated by user activity, user interaction with LOM concepts is directly or indirectly led to responses to questions / assertions, where user activity is expected to ultimately produce concepts with low or no relevant information from CKR, as indicated by a list of requested but unavailable concepts, where, in the case of Concept Sorting & Prioritization (CSP), concept definitions are received from a single independent source and aggregated to prioritize information requests for resources, where data provided by information sources is received and parsed at the Information Aggregator (IA) according to what concept definitions they request and relevant metadata is stored, where information is sent to Cross-Reference Analysis (CRA), where the received information is compared with prior knowledge from CKR and the received information is constructed with reference to prior knowledge from CKR.
[0183] A Personal Intelligence Profile (PIP) is a place to store an individual's personal information through multiple potential endpoints and front-ends, where the information is separate from the CKR but can be used for LOM-wide common logic. Personal information related to artificial intelligence applications is encrypted and stored in a pool of Personal UKF clusters in UKF format. In the case of Information Anonymization Processing (IAP), information is supplemented to the CKR after any personally identifiable information is removed. In the case of Cross-Reference Analysis (CRA), the received information is compared with prior knowledge from the CKR and the received information is constructed with the prior knowledge from the CKR in mind.
[0184] Life Monitoring & Automation (LAA) connects internet-enabled devices and services on the platform, where Active Decision Making (ADM) considers the availability and functionality of front-end services, back-end services, IoT devices, spending rules, and available quantities based on Funding Rules & Management (FARM); FARM receives human input to the module defining criteria, limitations, and scope to inform ADM of its jurisdiction over its activities, where cryptocurrency funds are deposited into digital wallets, where the IoT Interaction Module (IIM) maintains a database of which IoT devices are available, and where data feeds indicate when IoT-enabled devices send information to LAA.
[0185] The system further includes behavioral surveillance (BM), which monitors personally identifiable data requests from users to check for unethical and / or illegal material. This involves aggregating user-related data from external services, in the presence of metadata aggregation (MDA), to establish the user's digital identity. This information is then passed to inductive / deductive reasoning and finally to pre-crime detection (PCD), where sophisticated analysis is performed using verification factors from the MNSP. Authenticated users destined for PIPs undergo information tracking (IT) and are checked against a behavioral blacklist. Deductive and inductive information is merged and analyzed at pre-crime detection (PCD) to obtain pre-crime conclusions. PCD utilizes the CTMP, which directly references the behavioral blacklist to verify the positions generated by inductive and deductive reasoning. Blacklist maintenance authorization (BMA) operates within the MNSP's cloud service framework.
[0186] LOM is configured to manage personalized combinations in an individual's life, where LOM receives initial questions that are concluded through LOM's internal deliberation process, where it is connected to the LAA module, which is connected to an Internet-enabled device from which LOM can receive and control data, where, in contextualized situations, LOM deduces missing links in the process of constructing arguments, where LOM uses its logic to decipher the dilemmas caused by the original assertion, which it must first know or assume certain variables about the situation.
[0187] The computer implements a system called Linear Atomic Quantum Information Transfer (LAQIT).
[0188] The system includes:
[0189] a) Recursively repeat the same consistent color sequence in the logical structure syntax; and
[0190] b) Use this sequence to recursively translate using the English alphabet;
[0191] When constructing the 'base' layer of the alphabet, color sequences are used on the color channels with shortened and unequal weights, and remaining space is reserved for grammar definitions within the color channels for future use and expansion.
[0192] The complex algorithm utilizes LAQIT to report its log events and status reports, automatically generating status / log reports, which are then converted into transportable text-based LAQIT syntax, where syntactically insecure information is transmitted digitally, and the transportable text-based syntax is converted into highly readable LAQIT visual syntax (linear pattern), where the key is optimized for human memory and based on a relatively short sequence of shapes.
[0193] In this context, the partially insecure text is input by the sender and submitted to the receiver, where the text is converted into a transmissible, encrypted text-based LAQIT syntax, where syntax security information is transmitted digitally, and where the data is converted into a visually encrypted LAQIT syntax.
[0194] The incremental recognition effect (IRE) is the channel for information transmission and identifies the complete form of an information unit before it is fully delivered. This effect of combining the predictive index is achieved by showing the transition between words. The proximal recognition effect (PRE) is the channel for information transmission and identifies the complete form of an information unit when it is broken, combined, or altered.
[0195] In LAQIT's linear mode, blocks show a 'basic rendering' version of the linear mode, and dots show that it is not encrypted. In the case of word separators, the color of the shape indicates the character following the word and acts as a separator between the word and the next word. Single view areas merge smaller view areas with larger letters, and therefore less information per pixel. In double view areas, more active letters exist per pixel. Shadow overlays dull incoming and outgoing letters, keeping the observer's main focus on the view area.
[0196] In atomic mode with a wide range of encryption levels, the primary color primary character reference specifies the general rule for which letter is being defined, where there is a kicker of the same color range as the primary color, and it precisely defines the specific character. In the case of a read direction, message delivery reads begin on the top square of an orbital ring, where once the orbital ring is completed, the read continues from the top square of the next sequential orbital ring. The entry / exit entry is the point of creation and destruction of a character (its primary color), where a new character belonging to the relevant orbital ring will emerge from the entry and slide clockwise to its position. The atomic nucleus defines the character following the word.
[0197] In the case of word navigation, each block represents the entire word (or multiple words in molecular mode) on the left side of the screen, where the corresponding block moves rightward and outward as the word is displayed, and moves backward as the word is completed, wherein the color / shape of the navigation block is the same as the color / shape of the primary color of the first letter of the word; in the case of sentence navigation, each block represents a cluster of words, where the cluster is the maximum number of words that can be adapted on the word navigation panel, wherein atomic state creation is a transition that causes incremental recognition effect (IRE), in which the primary colors appear from the entry / exit entrance, causing their impact to be hidden, and move clockwise to assume their position; wherein atomic state expansion is a transition that causes proximal recognition effect (PRE), in which once the primary colors reach their position, they move outward in the 'expansion' sequence of information state presentation, revealing the specific definition of the information state that the impact can thus present; wherein atomic state destruction is a transition that causes incremental recognition effect (IRE), in which the primary colors have contracted (inverted expansion sequence) to cover the impact again, where they are now sliding clockwise to reach the entry / exit entrance.
[0198] In the case of shape obfuscation, the standard square is replaced by five visually distinct shapes, where shape variations within the syntax allow the insertion of useless (fake) letters at policy points of the atomic contours. These useless letters obfuscate the true and intended meaning of the message, and the deciphering of whether the letters are real or useless is accomplished via a securely and temporarily transmitted decryption key.
[0199] In the case of redirected bonds, the bond connects two letters together and changes the reading flow. When starting with a typical clockwise reading pattern, a bond that initiates (begins) and lands on a reasonable / non-useless letter (ending with that reasonable / non-useless letter) will redirect the reading pattern to resume on the landed letter.
[0200] In the case of radial elements, some elements can be "rattled," which can reverse the evaluation of whether a letter is useless. The shape shows the shape that can be used for encryption, and the central element shows the central element that defines the track of the character immediately following the word.
[0201] In the case of a redirection key, the key begins with the "initiating" letter and ends with the "landing" letter, either of which may be useless or may not be useless. If none of them are useless, the key changes the reading direction and position. If one or both are useless, the entire key must be ignored, otherwise the message will be decrypted incorrectly. In the case of a key definition, if the key must be followed during the reading of the message state, it depends on whether it has been specifically defined in the encryption key.
[0202] In the case of a single cluster, both neighbors are non-radioactive, thus limiting the cluster's scope. Since the key designates the dual cluster as valid, an element is processed if it is not initially radioactive. In the case of a dual cluster, the key definition limits the dual cluster to active, so all other clusters of all sizes are considered latent while the message is being decrypted. The incorrect interpretation shows how the interpreter does not treat the dual cluster as a deserialization (false positive).
[0203] In molecular mode with encryption and streaming enabled, in the presence of resistance to covert dictionary attacks, incorrect decryption of a message can lead to a "distraction" of an alternate message. This occurs when each molecule has multiple active words, which are presented in parallel during the molecular process, increasing the information per surface area ratio while maintaining a consistent transition speed. The binary and streaming modes illustrate the streaming mode, while the read mode is binary in a typical atomic configuration. The binary mode indicates which character follows the central element defining the word, and the molecular mode is also binary, except when encryption conforming to the streaming mode is enabled, where the streaming mode references special characters within the track.
[0204] The system implemented by this computer is a Universal BCHAIN All Matters Connection (UBEC) system with a Basic Connection Coordination Attachment Integration Node. This system further includes:
[0205] a) Communication Gateway (CG), which is the main algorithm for BCHAIN nodes to interact with their hardware interfaces, thereby enabling communication with other BCHAIN nodes;
[0206] b) Node Statistics Survey (NSS), which explains the behavior patterns of remote nodes;
[0207] c) Node escape index, which is the probability that the neighboring node it tracks will escape from the vicinity of the sensing node;
[0208] d) Node saturation index, which tracks the number of nodes within the detection range of the sensing node;
[0209] e) Node consistency index, which tracks the quality of node services as interpreted by the sensing node. A high node consistency index indicates that surrounding neighboring nodes tend to have more available uptime and performance consistency. Nodes with dual purposes tend to have lower consistency indices in use, while nodes dedicated to the BCHAIN network exhibit higher values.
[0210] f) Node overlap index, which tracks the number of overlapping nodes as interpreted by the sensing nodes.
[0211] The system further includes:
[0212] a) Custom Chain Recognition Module (CRM), which connects to custom chains including application chains or microchains previously registered by nodes, wherein when an update is detected on a segment of the application chain in the metachain emulator of the metachain or microchain, the CRM notifies the rest of the BCHAIN protocol.
[0213] b) Content Claim Delivery (CCD), which receives a verified CCR and then sends the relevant CCF to fulfill the request;
[0214] c) Dynamic Policy Adaptation (DSA), which manages the policy creation module (SCM) to dynamically generate new policy deployments by using a creative module to mix complex policies that have been selected by the Optimized Policy Selection Algorithm (OSSA) with the new policies varying based on inputs provided by a field chaos interpretation;
[0215] d) Cryptographic Digital Economy Exchange (CDEE) with various economic personalities managed by a graphical user interface (GUI) under the UBEC platform interface (UPI); wherein in the case of personality A, node resources are consumed only to match what you consume; in the case of personality B, as many resources as possible are consumed as long as the profit margin is greater than a predetermined value; in the case of personality C, work units are paid via transaction currency; and in the case of personality D, node resources are spent as much as possible without any expectation of return, whether it is content consumed or monetary compensation.
[0216] e) Current Work Status Interpretation (CWSI), which refers to the infrastructure economic segment of the metachain to determine the node’s current surplus or deficit in terms of completed work credit;
[0217] f) Economic Compulsory Incentives (ECWI), which considers the economic personality selected in the context of a current work surplus / deficit situation to assess whether more work should be performed; and
[0218] g) Symbiotic Recursive Intelligent Progression (SRIA), which is a triune relationship among different LIZARD algorithms. It improves the source code of the algorithm by understanding the purpose of the code, including the algorithm itself, the simulated virtual iterations, and the generated I. 2 GE, and the BCHAIH network, which is a vast network of chaotically connected nodes that can run complex, data-intensive programs in a distributed manner. Attached Figure Description
[0219] The invention will be more fully understood by referring to the detailed description in conjunction with the accompanying drawings, in which:
[0220] Figure 1-26 This is a schematic block diagram illustrating a critical infrastructure protection and punishment (CIPR) mechanism known as CIPR / CTIS, which utilizes cloud-based and layered information security (CTIS). In detail:
[0221] Figure 1-2 This is a diagram illustrating how to use definitions from multiple perspectives of security interpretation as an analytical method;
[0222] Figure 3 This shows the use of security EI 2 A schematic diagram of a cloud-managed encrypted security service architecture for (extranet, intranet, internet) networks;
[0223] Figure 4-8 This is a diagram illustrating an overview of a managed Network & Security Service Provider (MNSP);
[0224] Figure 9 This is a schematic diagram illustrating real-time security processing for encryption security based on the LIZARD cloud;
[0225] Figure 10 This is a schematic diagram illustrating a Critical Infrastructure Protection & Penalty (CIPR) example of cloud-layered information security (CTIS) in an energy system;
[0226] Figure 11 This is a schematic diagram illustrating Phase 1 - Initial System Intrusion;
[0227] Figure 12 This is a schematic diagram showing stage 2 - the initial Trojan horse;
[0228] Figure 13 This is a diagram illustrating the download of Stage 3 - Advanced Executable Malware;
[0229] Figure 14 This is a schematic diagram illustrating the compromises of the Phase 4 - Intrusion Prevention / Defense System;
[0230] Figure 15 This is a diagram illustrating the expected behavior of hackers and the actual security response;
[0231] Figure 16 This is a schematic diagram illustrating the planned Internal Authentication Protocol Access (SIAPA);
[0232] Figure 17 This is a schematic diagram illustrating root-level access and standard-level access;
[0233] Figure 18 This is a schematic diagram illustrating the oversight and review process;
[0234] Figure 19 This demonstrates iterative intelligent growth / iterative evolution (I 2 A schematic diagram of GE;
[0235] Figure 20 This is a schematic diagram illustrating the infrastructure system;
[0236] Figure 21 It is a schematic diagram illustrating the crime system, infrastructure system, and public infrastructure;
[0237] Figure 22 and 23 This is a diagram illustrating how foreign code rewriting can syntactically copy foreign code from scratch to mitigate potential undetected malicious exploitation.
[0238] Figure 24 and 25 This is a diagram illustrating how recursive debugging works by looping through code segments;
[0239] Figure 26 This is a schematic diagram illustrating the internal workings required for mapping and matching;
[0240] Figure 27-42 This is a schematic diagram illustrating Machine Secret Intelligence (MACINT) and its punishment through covert operations in cyberspace; in detail:
[0241] Figure 27 This is a schematic diagram illustrating intelligent information management, viewing, and control;
[0242] Figure 28 This is a schematic diagram illustrating actions analyzed through behavior analysis;
[0243] Figure 29 and 30 It is a diagram illustrating the crime system and the punishments imposed on the crime system;
[0244] Figure 31 and 32 This is a schematic diagram showing the MACINT flow;
[0245] Figure 33 This is a diagram illustrating an overview of MACINT covert operations and how criminals exploit vulnerabilities in enterprise systems;
[0246] Figure 34 This is a schematic diagram illustrating the details of long-term / deep scanning using big data;
[0247] Figure 35 This is a diagram illustrating how to locate any computer on a trusted platform;
[0248] Figure 36 This is a diagram illustrating how to identify double or triple espionage activities from a trusted platform that could lead to further court investigations.
[0249] Figure 37 This is a diagram illustrating how a trusted platform can be used to participate in ISP APIs;
[0250] Figure 38 This is a diagram illustrating how a trusted platform can be used to participate in secure APIs provided by software and hardware vendors to exploit any established backdoors;
[0251] Figures 39-41 This is a diagram illustrating how general and customizable exploits can be applied to arbitrary and criminal computers;
[0252] Figure 42 This is a diagram illustrating how long-term priority flags can be pushed to a trusted platform to monitor criminal systems;
[0253] Figure 43-68 This is a schematic diagram illustrating the prior real-time defense (LIZARD) of a logic inference zero database; in detail:
[0254] Figure 43 and 44 This is a schematic diagram illustrating the interdependent structure of LIZARD;
[0255] Figure 45 This is a schematic diagram illustrating an overview of LIZARD;
[0256] Figure 46 This is a schematic diagram illustrating an overview of LIZARD's main algorithmic functions;
[0257] Figure 47 This is a schematic diagram illustrating the internal workings of the static core (SC);
[0258] Figure 48This is a schematic diagram illustrating how the internal kernel manages the essential kernel functions of the system;
[0259] Figure 49 This is a schematic diagram illustrating the internal workings of the dynamic shell (DS);
[0260] Figure 50 This is a schematic diagram illustrating the Iterative Module (IM) that intelligently corrects, creates, and damages modules on a dynamic shell;
[0261] Figure 51 This is a schematic diagram illustrating the iterative core of the main logic used for code iteration for security improvement;
[0262] Figures 52-57 This is a schematic diagram illustrating the logical process of the Differential Modifier Algorithm (DMA);
[0263] Figure 58 This is a schematic diagram illustrating an overview of virtual obfuscation;
[0264] Figures 59-61 This is a schematic diagram illustrating the monitoring and response aspects of virtual obfuscation;
[0265] Figure 62 and 63 This is a schematic diagram illustrating the data callback tracking of all information uploaded from and downloaded to the suspicious entity.
[0266] Figure 64 and 65 This is a schematic diagram illustrating the internal workings of a data callback trigger;
[0267] Figure 66 This is a diagram illustrating data selection, which filters out highly sensitive data and merges real data with fake data;
[0268] Figure 67 and 68 This is a schematic diagram illustrating the internal workings of behavioral analysis;
[0269] Figure 69-120 This is a schematic diagram illustrating Critical Thinking Memory & Perception (CTMP); in detail:
[0270] Figure 69 This is a schematic diagram showing the main logic of CTMP;
[0271] Figure 70 This is a schematic diagram illustrating the angle of perception;
[0272] Figures 71-73 This is a schematic diagram showing the dependent structure of CTMP;
[0273] Figure 74This is a schematic diagram illustrating the final logic used to process intelligent information in CTMP;
[0274] Figure 75 This is a schematic diagram illustrating the two main inputs—intuition / perception and thought / logic—assimilated into a single terminal output representing CTMP;
[0275] Figure 76 This is a schematic diagram illustrating the range of intelligent thinking that emerges in the original selection pattern matching algorithm (SPMA);
[0276] Figure 77 This is a schematic diagram illustrating the juxtaposition of critical thinking performed by CTMP through perception and rules in a conventional SPMA.
[0277] Figure 78 This is a diagram illustrating how corrective rules are generated compared to the current, conventional rules;
[0278] Figure 79 and 80 This is a schematic diagram illustrating the Perception Matching (PM) module;
[0279] Figures 81-85 This is a schematic diagram illustrating the derivation / generation of rule syntax;
[0280] Figures 86-87 This is a schematic diagram illustrating the Rule-Based Syntax Format Separation (RSFS) module;
[0281] Figure 88 This is a schematic diagram illustrating the operation of the Rule Implementation Parser (RFP);
[0282] Figures 89-90 This is a schematic diagram illustrating the implementation of a debugger;
[0283] Figure 91 This is a diagram illustrating the execution of rules;
[0284] Figure 92 and 93 This is a schematic diagram illustrating the organization of sequential memory;
[0285] Figure 94 This is a schematic diagram illustrating non-sequential memory organization;
[0286] Figures 95-97 This is a schematic diagram illustrating memory recognition (MR);
[0287] Figures 98-99 This is a schematic diagram illustrating the Field Interpretation Logic (FIL);
[0288] Figure 100-101 This is a schematic diagram illustrating the Automatic Detection and Discovery Mechanism (APDM).
[0289] Figure 102 This is a schematic diagram illustrating the generation of primitive perception (RP2);
[0290] Figure 103 This is a schematic diagram illustrating the logic flow of a Comparable Variable Format Generator (CVFG);
[0291] Figure 104 This is a schematic diagram illustrating the Node Comparison Algorithm (NCA);
[0292] Figure 105 and 106 This is a schematic diagram illustrating system metadata separation (SMS);
[0293] Figure 107 and 108 This is a schematic diagram illustrating the Metadata Classification Module (MCM);
[0294] Figure 109 This is a schematic diagram illustrating metric processing (MP);
[0295] Figure 110 and 111 This is a schematic diagram illustrating the internal design of perceptual deduction (PD);
[0296] Figures 112-115 This is a schematic diagram illustrating a Perceived Observer (POE) simulator;
[0297] Figure 116 and 117 This is a schematic diagram illustrating the implicit derivation (ID);
[0298] Figures 118-120 This is a schematic diagram illustrating Self-Critical Knowledge Density (SCKD);
[0299] Figure 121-165 This is a schematic diagram illustrating Lexical Objectivity Mining (LOM); in detail:
[0300] Figure 121 This is a schematic diagram illustrating the main logic used for Lexical Objectivity Mining (LOM);
[0301] Figures 122-124 This is a schematic diagram illustrating a managed artificial intelligence service provider (MAISP);
[0302] Figures 125-128 This is a schematic diagram illustrating the interdependent structure of LOM;
[0303] Figure 129 and 130 This is a schematic diagram illustrating the internal logic of Initial Query Reasoning (IQR);
[0304] Figure 131This is a schematic diagram illustrating the Investigation Clarification (SC).
[0305] Figure 132 This is a schematic diagram illustrating the assertion construct (AC);
[0306] Figure 133 and 134 This is a schematic diagram illustrating the internal details of how a hierarchy mapping (HM) maps.
[0307] Figure 135 and 136 This is a schematic diagram illustrating the internal details of the Rational Appeal (RA);
[0308] Figure 137 and 138 This is a schematic diagram showing the internal details of the Central Knowledge Retention (CKR);
[0309] Figure 139 This is a schematic diagram illustrating the Automated Research Mechanism (ARM).
[0310] Figure 140 This is a schematic diagram illustrating text scanning (SS);
[0311] Figure 141 This is a schematic diagram illustrating a hypothetical overlay system (AOS);
[0312] Figure 142 It demonstrates intelligent information & configuration management (I 2 A diagram of the CM (Management Control Center) and management console;
[0313] Figure 143 This is a schematic diagram illustrating a Personal Intelligence Profile (PIP);
[0314] Figure 144 This is a schematic diagram illustrating Life Monitoring & Automation (LAA);
[0315] Figure 145 This is a schematic diagram illustrating behavioral surveillance (BM);
[0316] Figure 146 This is a diagram illustrating the Ethical Privacy Law (EPL);
[0317] Figure 147 This is a schematic diagram illustrating an overview of the LIZARD algorithm;
[0318] Figure 148 This is a schematic diagram illustrating iterative intelligent growth;
[0319] Figure 149 and 150 This is a schematic diagram illustrating the iterative evolution;
[0320] Figure 151 and154 This is a schematic diagram illustrating the creative module;
[0321] Figure 155 and 156 This is a schematic diagram illustrating a LOM used as a personal assistant;
[0322] Figure 157 This is a schematic diagram illustrating LOM used as a research tool;
[0323] Figure 158 and 159 This is a diagram illustrating the advantages and disadvantages of LOM using the proposed theory;
[0324] Figure 160 and 161 This is a schematic diagram illustrating how LOM (Legend of Mir) is created for executing strategies in a diplomatic strategy war game;
[0325] Figure 162 and 163 This is a diagram illustrating LOM performing investigative tasks for newspapers and magazines;
[0326] Figure 164 and 165 This is a schematic diagram illustrating the LOM execution history verification;
[0327] Figures 166-179 This is a schematic diagram illustrating LAQIT, a secure and efficient digitally oriented language; in detail:
[0328] Figure 166 This is a schematic diagram illustrating the concept of LAQIT;
[0329] Figure 167 This is a diagram showing the available languages for the main types;
[0330] Figure 168 and 169 This is a schematic diagram illustrating the linear pattern of LAQIT;
[0331] Figure 170 and 171 This is a schematic diagram illustrating the characteristics of the atomic mode;
[0332] Figures 172-174 This is a schematic diagram illustrating an overview of the cryptographic features of atomic mode;
[0333] Figure 175 and 176 This is a schematic diagram illustrating the mechanism of redirected bonding;
[0334] Figure 177 and 178 This is a schematic diagram illustrating the mechanism of radioactive elements; and
[0335] Figure 179 This is a schematic diagram illustrating the molecular mode with encryption and streaming enabled;
[0336] Figures 180-184 This is a schematic diagram illustrating the UBEC platform and the front end connected to the distributed information distribution system BCHAIN; in detail:
[0337] Figure 180 This is a schematic diagram showing a BCHAIN node that contains and runs BCHAIN-enabled applications;
[0338] Figure 181 This is a schematic diagram illustrating the core logic of the BCHAIN protocol;
[0339] Figure 182 This is a schematic diagram illustrating the Dynamic Policy Adaptation (DSA) of the Management Policy Creation Module (SCM);
[0340] Figure 183 This is a schematic diagram illustrating the Cryptographic Digital Economy Exchange (CDEE) with various economic identities;
[0341] Figure 184 This is a schematic diagram illustrating Symbiotic Recursive Intelligent Progress (SRIA). Detailed Implementation
[0342] Critical Infrastructure Protection & Penalty (CIPR) through Cloud & Layered Information Security (CTIS) .
[0343] Figure 1-2 This illustrates how definitions from multiple perspectives of security interpretation are presented as an analytical method. In Figure 1, an established network of beacons and spies is used to form a graph of aggressors and bad actors. When such a graph / database is paired with sophisticated predictive algorithms, potential pre-criminal threats emerge. 2GE utilizes big data and malware signature identification to determine who is at fault. Security Behavior 20 stores precedents for security incidents, their impact, and appropriate responses. Such appropriate responses can be critiqued by CTMP22 (Critical Thinking, Memory, Perception) as a supplementary layer to security. Label 2 indicates which assets are at risk and what potential damage might occur. Example: A hydroelectric dam could open all its gates, ultimately flooding nearby villages and causing loss of life and property. Infrastructure DB 3 refers to a general database containing sensitive and non-sensitive information about public or private companies involved in national infrastructure work. Infrastructure 4 controls potential technical, digital, and / or mechanical measures used to control industrial infrastructure equipment (such as dam spillways, watts of electricity on the national grid, etc.). Label 5 analyzes business patterns to highlight potential blind spots. Such attacks are easily concealed to blend in with and hide beneath legitimate business operations. The question to ask is: Are there any political / financial / sports / other events that might be of interest to bad actors? Trusted platforms use external spies' networks to report hacking activity and preparation. Therefore, the timing of attacks can be estimated. In Figure 6, the questions to be asked are: Who are the more vulnerable enterprises that are likely to be targeted? What types of enterprises are likely to be vulnerable in a given geographic location? What are their most vulnerable assets / controls and what is the best way to protect them? The network of external spies from trusted platforms returns reports on hacking activity and preparedness. Therefore, the location of the attack can be estimated. In Figure 7, the questions to be asked are: What kinds of geopolitical, corporate, and financial pressures exist in the world that would fund and instigate such an attack? Who would benefit from it and how much? The network of external spies from trusted platforms returns reports on hacking activity and preparedness. Therefore, the motives for the attack can be estimated. In Figure 8, the questions to be asked are: What are the potential exploit points and hiding places for malware? How can these blind spots and unsecured access points be used to compromise critical assets and infrastructure control points? LIZARD 16 can derive the purpose and functionality from foreign code and thus block it if there is malicious intent or no legitimate reason. CTMP22 is capable of critically considering blocking / approval decisions and acts as a supplementary layer of security.
[0344] Figure 3 Showing EI for security 2A cloud-managed, encrypted security service architecture (extranet, intranet, internet) network. Managed Network & Security Service Providers (MNSPs) 9 provide managed encrypted security, connectivity & compliance solutions & services to critical infrastructure industrial segments (e.g., energy, chemical, nuclear, dams, etc.). Trusted Platforms 10 are a collection of proven companies and systems that mutually benefit from sharing security information and services. Hardware & Software Vendors 11 are industry-recognized manufacturers of hardware / software (e.g., Intel, Samsung, Microsoft, Symantec, Apple, etc.). In this specification, they are providing Trusted Platforms 10 with any potential measures for access to and / or exploitation of their products, enabling backdoor access with limited or full capabilities. This has led to the development of potential security and / or punitive processes for Trusted Platforms that may collaborate with their partners and joint security agencies, and the desire to enact laws. Virtual Private Networks (VPNs) 12 are an industry-standard technology that enables secure and completely isolated communication between MNSPs 9, Trusted Platforms, and their associated partners. Extranets allow for the near-total sharing of digital elements as if they were located in the same local area (e.g., a LAN). Therefore, the combination of these two technologies facilitates efficient and secure communication between partners to enhance the operation of the trusted platform. Security service providers 13 are a collection of public and / or private companies that provide digital security strategies and solutions. Their solutions / products are organized contractually so that the trusted platform can benefit from raw security information (e.g., new malware signatures) and security analysis. This increase in security strength, in turn, benefits the security service providers themselves, as they gain access to additional security tools and information. Third-party threat intelligence (3PTI) feeds 14 are the mutual sharing of security information (e.g., new malware signatures). The trusted platform acts as a centralized hub for sending, receiving, and assimilating this security information. In the case of multiple feeds of information, more advanced security-related behavioral patterns can be obtained (by leveraging the security service provider) via analytical modules that discern information collaboration (e.g., conspiracy detection 19). Law enforcement agencies 15 refer to relevant law enforcement authorities, whether state (e.g., NYPD), national (e.g., FBI), or international (e.g., INTERPOL). Communication is established to receive and send security information to facilitate or complete the punishment of criminal hackers. Such punishment typically requires locating and arresting appropriate suspects and bringing them to trial in the relevant courts.
[0345] Figure 4-8This is an overview of the managed Network & Security Service Provider (MNSP) 9 and its internal sub-module relationships. LIZARD 16 analyzes threats themselves without referencing previous historical data. Artificial Security Threats (AST) 17 provides hypothetical security scenarios used to test the effectiveness of security rules. Security threats are consistent in severity and type to provide meaningful comparisons of security scenarios. The Creativity Module 18 performs the process of intelligently creating new hybrid forms from previous input forms. It is used as a plug-in module to serve multiple algorithms. Conspiracy Detection 19 provides routine background checks on multiple 'conspiracy' security events and attempts to identify patterns and correlations between seemingly unrelated security events. Security Behavior 20: Events, their security responses, and characteristics are stored and indexed for future queries. 2 GE 21 is a big data, retrospective analysis branch of MNSP 9. Within standard signature tracking capabilities, it can simulate potential future changes in malware by leveraging ASTs with creative modules. CTMP 22 utilizes data from multiple sources (e.g., I...). 2 Cross-reference intelligence from GE, LIZARD, Trusted Platforms, etc., and understand expectations of perception and reality. CTMP estimates its ability to form objective decisions about a matter and avoids asserting decisions made with low internal confidence. The Management Console (MC)23 is an intelligent interface used by humans to monitor and control complex and semi-automatic systems. Intelligent Information & Configuration Management (I... 2 CM)24 contains the flow of control information and the various functions utilized by the authorization system. Energy Network Exchange 25 is a large private extranet connecting energy suppliers, producers, buyers, etc. This allows them to exchange security information relevant to their shared industry. Energy Network Exchange then transmits this information to the MNSP Cloud 9 via VPN / extranet 12. Such cloud communication allows for bidirectional security analysis, in which 1) critical security information data is provided from Energy Network Exchange to the MNSP Cloud, and 2) critical security corrective actions are provided from the MNSP Cloud to Energy Network Exchange. All EIs of energy companies 2Internet access (extranet, intranet, internet) is always routed to the MNSP cloud via VPN 12. MNSP utilizes authentication and encryption that comply with national (country-specific, e.g., FedRAMP, NIST, OMB, etc.) and international (ETSI, ISO / IEC, IETF, IEEE, etc.) standards and encryption requirements (e.g., FIPS, etc.) for all services. Intranet 26 (encrypted layer 2 / 3 VPN) maintains secure internal connections within the enterprise (energy company) private network 27. This allows LIZARD Lite client 43 to operate within the enterprise infrastructure while communicating with LIZARD Cloud 16 present in MNSP Cloud 9. Reference numeral 27 indicates a local node of the private network. Such private networks exist in multiple locations (labeled as locations A, B, and C). Different technical infrastructure setups may exist in each private network, such as server clusters (location C) or shared employee offices with mobile devices and private WiFi connections (location A). Each node in the private network has its own assigned management console (MC) 23. Portable media devices 28 are configured to securely connect to the private network and thus to the intranet 26 via an extended connection, and therefore indirectly to MNSP 9 via a secure VPN / extranet connection 12. During the use of this secure connection, all traffic is routed through the MNSP to minimize exposure to deployed real-time and retrospective security analysis algorithms. Such portable devices can maintain this secure connection whether it originates from within a secure private network or from WiFi access in a public coffee shop. The Demilitarized Zone (DMZ) 29 is a subnet containing an HTTP server, which has a higher security responsibility than a regular computer. This security responsibility stems not from security negligence but from the complex software and hardware composition of the public service server. Because numerous potential attack points remain despite maximum security efforts, the server is placed in the DMZ so that the remainder of the private network (location C) is not exposed to this security responsibility. Due to this separation, the HTTP server cannot communicate with other devices within the private network that are not within the DMZ. Because the DMZ is installed on the HTTP server, the LIZARD Lite client 43 can operate within the DMZ. An anomaly occurs in the DMZ policy, allowing MC 23 to access the HTTP server and thus the DMZ. The Lite client communicates with the MNSP via an encrypted channel formed from events 12 and 26. As shown in reference numeral 30, these servers are isolated in a private network but not immersed in DMZ 29. This allows for internal communication between devices within the private network. Each of them has an independent instance of the LIZARD Lite client 43 and is managed by MC 23.The Internet 31 is relevant because it serves as the medium for information exchange between MNSP 9 and enterprise devices 28 running the LIZARD Lite client. The Internet is the most vulnerable source of security threats for enterprise devices, rather than threats originating from local scenarios on the LAN. Due to the high security risk, all information exchange across devices is routed to the MNSP like a proxy. Potential malicious actors from the Internet will only see information encrypted due to the properly positioned VPN / extranet structure 12. Third-Party Threat Intelligence (3PTI) Feed 32 represents customized, tuned information input provided by a third party and based on pre-existing contractual obligations. Iterative Evolution 33: Parallel evolution paths are mature and selected. Iterative generations adapt to the same human-made security threats (ASTs), while the path with the best personality traits to defend against the most severe security threats ends. Evolution Path 34: A series of rule sets that are actually contained and isolated across generations. Evolutionary characteristics and criteria are defined by this path's personality X.
[0346] Figure 9This demonstrates real-time security processing for encryption security based on the LIZARD cloud. Syntax Module 35 provides a framework for reading and writing computer code. For writing, it receives a complexly formatted objective from the PM, then writes code in arbitrary code syntax, and a helper function can translate this arbitrary code into actual executable code (depending on the desired language). For reading, it provides the PM with a syntactic interpretation of the code to derive the purpose of such code. Objective Module 36 uses Syntax Module 35 to derive objectives from the code and output such objectives in its own 'complex objective format'. Such objectives should adequately describe the intended function of the code block as interpreted by the SM (even if the code is covertly embedded in data). Virtual Obfuscation 37: Enterprise networks and databases are cloned in a virtual environment, and sensitive data is replaced with fake (fake) data. Depending on the target's behavior, the environment can be dynamically changed in real-time to include more fake elements or more real elements throughout the system. Signal Simulation 38 provides a form of punishment typically used when an analysis has concluded virtual obfuscation (protection). Signal Simulation uses a syntax module to understand the communication syntax between malware and its hackers. It then hijacks such communications to give the malware the false impression that it has successfully sent sensitive data back to the hacker (even if it is fake data sent to the hacker as a virtual illusion). The real hacker also sends the malware's faulty code via LIZARD, making it appear as if it came from the malware. This diverts the hacker's time and resources to the wrong debugging tangent and ultimately abandons the working malware with the false impression that it is not working. Internal Consistency Check 39 checks that all functionality of the foreign code is meaningful. Ensures that there is no piece of code that is inconsistent with the purpose of the entire foreign code internally. Foreign Code Rewriting 40 uses syntax and purpose modules to reduce the foreign code to a complex purpose format. It then uses the derived purpose to build the code set. This ensures that only the expected and understood purpose of the foreign code is executed within the enterprise, and that any unintended functional execution cannot gain access to the system. Stealth Code Detection 41 detects code that is stealthily embedded in data & transport packets. Need Mapping Matching 42 is a hierarchy of need & purpose mappings that is referenced to determine whether the foreign code fits the overall goals of the system. The LIZARD Lite client 43 is a lightweight version of the LIZARD program that omits resource-intensive features such as virtual obfuscation 208 and signal simulation. It performs immediate and real-time threat assessments with minimal computational resource utilization by leveraging objective prior threat analysis that does not use a signature database as a reference. With logs 44 present, the energy company system 48 has multiple log creation points, such as standard software error / access logs, operating system logs, monitoring probes, etc. These logs are then fed to a local pattern matching algorithm 46 and CTMP 22 for in-depth and responsive security analysis.In the case of business 45, all internal and external businesses present in the energy company's local pattern matching algorithm 46 consist of industry-standard software that provides an initial security layer such as antivirus, adaptive firewall, etc.
[0347] Corrective action 47 will be handled by the local pattern matching algorithm 46, which was initially understood to address security issues / risks. This might include blocking ports, file transfers, administrative function requests, etc. The energy company separates its system 48 from a dedicated security algorithm that also sends its logs and business information. This is because these algorithms, LIZARD 16, I 2 Both GE21 and CTMP 22 are based on MNSP Cloud 9. This separation emerged to provide a centralized database model, which resulted in a larger pool of secure data / trends and therefore more comprehensive analytics.
[0348] exist Figure 11In this scenario, the criminal system scans for exploitable channels to enter the target system. If possible, it compromises channels used to deliver small payloads. Criminal system 49 is used by the criminal party to launch a malware attack against partner system 51 and thus ultimately infrastructure system 54. Malware source 50 is a container of inactive malicious code (malware). Once the code eventually reaches (or attempts to reach) the target infrastructure system 54, the malware is activated to perform its specified or on-demand malicious tasks. Partner system 51 interacts with the infrastructure system according to a contractual agreement between the infrastructure company (energy company) and the partner company. Such an agreement reflects some kind of commercial interest, such as supply chain management services or inventory tracking exchange. To achieve the agreed services, the two parties interact electronically according to previously agreed security standards. Malware source 50, representing the malicious party running criminal system 49, attempts to find exploits for penetration in the partner system. In this way, the malware achieves its ultimate goal of infecting (i.e., infrastructure system 54). Thus, the partner system has been used as a proxy infection process originating from malware source 50. Of the many communication channels between Partner System 51 and Infrastructure System 54, channel 52 has been compromised by malware originating from malware source 50. Channel / protocol 53 illustrates the uncompromised communication channels between Partner System 51 and Infrastructure System 54. These channels may include file system connections, database connections, email routing, VoIP connections, etc. Infrastructure System 54 is a critical element for the energy company's direct access to Infrastructure DB 57 and Infrastructure Control 56. An industry-standard intrusion prevention system 55 is implemented as a standard security procedure. Infrastructure Control 56 is a digital interface connected to energy-related equipment. For example, this might include the opening and closing of water gates in a hydroelectric dam, the angle at which solar panel arrays are pointed, etc. Infrastructure Database 57 contains sensitive information related to the infrastructure system and the entire core operation of the energy company. Such information may include contact information, employee shift tracking, energy equipment documents and blueprints, etc.
[0349] exist Figure 12 In this scenario, the compromised channel 52 provides a very narrow window of opportunity for exploitation, allowing a very simple Trojan to be uploaded to the target system to expand the exploitation opportunities. Trojan 58 originates from malware source 50, travels through the compromised channel 52, and reaches its target (i.e., infrastructure system 54). Its purpose is to open up the opportunity provided by the exploit so that a more sophisticated executable malware payload (which is more complex and contains actual malicious code for stealing data, etc.) can be installed on the target system.
[0350] Figure 13This demonstrates how, after further exploitation of the system by a Trojan horse, a large executable malware packet is securely uploaded to the system via a new open channel created by the Trojan horse. The advanced executable malware 59 is transferred to the base system 54, as well as the consequently sensitive database 57 and control 56. The advanced executable malware uses the digital path opened by the previous Trojan horse exploit to reach its destination.
[0351] Figure 14This illustrates how advanced executable malware 50 compromises an ID so that sensitive infrastructure information and control points can be separately downloaded to an undetected criminal system. Hacker 65 has managed to obtain trusted credentials from a company employee with legitimate authorized access credentials. The hacker intends to use these credentials to gain discreet and inconspicuous access to a LAN intended solely for employee use. The hacker intends to go beyond a typical “too little, too late” security response. Even if the endpoint security client manages to relay data to a cloud security service, retrospective analysis security solutions can only manage damage control, not eliminate and manage threats from the initial intrusion in real time. With an actual security response 61, the LIZARD Lite client (for endpoint use) cannot explicitly verify the need, functionality, and purpose of explicit credential login and system access. Because it doesn't yet know whether this is truly a reserved and legitimate user with credentials, the user is placed in a partially virtualized / fake environment. Such an environment can dynamically change the exposure to sensitive data in real time while analyzing user behavior. Behavioral analysis 62 is performed on the hacker 65 based on elements present on both the real and virtual cloned LAN infrastructure 64 through his interactions. With compromised credentials 63, the hacker gains credentials authorizing him to manage access to the energy company's laptop 28 and the LAN infrastructure 64 to which the laptop is thus configured to connect. These credentials could initially be compromised by intercepting unencrypted emails, stealing locally stored credentials from unencrypted corporate devices, etc. The LAN infrastructure 64 represents a set of corporate devices connected via a local network (wired and / or wireless). This could include printers, servers, tablets, telephones, etc. The entire LAN infrastructure is virtually reconstructed within the MNSP cloud 9 (virtual router IP assignments, virtual printers, virtual servers, etc.). Then, when the system performs behavioral analysis 62, the hacker is exposed to elements of both the real LAN infrastructure and the virtual clone. If the results of this analysis indicate a risk, the hacker's exposure to the fake infrastructure (as opposed to the real infrastructure) increases to reduce the risk of real data and / or devices being compromised. The hacker 65 is a malicious actor intending to access and steal sensitive information through the initial intrusion enabled by compromised credentials 63. With a password set 66, a set of three passwords is assigned to authenticated access. These passwords are never stored individually and always appear as a set. Employees must enter a combination of three passwords according to a protocol temporarily assigned from SIAPA. In the case of Planned Internal Authentication Protocol Access (SIAPA) 67, the authentication protocol for an individual employee's login portal is modified weekly / monthly. Such a protocol may involve choosing passwords A and C from a set of passwords A, B, and C (which have been pre-assigned for authentication).By scheduling authentication changes on a consistent basis (every Monday or the first day of the month), employees will become accustomed to switching authentication protocols, minimizing false alarms (when legitimate employees using the old protocol are trapped in fake data environment 394). To mitigate the risk of the new protocol being compromised by hackers, the employee can only view it once before their new protocol is compromised and cannot conduct audits. This first and only view requires special multi-factor authentication, such as biometrics / retinal / text messaging to a mobile phone, etc. The employee only needs to remember one or two letters that indicate which of the three passwords they should enter. For week 1, entry 68 will trigger fake data environment 394 if anything other than passwords A and B are entered. For week 2, entry 69 will trigger fake data environment 394 if anything other than passwords A and C are entered. For week 3, entry 70 will trigger fake data environment 394 if anything other than password B is entered. For week 4, entry will trigger fake data environment 394 if anything other than all passwords are entered. At SIAPA 72, the authentication protocol is kept confidential, and only anyone with access to the interim announcement knows the correct protocol. In the LAN infrastructure virtual clone 73, because hacker 65 entered all three passwords instead of omitting the correct ones, hacker 65 was silently transferred to a replicated environment in MNSP Cloud 9 that did not contain important data or functionality. While the hacker believed he had successfully infiltrated the real system, forensic evidence and behavioral analysis were collected. Regarding the case scenario 'using the wrong protocol' 74, the hacker did not use the correct protocol because he had no way of knowing, let alone anticipating, the existence of a special protocol that omitted specific passwords. At reference 75, the hacker had managed to steal legitimate credentials and intended to log into the company system to steal sensitive data. The internal oversight department 76 consists of the management committee and the technical command center. It is the top level for monitoring and approving / preventing potential malicious activities. Employees B and D 77 are not thieves (they are completely loyal to the company's interests) and have been selected as qualified employees for the three-way collaboration process for approving root-level function 80. Employee A 78 was not selected for the three-way collaboration process 80. This could be because he lacks sufficient experience working for the company, technical expertise, criminal record, or he is too close a friend to other employees, which could lead to conspiracies against the company, etc. Employee C (the thief) 79 attempted to access a root-level function / action intended for malicious purposes. Such a root-level function 80 cannot be executed without the consent and approval of three employees with individual root-level access rights. Although Employee C is the only employee with malicious intent, all three employees share equal responsibility for the consequences of executing this root-level function. This fosters a culture of caution and suspicion, and, due to the foresight of the procedures, significantly deters malicious behavior by employees in the first place.Employees E and F 81 were not selected for the three-way collaboration process 80 because they did not have root-level access to execute or first approve the requested root-level function. Supervisory review 82 uses the artificially provided delay to review and critique the requested action. Root-level action 83 is delayed by one hour to allow supervisory oversight to review the action and explicitly approve or block it. In cases where supervisory oversight is unavailable or inaccessible for decision-making, the strategy can limit the default action (approval or refusal). Supervisory review 84 determines the reasons why a consensus decision was not achieved. For the executed root-level action 85, the root-level action is executed while securely maintaining records of who approved what through the collaboration and supervisory monitoring system. This allows for a more detailed investigation if the root-level action results in a situation contrary to the company's best interests. At reference 86, the root-level action has been cancelled due to the failure of the three-way collaboration (no consensus decision). At reference 87, all three selected employees with root-level access unanimously approved the root-level action. If the root-level action is actually malicious, then all three employees need to be part of a conspiracy against the company. Due to this unlikely but still present possibility, the root-level action was delayed by 1 hour 83, and oversight had an opportunity to review it (see reference numerals 76 and 82). At reference numeral 88, one or more of the qualified employees selected for three collaborations have / have rejected the requested root-level action. Therefore, the root-level action itself is cancelled 89, and root-level action 89 is cancelled because no consensus was reached on the decision. The evolution pattern database 90 contains previously discovered and processed security risk patterns. These patterns enumerate potential means by which evolution could transform into the current malware state. The malware root signature 91 is provided to AST 17 so that iterations / variants of signature 91 can be formed. Polymorphic variants 92 of the malware are provided as from I. 2The output of GE is transferred to the malware detection system 95. Infrastructure system 93 is physically part of the infrastructure. This system typically manages infrastructure functions such as hydroelectric power plants and power grids. Infrastructure computer 94 is a specific computer that performs a function or part of a function that enables the infrastructure functions from system 93 to be performed. Malware detection software 95 is deployed across all three levels of the computer's composition. This includes user space 97, kernel space 99, and firmware / hardware space 101. This corresponds to malware detection deployments specifically deployed on Lizard Lite spyware at each of the three levels. Malware 96, iterated via evolution path 34, was found in the driver (which resides within kernel space 99). User space 97 is used for mainstream developer applications. The space most easily infiltrated by malware is also the easiest to detect and isolate malware. All user space activity is effectively monitored by Lizard Lite. Applications 98 within user space can include programs such as Microsoft Office, Skype, Quicken, etc. Kernel space 99 is largely maintained by operating system vendors such as Apple, Microsoft, and the Linux Foundation. While more difficult to penetrate than user space, most responsibility lies with the vendor unless the underlying infrastructure has been modified through the kernel. All kernel activities (including registry changes (Microsoft OS), memory management, network interface management, etc.) are effectively monitored by LIZARD Lite. Driver 100 enables the infrastructure computer 94 to interact with peripherals and hardware (mouse, keyboard, fingerprint scanner, etc.). Firmware / hardware space 101 is entirely maintained by the firmware / hardware vendor. Malware is extremely difficult to infect without direct physical access to the hardware (i.e., removing the old BIOS chip from the motherboard and soldering it onto a new one). Some firmware activities are monitored by LIZARD Lite, depending on the hardware configuration. BIOS 102 (a type of firmware) is the first layer of software built upon by the operating system. Public infrastructure 103 refers to unknown and potentially compromised digital infrastructure (ISP routers, fiber optic cables, etc.). Spyware 104 is implanted into the public infrastructure by participating in its known descriptions (ports, protocol types, etc.) stored in a trusted platform database and monitoring known callback channels. Spyware checks heartbeat signals and notifies the trusted platform of malware sources. With automatic discovery and installation of the streamlined client 105, the LIZARD cloud in MNSP 9 detects endpoint systems (such as laptops) that are not providing a signal response (handshake) to LIZARD. The endpoint will synchronize upon discovery and communicate via I... 2CM 24 is classified. Therefore, the LIZARD cloud (via SSH remote root shell) detects that the Lizard Lite client 43 is not installed / activated, and by exploiting the root shell, it forces the installation of client 43 and ensures its proper activation. Malware 106A initially enters because the Lite client 43 is not installed on the ingress device. The Lite client 43 is installed on almost every possible instance on the system, not to mention all incoming and outgoing traffic is routed through the MNSP containing the LIZARD cloud. With the initial exploit 107 present, the initial entity is detected and potentially blocked from exploiting the vulnerability before it can establish a covert callback channel 106B. Channel 106B is an obfuscated communication path for malware 106B to communicate discretely with its base. This can include masking signals to make it appear as a legitimate HTTP or HTTPS application. A wide range of vendors 108 provide valuable resources, such as covert access to software, hardware, firewalls, services, finances, and critical infrastructure, to allow spies 104 to be implanted in public infrastructure 103. The heartbeat signal is emitted by the malware at regular intervals with a specific size and frequency via callback channel 106B, and is directed to its origin / loyal source via a covert callback channel. This signal indicates the malware source 50's status / capability to determine future exploits and coordinate attacks. Such a malware source represents an organization with malicious intent and hacking capabilities; whether it is a black hat hacking group or a national / state government. LIZARD, running in MNSP Cloud 9, detected malware 106A and the heartbeat signal (within channel 106B) because all incoming and outgoing traffic is routed through a VPN tunnel via MNSP Cloud / Lizard.
[0352] Figure 22 and 23This demonstrates how foreign code rewriting syntactically replicates foreign code from scratch to mitigate potential undetected malicious exploits. Combination method 113 compares and matches the declared purpose 112A (which can be optional, depending on enterprise policy 147, if available) with the derived purpose 112B. Purpose module 36 is used to manipulate complex purpose formats and implement matching or mismatch scenarios. In the case of derived purpose 112B, the mapping match needs to maintain a hierarchy to preserve all the jurisdiction required by the enterprise. Therefore, the purpose of a code block can be defined and justified, depending on the gaps in the jurisdiction-oriented needs mapping 114. Input purpose 115 is the introduction of a recursive debugging process (which utilizes purpose & syntax modules). Instead of merging multiple introductions (e.g., purposes), each purpose input initializes a separate and parallel instance. Finally, security check 116 uses syntax 35 and purpose 36 modules to perform a multi-purpose 'sane' check to protect against any exploit points in the programming and transfers the final output 117 to a VPN / extranet 12.
[0353] Figure 24 and 25This illustrates how recursive debugging 119 iterates through code segments to test for errors and apply error fixes 129 (solutions) where possible. If an error persists, the entire code segment is replaced 123 with the original (external) code segment 121. The original code segment is then flagged to facilitate additional security layers (such as virtual obfuscation and behavioral analysis). In the case of external code 120, the original state of the code is interpreted by the target module 36 and syntax module 35 used for code rewriting. In cases where the original (external) code segment needs to be installed due to a permanent error in the rewritten version, the external code 120 is directly referenced by the debugger. The rewritten code segment 122 121 is tested by a virtual runtime environment 131 to check for coding errors 132. Such an environment 131 executes the code segment 121 (e.g., function and type) and checks for runtime errors (syntax errors, buffer overflows, faulty function calls, etc.). Any coding errors are handled for fixes. In the case of coding errors 132, the errors generated in the virtual runtime environment are defined in terms of scope and type. All relevant coding details are provided to facilitate the solution. In the case of purpose alignment 124, potential solutions to coding errors 132 are formulated by re-deriving code from the stated purpose of such functions and types. The scope of the coding error is rewritten in an alternative format to avoid such errors. Potential solutions are output, and if no solutions are retained, the code rewrite for that code segment 121 is lost and the original code segment (directly from the foreign code) is used in the final code set. Typically, coding error 132 will receive coding solutions 138 multiple times in a loop. If all coding solutions have been exhausted with the resolution of error 132, the solution is lost 137 and the original foreign code segment 133 is used. Code segment 121 can be marked 136 as foreign to facilitate decisions on additional security measures such as virtual obfuscation and behavioral analysis. For example, if the rewritten code block contains a high degree of foreign code segments, it is easier to place it in a dummy data environment 394. In the case of code segment caching 130, individual code segments (functions / types) are cached and reused across multiple rewrite operations to increase LIZARD cloud resource efficiency. This cache is highly utilized because all business operations are centralized via a VPN in the cloud. In the case of a rewritten code segment provider 128, previously rewritten code segments 121 are provided so that coding errors can have their respective solutions 129 applied to them.
[0354] Figure 26The internal workings of Need Mapping Match 114 are illustrated, which validates the purpose jurisdiction. The hierarchy mapping 150 references the enterprise jurisdiction branches in the LIZARD Cloud and the simplified version. This is done to justify the code / function's purpose and potentially prevent such code / function from being executed without valid justification. Whether the input purpose 139 is requested or derived (via the purpose module 35), Need Mapping Match 114 validates the justification for the code / function to execute within the enterprise system. The master copy of the hierarchy mapping 150 is stored on the LIZARD Cloud in MNSP 9, on the account of the corresponding registered enterprise. The need index 145 within Need Mapping Match 114 is calculated by referencing the master copy. The pre-optimized need index (and not the hierarchy itself) is then distributed among all accessible endpoint clients. Need Mapping Match receives need requests 140 for the most appropriate need for the entire system. The corresponding output is a complex purpose format 325 representing the appropriate need. It has need criteria + priority filtering 143 and searches for appropriate needs within the enterprise strategy 147. Such strategy 147 specifies the types and categories of needs that each jurisdiction may have. The scope of needs can range from email communications, software installation requirements, etc. Strategy 147 determines what needs to be prioritized based on the company's requirements. Based on the definitions associated with each branch, needs are associated with their respective departments. This allows for permission checks. Example: A need mapping matches a request to approve HR downloading all employee CVs because it's currently time for an annual performance review based on employee capabilities. With initial resolution 148, each jurisdictional branch is downloaded for reference. In the case of calculation branches requiring 149, needs are associated with their respective departments based on the definitions associated with each branch. This allows for permission checks. Example: A need mapping matches a request to approve HR downloading all employee CVs because it's currently time for an annual performance review based on the jurisdiction defined in hierarchy mapping 150.
[0355] Machine secret intelligence (MACINT) through covert operations in cyberspace & punishment
[0356] Figure 27This demonstrates intelligent information management, viewing, and control. Aggregation 152 uses general-level criteria to filter out unimportant and redundant information while merging and tagging information flows from multiple platforms. Configuration & Deployment Service 153 is used to deploy interfaces for new enterprise network assets (computers, laptops, mobile phones) with proper security configurations and connectivity settings. After devices are added and configured, they can be adjusted via a management console with management feedback control as an intermediary. This service also manages the deployment of new client / user accounts. This deployment can include associating hardware with user accounts, customizing interfaces, and listing client / user variables (e.g., business type, product type, etc.). Through separation of jurisdiction 154, the tagged information pools are isolated based on the relevant jurisdiction of the management console user. In the case of separation through threat 155, information is organized according to individual threats. Each type of data is either associated with a threat (this is redundant) or removed. At this stage of the process marked as Intelligent Contextualization 156, the remaining data now looks like a cluster of islands, each representing a cybersecurity threat. To further refine security analysis, correlations are established between platforms. Historical data (from I) 2GE 21 (instead of LIZARD 16) is accessed to understand threat patterns, and CTMP is used for critical thinking analysis. In the case of threat dilemma management 157, cybersecurity threats are perceived from a bird's-eye view (large picture). Such threats are presented graphically on the management console. Because the calculated measurements related to threat mechanisms are ultimately merged from multiple platforms, more informed threat management decisions can be automated. Automated control 158 represents access to algorithms used to control management related to MNSP 9, TP, and 3PS. Management feedback control 159 provides advanced control over all MNSP cloud, trusted platform 10, plus third-party service (3PS) services that can be used to facilitate decision-making, forensics, threat investigation, etc. Such management controls are ultimately reflected on the management console (MC) with appropriate customizable visuals and presentation efficiency. This allows for effective control and manipulation of the entire system (MNSP, TP, 3PI) directly from a single interface (which can zoom in on details as needed). Manual control 160 refers to human access to management-related controls used to control MNSP9, TP, and 3PS. Direct management 161 utilizes manual control to provide a human interface. In the case of categories and jurisdiction 162, users of the management console use their login credentials to define their jurisdiction and scope of access to information categories. All potential data vectors 163 are running data, static data, and data in use. Customizable visual materials 164 are available for use by various enterprise departments (accounting, finance, HR, IT, legal, security / inspector general, privacy / disclosure, unions, etc.) and stakeholders (staff, managers, and administrators in each relevant department), as well as third-party partners and law enforcement authorities. Integrated single view Figure 165It is a single view of all potential capabilities such as monitoring, logging, reporting, event correlation, alert handling, policy / rule set creation, corrective actions, algorithm optimization, service provisioning (new clients / modifications), use of trusted platforms, and third-party services (including receiving reports and alerts / logs from third-party service providers & vendors, etc.). A unified view of all aspects of security 165 is a collection of visual materials representing the perimeter, enterprise, data center, cloud, removable media, mobile devices, etc. A cybersecurity team 167 is a team of qualified professionals who monitor the activity and status of multiple systems across boards. Because intelligent processing of information and AI decision-making are being made, costs can be reduced by employing fewer people with less experience. The team's primary purpose is to serve as a backup layer in verifying that the system is maturing and progressing according to expected criteria while performing large-scale analysis points. Behavioral analytics 168 observes the state and actions of malware 169 while it is in a 100% fake data environment 394. When the malware interacts with fake data 170, behavioral analysis records patterns observed during activation (e.g., activation only when the office is closed on Sundays), file access requests, requested root management functions, etc. Malware 169 has been implanted by hacker 177. Although the hacker believes he has successfully implanted the malware into the target system, the malware has been quietly moved and isolated to a 100% fake data environment 394. At fake data 170, malware 169 digitally holds a copy of the fake data. While doing so, under the impression that the data is real, and through extension, hacker 177 forgets whether the data is real or fake. When the malware attempts to send fake data to the hacker, the output signal is rerouted so that it is received by the fake hacker 174, contrary to the expectations of the real hacker's malware. With the hacker interface 171, syntax module 35 and target module 36 (which, according to jurisdiction, belong to the LIZARD system) receive the code structure of malware 169. These modules reverse engineer the internal structure of the malware to output the hacker interface. This interface details the communication methods used between malware and hackers, the malware's expectations of the hacker (e.g., receiving commands), and the hacker's expectations of the malware (e.g., status reports). This information allows for the simulation of a fake hacker 174 and fake malware 172 within the virtualized environment 173. Once behavioral analysis 168 has thoroughly studied the behavior of malware 169, MNSP 9's signal simulation capabilities can simulate a program behaving similarly to hacker 177. This includes the communication protocols existing between the real malware 169, fake data 170, and the fake hacker 174. With simulated signal responses 175, the virtualized fake hacker 174 sends response signals to the real malware 169, giving it the impression that its mission has succeeded or failed.Such signals can include commands regarding malware behavior and / or requests for information status updates. This is done for further behavioral analysis to observe the malware's next behavioral pattern. At the end of the study, the fake data environment 394 containing the malware is either frozen or destroyed. In the case of a simulated response code 176, the hacker is given a fake response code unrelated to the behavior / status of the real malware. Depending on the desired penalty strategy, a fake error code or a fake success code can be sent. A fake error code gives the hacker the impression that the malware is ineffective (as it would be in reality) and wastes the hacker's time on useless debugging tangents. A success error code reduces the hacker's likelihood of shifting their attention to creating new forms of malware, instead focusing on the current malware and any possible incremental improvements. Because such malware has been compromised and understood by LIZARD, the hacker wastes their energy on the compromised malware, believing it is succeeding. Hacker 177 still believes that the malware he implanted has successfully penetrated the target system. In reality, the malware has been isolated within the virtualized environment. The same virtualized environment has been subjected to behavioral analysis 168 of the malware to simulate its methods and syntax of communication with hackers (whether bidirectional or omnidirectional). Criminal assets 178 represent investments made via criminal finance 184 to facilitate hacking and malicious operations of criminal system 49. Such assets 178 typically manifest as computing power and internet connectivity, and strong investments in both assets enable more sophisticated and elaborate hacking performance. Using criminal code 179, an exploit scan is performed by an espionage agent on a trusted platform to gather as much forensic evidence as possible. Using a criminal computer 180, a CPU exploit is performed, which uses AVX instructions to cause CPU overflow. This results in increased heat, increased power consumption, more CPU degradation, and reduced processing power available for the criminal process. Exploit scans 181 of criminal assets 178 are performed to identify their capabilities and characteristics. The resulting scan results are managed by exploit 185 and forwarded to trusted platform 10. Exploit 185 is a program sent by trusted platform via a penalized exploit database 187 that has penetrated the target criminal system 49. Figure 27-44The simulation is performed in MACINT. Power and cooling expenses have increased significantly, depleting the criminal finances 184. Shutting down the computer would severely hinder criminal operations. Purchasing a new computer would place even greater pressure on the criminal finances, and such a new computer would be easily exploited like the old one. The Exploitation Punishment Database 187 contains measures to address criminal activities that exploit vulnerabilities provided by hardware vendors 186 in the form of established backdoors and known weaknesses. The Unified Forensic Evidence Database 188 contains a compilation of forensic evidence from multiple sources across multiple enterprises. In this way, potentially the strongest legal cases are established within the criminal enterprise and submitted to the relevant courts. In cases with target selection 189, a target is selected for punishment only after sufficient forensic evidence has been established against it. This may include minimum time requirements (e.g., 6 months) for forensic cases subject to oversight review. Evidence must be highly self-verifiable, and isolated incidents cannot be used to impose punishment for fear of attacking innocent targets and provoking legal repercussions. With target verification 190 in place, multiple methods were used to verify the suspected criminal system to surpass any potential covert methods (public cafes, TOR networks, etc.), including:
[0357] - Physical location. GPS can be used. Cloud services can help verify (e.g., long-standing precedents for cloud-based (Dropbox) login locations).
[0358] - Physical device. MAC address, serial number (from manufacturer / supplier).
[0359] - Personnel verification. Biometric data is used on the security system, including a photo taken from a front-facing camera, to verify consistent login credentials across multiple platforms.
[0360] Figure 33This section outlines the covert operations of MACINT, illustrating how criminals exploit vulnerabilities in enterprise systems. Enterprise system 228 defines the entire scope and jurisdiction of the enterprise's infrastructure and assets. Enterprise computer 227 is a critical part of enterprise system 228 because it contains sensitive information 214 and relies on enterprise network 219, as it is typically a planned operation. The dormant double spy 215 is malware that remains lurking and 'dormant' on the target computer 227. Due to its lack of activity, it is difficult for programmers and cybersecurity analysts to detect because no damage has yet occurred. When hackers from criminal system 49 find an opportunity to use their dormant spy 215, the spy 215 stealthily captures a copy of the sensitive file 214. At this stage, the hackers expose themselves to being tracked, but this is an opportunity for them to decide for themselves when to use the spy 215 for installation (i.e., if file 214 is worthwhile) without administrator notification. In stage 216, the captured file 214 is pushed to the thief's destination server via encryption outside the enterprise network. This encryption (i.e., HTTPS) is permitted by policy, so the transmission is not immediately blocked. The captured file 214 is passed to the network infrastructure of the corporate network 219, attempting to leave the corporate system 228 and enter arbitrary system 262, ultimately reaching the criminal system 49. This network infrastructure is represented by LAN routers 217 and firewalls 218, which are the last barriers the malware must overcome before it can transmit the captured file 214 outside the corporate system. In this example, the industry-standard firewall 218, deemed unable to prevent the theft of the captured file 214, generates logs forwarded to log aggregation 220. Such aggregation then separates the data categorized for both long-term / deep scanning 221 and real-time / surface scanning 222. In the case scenario of empty result 223, real-time 222 is not adequately prepared to perform near-immediate malicious activity identification, so it is stopped before it can be executed. In the case scenario of malware connection discovery 224, long-term scanning 221 will eventually identify the malicious behavior because it has the advantage of more time for analysis. This ample time allows long-term 221 to perform a more thorough search using more sophisticated algorithms and data points. In the case of a compromised botnet segment 225, a computer belonging to an arbitrary third-party system is used to transfer sensitive files 226 to evade investigation and frame any third party. Thieves receive the sensitive files 226 at the criminal computer 229, while simultaneously maintaining a hidden presence through their botnet and continuing to use the files for illegal extortion and profit. Potential tracing of the criminal computer's identity (e.g., IP address) may only remain on the arbitrary computer 238, which is inaccessible to administrators and investigators of the enterprise system 228.
[0361] Figure 34This section shows more details regarding the long-term / deep scanning 230 using Big Data 231. Deep scanning 230 assists and participates in Big Data 231, while utilizing two sub-algorithms: 'conspiracy detection' and 'external entity management'. Intermediate results are pushed to anomaly detection systems, which are responsible for the final results. Standard logs from security checkpoints (such as firewalls and central servers) are aggregated and selected at log aggregation 220 with low-restriction filters. With event indexing + tracing 235, event details such as IP address, MAC address, vendor ID, sequence number, time, date, DNS, etc., are stored. These details exist in both a local database and a shared cloud database (the databases are different in the data). The local storage of these entries (along with restrictions based on the enterprise's policies) is pushed to the cloud database to benefit other enterprises. In turn, useful event information is received to benefit local analytics. Enterprises registered with trusted third parties 235 may have experienced botnet breaches and can provide preventative details to mitigate such risks. In the case of security behavior 236, security countermeasures are stored in a local database and a shared cloud database (these databases are not identical in terms of data). These countermeasures define the points of action to ensure the security of the system. For example, if an IP address accesses a system that the event index shows has been associated with a botnet 6 out of 10 times, the IP address is banned for 30 days, and a priority flag is set on the log system to mark any attempts by the IP address to access the system during that time. The local storage of these guidelines (along with restrictions based on enterprise policies) is pushed to the cloud database to benefit other enterprises. In turn, useful event information is received to benefit local analysis. In the case of anomaly detection 237, any potential risk events, such as unauthorized spies transferring sensitive files to arbitrary systems outside the enterprise network, are identified using the event index and security behavior based on intermediate data provided by the deep scan module. Arbitrary computers 238 are shown as the destination servers involved in the results obtained in the branch, highlighted, and defined by any known characteristics such as MAC address / last known IP address 239, country, and uptime pattern. Such analysis primarily involves the extraneous entity management 232 module. The system can then determine the likelihood of this computer participating in a botnet.240 This analysis primarily involves conspiracy detection.19
[0362] Figure 35This demonstrates how to locate any computer on Trusted Platform 10 to check if it or its server relatives / neighbors (other servers connected to it) have previously established double or triple espionage for Trusted Platform 10. Phase 242 shows how known information about any computer 238, such as MAC address / IP address 239, is sent for querying at Event Index + Tracking 235 and Cloud Version 232. Such Cloud Version Tracking event details, operated from Trusted Platform 10, are used to identify future threats and threat patterns, i.e., MAC addresses, IP addresses, access timestamps, etc. The results of this query 242 are sent to System Collection Details 243. Such details include: details of the original arbitrary computer 238, computers / systems that periodically receive packets and / or send packets to computer 238, and systems physically close to computer 238. Such details are then forwarded to Phases 246 and 247, which check whether double espionage 247 or triple espionage 246 has occurred in any of the aforementioned computers / systems. This spy lookup check is performed at Trusted Double Spy Index + Tracking Cloud 244 and Trusted Triple Spy + Index Tracking Cloud 245. The double spy index 244 contains a list of systems with dormant spies installed and controlled by a viable platform and its affiliates. The triple spy index 245 contains a list of systems compromised by criminal groups (e.g., botnets) but also discretely compromised by the trusted platform 10 to monitor malicious activity and developments. Both clouds then output their results, which are collected in a list of active and associated spies 248.
[0363] Figure 36 This demonstrates how it becomes clear that a double or triple spy from Trusted Platform 10 is involved in a further court investigation. Transfer from the spy list 248; an appropriate dormant spy 252 is activated 249. A double spy computer 251, trusted by arbitrary computer 238, pushes an exploit 253 through its trusted channel 254. After successful deployment on arbitrary computer 238, exploit 253 tracks the activity of sensitive file 241 and learns that it was sent to the one now known to be the criminal computer 229. It follows the same path used to first transfer file 241 on channel 255 216 and attempts to establish itself on criminal computer 229. Exploit 253 then attempts to locate sensitive file 241, isolate it, send its exact state back to Trusted Platform 10, and then attempt to erase it from criminal computer 229. Trusted Platform 10 then forwards the isolated file back to the original enterprise system 228 (which possesses the original file) for court purposes. It is not always guaranteed that exploit 253 can retrieve sensitive files 241, but it can at least forward identifiable information 239 about the criminal computer 229 and system 49.
[0364] Figure 37This demonstrates how Trusted Platform 10 is used to participate in the ISP (Internet Service Provider) 257 API regarding arbitrary computer 238. Network surveillance 261 is used to attempt to compromise arbitrary system 262 for further judicial investigation. Enterprise system 228 knows only limited information 259 about arbitrary computer 238 and is seeking information about criminal computer 229 and system 49. The ISP 257 API request is made via Trusted Platform 10. At Network Surveillance 261, system network logs for arbitrary system 262 are found, and potential files are transferred to criminal computer 229 (which is later identified as criminal computer 229). The log history is not detailed enough to record the accurate and complete composition of sensitive file 241, but metadata 260 can be used to determine with significant confidence which computer the file should be sent to. Network Surveillance 261 discovers network details 258 of criminal computer 229 and therefore reroutes this information to Trusted Platform 10, which in turn notifies Enterprise system 228.
[0365] Figure 38This demonstrates how a trusted platform 10 can be used to participate in any established backdoors provided by the software 268 and hardware 272 vendors to exploit vulnerabilities that could aid a judicial investigation. In phase 263, known identity details of the criminal computer 229 are transferred to the trusted platform 10 to participate in the backdoor API. Such details may include the MAC address / IP address 239 and the suspicious software and hardware of the criminal computer. The feasible platform 10 then delivers exploit 253 (the exploit code is transferred but not executed) to the latent vendors of the affiliated software 268 and hardware 272. Also delivered to the vendors is the suspicious software 269 and hardware 273 of the criminal computer 229 suspected by the enterprise system 228 at phase 263. The vendors retain a list of established software 270 and hardware 274 backdoors, including information on how to invoke them, what authorization measures are required, and what their capabilities and limitations are. All these backdoors are isolated and confidential from within the vendors, so the feasible platform does not receive sensitive information to process these backdoors, but instead provides exploit 253 that will benefit from them. Upon successful implementation of the software 267 or hardware 271 backdoor, exploit 253 is discretely installed on the criminal computer 229. Sensitive file 241 is isolated and copied for subsequent analysis of its metadata usage history. Any remaining copies on the criminal computer 229 are securely wiped. Any other possible supplementary forensic evidence is collected. All of this forensic data is returned to the point of contact of exploit 253 at the trusted platform 10. Subsequently, forensic evidence 265 is forwarded to enterprise system 228, which includes the sensitive file 241 found on the criminal computer 229, and the identity details of those associated with the criminal system who possess evidence of the initial theft of file 241. Thus, if enterprise system 228 deleted file 241 from its system during the initial theft, enterprise system 228 can recover file 241, and the identity details 264 will enable them to seek punishment in terms of legal damage and disabling the criminal system 49 botnet to mitigate the risk of future attacks.
[0366] Figures 39-41This demonstrates how to apply generic 282 and custom 283 exploits to arbitrary 238 and criminal 229 computers in the process of attempting a direct compromise without the direct assistance of a trusted platform 10. The generic exploit 282 is a collection of software, firmware, and hardware exploits organized and assembled by the enterprise system 280 through independent cybersecurity research. In the case of an exploit, the custom 283 exploit is tailored based on known information about the target. The exploit 253 is delivered in a manner most likely to succeed first and least likely to succeed last. A set of available information 284 about the criminal computer 229 is transferred to the custom 283. Such information includes any known computer information, such as MAC address / IP address 239 and suspicious software and hardware 285 being used by the criminal computer 229. Agent management 286 is a combination of algorithms and databases that intelligently select agents for the exploit attempt. The agent network 279 is a series of agent nodes 278 that allow any individual system to conceal its original identity. This node passes through this digital communication and becomes the apparent initiator. The agent management 286 intelligently selects nodes based on their overall performance, availability, and current workload. Three potential exploit points are explored for the criminal computer 229 and / or arbitrary computer 238. If exploiting the criminal computer 229 fails, an attempt to exploit the arbitrary computer 238 is made regardless, as it still facilitates the entire court investigation. One approach is direct exploitation, the second is via a botnet tunnel 276 on the arbitrary computer, and the third is the original means of exploiting the criminal system to install botnet 277 (along with other unused exploit points). Botnet tunnel 276 is the established communication means used between the criminal computer 229 and the active portion of botnet 240. Any court data generated by exploit 253 is sent to enterprise system 228 at stage 275.
[0367] Figure 41This demonstrates how a specific API with a viable platform 10 is used to push software or firmware update 289 to a criminal computer 229 to establish a new backdoor. A placebo update 288 is pushed to a nearby similar machine to maintain stealth. Enterprise system 228 sends target identity details 297 to trusted platform 10. Such details include MAC address / IP address 239. Trusted platform 10 communicates with software / firmware maintainer 287 to push placebo update 288 and backdoor update 289 to the relevant computers. The backdoor update introduces a new backdoor into the criminal computer 229 system using a pre-built software update system installed on the computer. This update may target the operating system, BIOS (firmware), or specific software such as a word processor. Placebo update 288 omits the backdoor to avoid security compromises but shows the same details and identifiers (i.e., update number / code) as backdoor update 289 to evoke the environment that maintains the backdoor's stealth. Maintainer 287 delivers backdoor 295 to the target, as well as computers that also have above-average exposure to the target. Such an additional computer 296 could be a computer belonging to the infrastructure of criminal system 49, or a computer on the same local network as criminal computer 229. Exploiting such an additional computer 296 increases the chance of gaining access to criminal computer 229 when a direct attack is impossible (i.e., they have no updates to the operating system, etc.). If it is possible to establish itself on a nearby computer 296, the exploit 253 will be able to consider different points of entry into the target. For the involved computer 291 with an average exposure to the target, a placebo update 228 is submitted. Exposure can be understood as sharing a public network (i.e., a virtual private network, etc.) or a public service platform (i.e., file sharing, etc.). The involved system 290 may also be strategically associated with criminal system 49, such as by sharing the same corporate legal structure, etc. Neighboring computers 293 belonging to the adjacent system 292 are given placebo updates because they are close to the physical location of the target criminal computer 229 (same region, etc.). Both the involved system 290 and the adjacent system 292 are given a placebo update 288 to facilitate a time-sensitive court investigation, while there are no scheduled updates (or any suitable and feasible investigations) planned to be delivered by maintainers 287 in the near future. In a case scenario where there are scheduled updates intended to improve the software / firmware, the involved system 290 and the adjacent system 292 do not need to be given a placebo update to verify the legitimacy of the perceived backdoor 289 update. Instead, backdoor 289 can be implanted into some legitimate updates targeting the criminal computer 229 and other computers 296. Upon successful exploitation 253 via backdoor update 295, sensitive files 241 are isolated and copied for subsequent analysis of their metadata usage history. Any remaining copies on the criminal computer 229 are then securely removed. Any supplementary court evidence is collected.The court data is then sent to the exploit contact point at Trusted Platform 10. After the data is verified at Platform 10, it is then forwarded to Enterprise System 228 at Result 281.
[0368] Figure 42 This demonstrates how long-term priority flags are pushed to Trusted Platform 10 to monitor Criminal System 229 for any and all changes / updates. New developments are monitored long-term according to priority to facilitate investigation. First, Enterprise System 228 submits Target 297 (including identifiable details 239) to Assurance Module 300, which is a subset of the viable platform 10. This Assurance Module scans all Subsidiary System 303 inputs 299 for any association with the defined Target 297. If any match is found, the information is passed to Enterprise System 228, which has defined the Assurance and attempted to penetrate Target 297. Information input 299 is information typically used by Subsidiary Trusted Platform 10 to receive system reports for the required analysis. Inputs may also be submitted solely for the purpose of gaining the approval and reputation of Trusted Platform 10. Subsidiary Systems 303 submit their inputs to Trusted Platform 10 to seek an advantage over Enterprise System 228 in monitoring Target 297. This increases the chance that one of these Subsidiary Systems 303 will encounter the Target or a relative Target, whether this is an active, neutral, or passive interaction. Such input 299 is passed to the desired analysis module 301, which represents most of the functions of the trusted platform 10 used to synchronize mutually beneficial security information. Subsidiary system 303 issues security requests and exchanges security information. If information related to target 297 or any of target's relatives is found, the information is also forwarded in parallel to the assurance module 300. The information output 302 of module 301 is forwarded to subsidiary systems 303 to complete their requested tasks or functions, and any useful information learned by the assurance module 300 about target 297 is passed to result 298 as part of the court investigation of enterprise system 228.
[0369] LIZARD: A priori real-time defense against zero-database logical inference.
[0370] Figure 43 and 44 This illustrates the dependency structure of LIZARD (a priori real-time defense for logic inference zero database). The static kernel 193 is the main fixed-program module, hard-coded by a human programmer. Iterative modules 194 intelligently modify, create, and destroy modules on the dynamic shell 198. Human-based security threats (ASTs) are used as a reference for security performance, and iterative kernels are used to handle automated code writing methods. (See also...) Figure 51As illustrated, the iterative kernel 195 is the main logic for iterating the dynamic shell 198 to improve security. The differential modifier algorithm 196 corrects the basic iteration based on defects found by the AST. After applying the differential logic, a new iteration is proposed, on which the iterative kernel is recursively called and undergoes the same process tested by the AST. The logical deduction algorithm (LAD) 197 receives the known security response of the dynamic shell iteration in its current state from the human security threat (AST). The LDA also deduces what kind of code set constitutes a known correct response to the security scenario (provided by the AST). The dynamic shell DS 198 mainly contains dynamic program modules that have been automatically programmed by the iterative modules. Code isolation 199 isolates foreign code into a restricted virtual environment (e.g., a Piper dish). Stealth code detection 200 detects code secretly embedded in data and transmission packets. When the system can only perform low-confidence decisions, the AST overflow repeater 201 relays data to the AST for further iterative improvement. Internal consistency check 202 checks whether all internal functions of the foreign code block are meaningful. It ensures that there is no code that is inconsistent with the overall purpose of the foreign code. Foreign code rewriting 203 rewrites a portion of the entire code itself after deriving the purpose of the foreign code and only allows the rewritten code to be executed. Mirror testing checks ensure that the rewritten input / output dynamics are the same as the original. This makes any hidden exploits in the original code redundant and never executed. Need mapping matching 204 is a hierarchy of needs and purposes that is referenced to determine whether the foreign code fits the overall goals of the system (e.g., an educational toy). Real data synchronizer 205 is one of two layers (the other being the data manager) that intelligently selects which data to give to the merging environment and with what priority (the other being the data manager). This ensures that highly sensitive information is not accessed by suspected malware and is only available to code that is known and determined to be trustworthy. Data manager 206 is the intermediary interface between entities and data from outside the virtual environment. Framework coordinator 207 manages all inputs, outputs, thread injections, and diagnostics of semi-artificial or artificial algorithms. Virtual obfuscation 208 obfuscates and restricts code (and therefore potential malware) by gradually and partially immersing it in a virtualized fake environment. Stealth transfer module 209 quietly and discretely transfers malware into fake data environment 394. With purpose comparison module 210, four different types of purposes are compared to ensure that the presence and behavior of entities are deserved and understood by LIZARD in the production of the overall goal of the system. Potentially large discrepancies in purposes indicate malicious behavior. Fake data generator 211 creates fake data designed to be indistinguishable from real data (i.e., a batch of SSNs). Virtual environment manager 212 manages the construction of virtual environments, including variables such as the ratio of fake data, available system functions, network communication options, and storage options.Data callback tracking 213 tracks all information uploaded to and downloaded from suspicious entity 415. This is done to mitigate the security risk of sensitive information potentially being transferred to malware. This security check also mitigates the logical problem of legitimate enterprise processes receiving fake (false) data. In the event that fake data has been sent to (now known as) a legitimate enterprise entity, a "callback" is executed, which retrieves all fake data and sends the real data (the originally requested data).
[0371] Figure 45This section provides an overview of LIZARD (Logical Inference Zero Database Prior Real-Time Defense), a centrally monitored algorithm capable of blocking all potential cybersecurity threats in real time without directly assisting in the dynamic growth of the database. The determination of whether to allow data / access into the system is based on the need to know, the required functionality, and the purpose-driven foundation. If code or data blocks do not provide functionality / purpose toward achieving the system's hard-coded goals, they will be denied in a covert manner, including virtual orphanage and obfuscation. LIZARD is equipped with a syntax interpreter that can read and write computer code. Combined with its purpose inference capabilities, it can derive goal-oriented behavior from code blocks, even those covertly embedded in seemingly healthy data. All enterprise devices (even those outside the enterprise premises, such as company phones in public coffee shops) are routed through LIZARD. All software and firmware running enterprise assets are hard-coded to perform any kind of download / upload via LIZARD, acting as a permanent agent. Non-compliance with permanent agent policies is mitigated through a tipping policy for loyal assets. Digital transfers occurring within an enterprise system are necessarily bound to a piece of hardware hard-coded to be relayed via LIZARD, thus preventing malicious code from discovering secure locations or any computers that ignore the collaborative compromises of the persistent proxy policy. LIZARD has a symbiotic relationship with the Iterative Module (IM). IM clones the hard-coded, target-oriented tasks and LIZARD's syntactic understanding capabilities. It then uses these syntactic capabilities to modify LIZARD to fit the hard-coded targets. The Artificial Security Threat (AST) module participates in a parallel virtual environment to stress test different variants of LIZARD. The variant with the highest score is selected as the next formal iteration. LIZARD offers an innovative paradigm that deviates from the status quo of cybersecurity solutions. With its advanced logical deduction capabilities, it can perform immediate and accurate security decisions without the "too little, too late" paradigm of modern cybersecurity defenses. LIZARD interacts with three types of data: data in motion, data in use, and data at rest. LIZARD interacts with six types of data media (known as vectors): files, emails, networks, mobile devices, the cloud, and removable media (USB). Enterprise system 228 illustrates the types of servers running within its infrastructure, such as HTTP and DNS. Mobile device 305 is shown operating within a public coffee shop 306, while simultaneously connecting to the digital infrastructure of enterprise system 228 via LIZARD Lite client 43. Such client 43 acts as a gateway to the internet 304, from which it connects to the encrypted LIZARD cloud 308.
[0372] Figure 46This section provides an overview of LIZARD's main algorithmic capabilities. LIZARD's outer dynamic shell (DS) 313 is a functional section that is more easily modified through iteration. Modules requiring high complexity to achieve their purpose typically reside in this shell 313; as they exceed the level of complexity that a team of programmers can directly handle. Iterating module 314 uses static kernel (SC) 315 to syntactically modify the DS313 codebase based on the 'fixed target' and the purpose defined in the data from data return relay (DRR) 317. This modified version of LIZARD is then stress-tested (in parallel) by artificial security threat (AST) 17 under multiple and varying security scenarios. The most successful iteration is adopted as the live functional version. LIZARD's SC 315 is the least likely to be modified through automatic iteration and is instead directly modified by human programmers. In particular, the innermost square, known as kernel 334, is completely unaffected by automatic iteration. This innermost layer 334 acts like the root of a tree guiding LIZARD's direction and overall capabilities. The General Dynamic Module (GDM) 316 is the most extensible module area for automated self-programming and therefore falls under the jurisdiction of the Dynamic Shell 313. This is because such a program running in GDM 316 is in a constant 'beta' state (not necessarily stable and in progress). When LIZARD performs low-confidence decisions, it relays relevant data to AST 17 via the Data Return Relay (DRR) 317 to improve future iterations of LIZARD. LIZARD itself does not directly rely on the data used to perform the decisions, but data on evolving threats may indirectly benefit from the prior decisions that future iterations of LIZARD may perform. Label 342 shows that the more human work involved in code design, the more static (very slow to change) the code becomes. The more times the Iteration Module (IM) 314 programs the code, the more dynamic and fluid the code becomes. The Syntax Module 35 and the Purpose Module 36 demonstrate their functions from within SC 315.
[0373] Figure 47This illustrates the internal workings of the Static Core (SC) 315. Logical Derivation 320 derives logically necessary functions from initially simpler functions. The end result is the construction of an entire function dependency tree from the stated complex purpose. Code Translation 321 translates arbitrary (general) code, directly understood by the syntax module functions, into any chosen known computer language. It also performs the inverse operation of translating a known computer language into arbitrary code. Rules and Syntax 322 contains static definitions that help explain and generate syntactic structures. For example, rules and syntax for the C++ programming language can be stored in 322. Logical Simplification 323 reduces logic written in code to a simpler form to produce a mapping of interconnected functions. Writing Code 324 is the final output executable program, while the code target 332 is the input. Complex Purpose Format 325 is a storage format used to store interconnected sub-purposes representing the overall purpose. Purpose Association 326 is a hard-coded reference to what kind of purpose the behavior's function and type refer to. Iterative Extension 327 adds detail and complexity by referencing purpose associations to evolve simple purposes into complex ones. Iterative interpretation 328 traverses all interconnected functions and generates an interpretation target by referencing target association 326. The outer kernel 329 is primarily composed of syntax and target modules that work together to derive the logical target into unknown foreign code and generate executable code based on the stated function code target. The foreign code 330 is code unknown to LIZARD and its function and intended purpose are unknown. When the foreign code 330 is input to the inner kernel, the derived target 331 is the output. The target 331 is the intent of the given code 330 estimated by the target module 36. The derived target is returned in complex target format 325.
[0374] Figure 48This illustrates how the internal kernel 334 hosts the essential core functions of the system, which are directly and specifically programmed by relevant cybersecurity experts 319 via the maintenance platform 318. The kernel code 335 forms the fundamental basis required to run LIZARD. Within kernel 336, the basic framework and libraries 336 possess all the functionality required to operate LIZARD, such as compression and comparison capabilities. Within kernel 336, thread management and load balancing 337 enable LIZARD to scale efficiently across server clusters, while communication and encryption protocols limit the types of encryption used (e.g., AES, RSA, etc.). Within kernel 336, memory management 339 allows for efficient management of data interpreted and processed by LIZARD within the server's random access memory (RAM). System objectives 336 include security policies 340 and enterprise objectives 341. Policies 340 are manually designed by one (or more) cybersecurity analysts as guidelines for LIZARD to operate according to customized variables. Therefore, LIZARD has standards for what actions are considered insecure and prohibited, and what is permissible. For example, within Enterprise Security Policy 340, sending emails to recipients outside the organization might be prohibited, or an account might be locked after a third failed password attempt. Enterprise Objective 341 defines the broader characteristics of what kind of general infrastructure the enterprise desires to achieve. Objective 341 primarily serves to guide the self-programming of Dynamic Shell 313 regarding what functionalities LIZARD must possess and what functions it must perform within the context of the enterprise's infrastructure.
[0375] Figure 49 The internal workings of the dynamic shell (DS) 313 are shown. This section of LIZARD is primarily manipulated by artificial intelligence programming modules (iterative modules). Modules in the outer shell 345 are new and experimental modules that have a minor impact on the overall system's decisions. The inner shell 344 is the core of LIZARD; most of its intelligent capabilities are operated there. The new and experimental algorithms 343 'Beta' are allocated software space where new modules are programmed and tested by humans, artificial intelligence, or both to fulfill the required functionalities.
[0376] Figure 50The iterative module (IM) is shown to intelligently modify, create, and corrupt modules on the dynamic shell 313. It uses Artificial Security Threat (AST) 17 as a reference for security performance and uses the iterative core 347 to handle automated code writing methods. At the Data Return Relay (DRR) 317, data about malicious attacks and bad actors is relayed to AST 17 when LIZARD has to make decisions with low confidence. AST 17 creates a virtual test environment with simulated security threats to enable the iterative process. The artificial evolution of AST 17 is fully involved to keep it ahead of the organic evolution of criminal malicious network activities. In the case of a static core clone 346, the static core 315 (including a semi-dynamic outer core 329) is used as a guideline for iteration. Because of this iteration, the outer core 329 is partially modified; self-programming has reached a full cycle in the artificial intelligence loop. The iterative core 347 receives objective guidance from artificial security scenarios and systems to modify the dynamic core 313. The iterative core 347 generates numerous iterations. The best iteration performed in the human safety test is uploaded so that it can become the live functional iteration of the dynamic shell in stage 348.
[0377] Figure 51 The iterative core 347 is shown as the main logic for code iteration used for security improvement. In the case of recursive iteration 350, a new instance of iterative core 347 is called, replacing the basic iteration 356 with the new iteration 355. This transition is managed by thread management 349, which enables load balancing 337 and thread management derived from the subset of core code 335. Differential Modifier Algorithm (DMA) 353 receives syntax / purpose programming capabilities 351 and system objective guidance 352 from internal core 334. These two inputs are associated with the basic framework and library 336 and security policy 340 / enterprise objective 341. Such a code set is then used to modify the basic iteration 356 based on the defects found in AST 17. After applying the differential logic, a new iteration 355 is proposed, after which iterative core 347 is recursively called and undergoes the same process tested by AST 17. In the case of a queued security scenario 360, multiple scenarios jointly perform a comprehensive test of the dynamic shell 313 at all known security points. In the context of active security scenario 361, the current active security scenario is being tested with a dynamic shell 313 in an isolated virtual execution environment 357. This environment 357 is a virtual instance completely isolated from the field system. It executes artificially generated malicious attacks and intrusions. While running the virtual execution environment 357, security outcome flaws 362 can be visually presented to indicate security threats that 'pass' the basic iteration 356. Subsequently, any discovered flaws 363 are forwarded to DMA 353 to facilitate the generation of a new iteration 355 that attempts to omit such flaws.
[0378] Figures 52-57 The logical process of the Differential Modifier Algorithm (DMA) 353 is illustrated. The current state 365 represents a code set with a symbolically related shape, size, and position (dynamic shell 313). Different configurations of these shapes indicate different configurations of security intelligence and response. AST 17 provides any potential responses to the current state 365 that happen to be incorrect, as well as what the correct response is (isolate the file, as it is a virus). The attack vector 370 (all dotted arrows) serves as a symbolic demonstration of a cybersecurity threat. The direction, size, and color are all related to assumed security attributes (such as the attack vector, the size of the malware, and the type of malware). The attack vector symbolically pops off the code set to represent a security response to the code set. Reference A 367 shows a specific security configuration that allows the attack vector to pass through, which may or may not be a correct security response. Reference B 368 shows an attack vector popped off the code set, illustrating the alternative response types of Reference A while considering potential correctness or incorrectness. Reference C 369 shows a security response that sends the attack vector back to its origin position, which may or may not be a correct security response. Figure 53 Above, the correct state 354 represents the final result of the process of the differential modifier algorithm 353 used to generate the required security response from the code block of the dynamic shell 313. The correct state 354 is generated by recursively iterating 350 on a new iteration 355 of the dynamic shell 313. Although there are subtle differences between the current state 365 and the correct state 354, these differences can lead to completely different attack vector 370 responses. While reference A 367 allows the attack vector to pass directly, reference A 371 (the correct security response) pops the attack vector at a right angle. In both the current state 365 and the correct state 354, the attack vector response to reference B remains unchanged. In the case of reference C 373, the attack vector is also sent back to its origin (albeit at a different location than reference C 369). All these attack vector representations illustrate and correspond to the logical management of security threats. Figure 54 The AST security attack vector 375 is shown, which is the attack sequence provided by AST 17. The correct security response 376 shows the expected security response for attack vector 370. The code set (shape) used to generate this correct security response has not yet been shown at this stage; it is not yet known. Figure 55 The current dynamic shell response attack 377 is shown, which exhibits a poor security response to a correct dynamic shell response attack 378. Such a correct response 378 is generated by a logical deductive algorithm (LDA) 197. Figure 56This illustrates how LDA 197 infers the correct security settings to match the correct attack response 378. The static core 315 provides LDA 379 with a system framework / guidance 352 and syntax / purpose automatic programming capabilities 351, enabling it to construct a secure program that produces the correct attack response 378. At stage 381, a basic iteration 356 of the dynamic shell 313 is provided to LDA 379. This iteration is represented as a security response program 382 that produces an insufficiently standard and inefficient security response. Such a program 382 is provided as input to LDA 379. LDA uses the syntax / purpose functionality 351 from the static core 315 to construct from the incorrect security response program 382, making it conform to the correct response to the attack 378. Thus, a correct security response program 383 is produced, which is considered a new iteration 355 of the dynamic shell 313. The process, continuing via recursive iterations 350 through iterative core 347, will continue to upgrade the security capabilities of the dynamic shell 313 until it is filled with all the security information available from AST 17. Figure 57 A simplified overview of the process is shown, as AST 17 provides known security flaws 364 and correct security responses 384. While AST 17 is able to provide known security flaws 364 and responses 384, it cannot construct an effective and running program that will produce such a correct response 384. Therefore, LDA 379 uses a priori (basic) iteration 356 of the dynamic shell 313 to produce a superior and better-equipped iteration 355 of the dynamic shell, referred to as the correct security response program 385. The use of the term 'program' indicates the overall functionality of the many different functions and submodules operating within the dynamic shell 313.
[0379] Figure 58This section provides an overview of virtual obfuscation. The following capabilities of virtual obfuscation & fake data generation are deployed on encrypted cloud platforms intended for use by small / medium-sized businesses with few to no cybersecurity personnel. Security systems can also be installed directly in the data centers of large companies. In this case scenario, malware 385 originates from the internet (304) and bypasses industry-standard firewalls / intrusion detection systems / antiviruses, etc. At its current security iteration state, LIZARD16 has a low-confidence assessment of the intent / purpose of the incoming code block 385. These conditions are assumed to be worst-case scenarios. To mitigate the risk of innocent processes being deprived of access to critical data, and also to avoid the risk of allowing malicious code to possess sensitive data, suspicious code 385 is covertly assigned to an environment where half of the data is intelligently merged with fake (false) data. In addition to typical administrative access requirements, the real system 388 is not restricted by the real data 389. Due to virtual orphanage 390, any object operating within the real system 388 can easily and covertly transfer to part or all of the fake data environment (391 or 394). The Real Data Synchronizer 386 intelligently selects one of two layers (the other being the Data Manager 401) as the data to be given to the merging environment and with what priority. This prevents suspected malware from accessing highly sensitive information, ensuring that only code known and established as trustworthy gains access. The Fake Data Generator 387 uses the Real Data Synchronizer 386 as a template for creating fake and unusable data. Based on the Real Data 389, it simulates attributes such as data type, data format, data density, and data details to produce a database with a realistic appearance that looks well integrated into the system (without irrelevant or odd data). The perceived confidence risk in the incoming foreign code influences the obfuscation level chosen by LIZARD 16. A high confidence level indicating malicious code will trigger an allocation to an environment containing a large amount of fake data 394. A low confidence level indicating malicious code may trigger an allocation to the Real System 388 (considered a benefit of suspicion) or a 100% fake data environment 394 (considered a default non-trust). This customized option for security behavior is defined in security policy 340, which is a subset of system target 336 and a subset of internal kernel 334. A highly monitored network interface 392 is used in the environment containing spoofed data 393. This secure interface is used to protect the environment from being leaked into restricted environments, such as a real system 388 combined with virtual orphanage 390. Such orphanage 390 uses virtualization technology to completely isolate and protect random access memory (RAM) and CPU threads from merging, so that each environment is separate from itself.
[0380] Figures 59-61This illustrates the monitoring and response aspects of virtual obfuscation. Such a system monitors and manages malware based on malware behavior. Initially, LIZARD considers a code block at its current, complex iteration level to be either malware or not. If it is not malware, LIZARD pushes it into a virtual clone of a real system consisting of 50% fake data (391). This is done so that if it is ultimately proven not to be malware, the system and enterprise functions will not be severely impacted (e.g., providing a false SSN). In the illustrated example, the code block is indeed malware (385), but LIZARD is still uncertain at this stage due to the novel and unknown nature of this threat and exploitation method. Figure 60 This is specifically illustrated how malware 385 was immersed in a virtual orphanage 380 fake data environment 391, because LIZARD was still unsure whether it was malware or not. Data Manager 401 intelligently merged real data with fake data to ensure that highly sensitive data was not exposed. Manager 401 uploaded 402 the information generated by malware 385 to fake data storage device 400 and downloaded 398 previously stored fake data to merge with real data 397. In this way, malware does not have write access to real data storage device 397 and cannot overwrite sensitive information. Malware 385 was virtually orphaned 380, so that it was only exposed to data manager 401. This virtual orphanage prevented malware from accessing all real data 397 by bypassing data manager 401. Behavioral analysis 403 tracked the download 398 and upload 402 behavior of suspicious code blocks to determine potential corrective actions. Analysis 403 monitored how malware 385 behaved in its impartial form to help confirm or disprove LIZARD's initial suspicion. By monitoring the behavior of malware in its impartial form, LIZARD confirmed its initial suspicion that the foreign code was indeed malware. Malware 385 is quietly and cautiously transferred to a 100% fake data virtual environment 394 via a covert transfer module 395. As a precaution, to prevent the malware from multiplying and infecting the 50% fake data environment 391, the entire virtual environment (including the malware) is securely destroyed. At this stage, malware 385 is now completely immersed in the fake environment 394 without exposing any sensitive information. Potential communications of the malware to its home (e.g., heartbeat signals) via covert communication channels are monitored to potentially improve future iterations of the dynamic shell 313. Such malware behavior information is passed to AST 17 via a Data Return Relay (DRR) 317 to benefit future iterations. In this way, DS 313 can make more confident decisions regarding similar malware 385 without having to take steps to place it again in the 50% fake data environment 391 (which still carries some risk of legitimate data theft).
[0381] Figure 62 and 63 Data callback trace 399 is shown, tracking all information uploaded and downloaded from and to suspicious entity 415. This is done to mitigate the security risk of sensitive information potentially being passed to malware. This security check also mitigates the logical problem of legitimate enterprise processes receiving spoofed data 400. In the event that spoofed data has been sent to (now known to be) a legitimate enterprise entity, a 'callback' is executed that will call back all spoofed data and, in return, send the real data (which was originally requested). A callback trigger is implemented so that the legitimate enterprise entity does not take action on certain information until there is confirmation that the data is not spoofed. If real data has been passed to malware inside the virtual merged environment, the entire environment container will be securely destroyed along with the malware 385 inside. System-wide alerts are placed for any anomalous activity regarding any data known to be in the malware before it is destroyed. This concept is embodied in system-wide monitoring 405. If the entity that received partial real data is eventually proven to be malware (during behavioral pattern analysis), then the virtual environment (including the malware) is securely destroyed, and the enterprise-wide network is monitored for anomalous activity related to the flagged real data. This prevents any potential information leakage. In cases where there is tracking of fake data downloads 407 and uploads 408; tracking fake data sent to and from suspicious entity 415 in the virtual container. In cases where there is notification of upload security 410, data initially written to the fake data collection 400 as security protection is later deemed secure and is therefore prepared to be written to real data 412 to satisfy the upload request 402 of suspicious entity 415. Thereafter, upload relay 411 passes the security information marked in this way to real data 412. In cases where a legitimate business entity (not malware) receives fake data 400, notification 413 is given regarding the scope of the fake data. Real data 412 is uploaded to accurately replace the fake data. Data callback trigger 414 is the installation of software executed on a legitimate entity (and unintentionally; a malicious entity attempting to appear legitimate), which checks for hidden signals indicating that the merged data environment may have been potentially activated. Data manager 401 is a man-in-the-middle interface between entity 415 and data that calculates the proportion of real data 412 (if any) that should be merged with fake data 400 (if any). In the case of an upload 402 and download 398 information stream, mark each group / file for data callback trigger 414 (if necessary) to account for data inversion.
[0382] Figure 64 and 65The internal workings of data callback trigger 414 are illustrated. Behavioral analysis 403 tracks the download and upload behavior of the suspicious entity 415 to identify potential corrective actions 419. The real system 417 contains the original real data 412, which exists entirely outside the virtualized environment and contains all possible sensitive data. The real data that replaces the fake data 418 is the real data provided to the data callback trace 399 in this case without filtering (even before the real data synchronizer 386). In this way, a real data patch 416 can be created to replace the fake data with the real data on the original suspicious entity 422. The data manager 401, immersed in the virtual orphaned environment 404, receives the real data patch 416 from the data callback trace 399. The patch 416 includes replacement instructions to convert the previously suspicious entity 422 (now known to be harmless) into a correct, real, and accurate information state. Such a patch 416 is passed to the data callback interface 427, which is then passed to the previously suspicious entity 422. Downloaded data 420 is data that the enterprise has already downloaded in the fake data environment 404 (therefore the data is partially or completely fake). Fixed data 421 is where the fake data is replaced with its corresponding real data after the real data patch 416 has been applied. When harmless code 409 has been cleared as malicious by behavior analysis 403, a corrective action 419 is performed. This action 419 replaces the fake data in the previously suspicious entity 422 with the real data 412 it represents. Secret token 424 is a secure string generated and assigned by LIZARD. Secret token 424 cannot prove to the virtual obfuscation system that the suspicious entity 415 is legitimate and harmless. Instead, it allows a truly harmless entity to stop its work because it knows it has been affected by the partial or complete fake data environment 391 or 394. As long as the entity is legitimate, the role of employees / software, etc., in the disinformation should not present logical problems and cause real-life problems (sending to the wrong address, wrongly dismissing employees, etc.). Data callback trigger 414 exists only on legitimate enterprise functions and entities. By default, a legitimate entity will check a pre-arranged location in the embedded server environment 404 to determine the presence of a token 424. If the token is missing 429 and 425, this indicates that the legitimate entity may have been accidentally placed in a partially fake data environment (because the risk assessment of it is malware). Subsequently, a delayed session 428 with a delayed interface 426 is activated. If tokens 426 and 424 are found, this indicates that the server environment is genuine and therefore any delayed sessions are deactivated 427. The delayed interface 426 is a module pre-installed directly on the entity. A delayed session is activated when indicated to be in a fake environment 404. A delayed session means that the entity's processes are artificially and slowly allowed behavioral analysis 403 time to make a decision about whether the entity is harmless or malicious. In practice, such a delay is expected to take several seconds per action.For actual malware, obtaining a copy of the secret token (which itself can be modified and regenerated as usual) is extremely difficult whenever it occurs, because it is secretly embedded in a 100% real data system, and malware can almost never access it. In the case scenario where the secret token is not found, combined with delayed interface 426, this implies that the entity is patient before regaining access to the real data through behavioral analysis 403.
[0383] Figure 66 The data selection process filters out highly sensitive data and merges real and fake data. Real data 412 is provided to a real data synchronizer 386 that filters out highly sensitive data 431. The filtering scope varies according to a system policy 430 defined in a static core 315. This module 431 ensures that sensitive information never reaches the same virtual environment where the suspected entity 415 exists. Data is filtered once when generating the virtual environment 404. With criteria for generation 433, the filtered real data is used as a criterion for what kind and how much fake data should be generated. The fake data generator 387 creates fake data designed to be indistinguishable from real data (i.e., a batch of SSNs). With compatibility enforcement 432, the generated fake data is verified to be compatible with the real data, ensuring that there is no excessive overlap and that there are no missing data type groups. This allows the collection of both real and fake data to be seamlessly merged without raising any suspicion, i.e., fake SSNs and real SSNs do not overlap (avoiding duplication). The virtual environment generator 434 manages the construction of the virtual environment 404, including variables such as the fake data ratio, available system functions, network communication options, and storage options. The data baseline 435 is a variable used to tune the ratio of real data to fake (false) data. With merged data 438, the data is merged according to the data baseline 435. During the merging process, real data marked as less sensitive is merged with fake data that gives a more sensitive impression. Ratio management 437 continuously adjusts the amount of real and simulated data being merged to match the desired fake data ratio. Data is merged in real time based on the data request 440 from the suspected entity 415. Data is returned at the requested data 439 with an appropriate fake data ratio.
[0384] Figure 67 and 68The internal workings of Behavior Analysis 403 are illustrated. Purpose Mapping 441 is a hierarchy of system objectives that assign purposes to the entire enterprise system. Such purposes are even assigned at the granularity of small-scale network, CPU processing, and storage events. The declared, activity, and codebase purposes are compared to the inherent system requirements of whatever the suspected entity 415 is supposedly doing. Storage, CPU processing, and network activities of the suspected entity are monitored using Activity Monitoring 453. Syntax Module 35 interprets these activities 443 according to the desired functions. Such functions are then translated by Purpose Module 36 into the expected behavioral purpose. For example, codebase purpose 446 might be submitting an annual revenue report, while activity purpose 447 might be "collecting the SSNs of all high-paid employees." This approach is similar to customs at an airport, where someone must declare certain items to customs, and customs will search their luggage anyway. Codebase 442 is the source code / programming structure of the suspected entity 415. Entities that do not publicly disclose their source code (because it is a compiled, closed-source program) can be prevented from accessing the system by system policy 430. Such a codebase 442 is forwarded as a subset of behavioral analysis 403 to the syntax module 35. The syntax module 35 understands the encoding syntax and is able to reduce the programming code and code activities to intermediate mappings of interconnect functions 444. Such functions 444 represent the functionality of the codebase 442 and activities 443 and are transferred to the purpose module 36, which generates a perceived 'intent' for the suspected entity 415. The purpose module 36 produces output codebase purpose 446 and activity purpose 447. The codebase purpose 446 contains the known purpose, function, jurisdiction, and authority of entity 415 as derived from LIZARD's syntax programming capabilities. The activity purpose 447 contains the known purpose, function, jurisdiction, and authority of entity 415 as understood by LIZARD's understanding of its storage, processing, and networking activities 453, where the stated purpose is the entity's assumed purpose, function, jurisdiction, and authority as declared by the entity itself. The desired purpose 445 contains the expected purpose, function, jurisdiction, and authority required by the enterprise system. This is analogous to hiring to fulfill the company's needs. This allows LIZARD to block suspicious entity 415 if its capabilities and / or services are not absolutely necessary for the system. All four objectives 445-448 are compared in comparison module 449 to ensure that the presence and behavior of entity 415 are deserved and understood by LIZARD in the production of objective 336 toward the system. Any inconsistency between the four objectives 445-448 will invoke the disagreement in objective 450, leading to corrective action 419. The corrective action may potentially mark suspicious entity 415 as malware 385 or harmless 409. Subsequent actions might include securely destroying the virtual container or cautiously moving malware 385 to a new virtual environment with zero access to real data (only fake data) and the real enterprise network.
[0385] Critical Thinking Memory & Perception (CTMP)
[0386] Figure 69 The diagram illustrates the main logic of CTMP 22. The primary goal of CTMP is critical decision-making by a third party. CTMP 22 cross-references multiple sources (i.e., I...). 2The system (such as GE, LIZARD, and Trusted Platforms) is intelligent and understands expectations of perception and reality. CTMP estimates its ability to make objective decisions about a matter and will avoid asserting decisions made with low internal confidence. Incoming data streams (such as the military's global deployment of spies and information from feasible platforms) are transformed into actionable data. Subjective opinion decision 454 indicates the original subjective decision provided by the input algorithm, referred to as the Selected Pattern Matching Algorithm (SPMA) 526. This SPMA is typically a security-related protection system, but is not limited to other types of systems, such as Lexical Objectivity Mining (LOM) (inference algorithm) and Permanent Giving Method (MPG) (tax interpretation algorithm). Input system metadata 455 indicates the original metadata from SPMA 526, which describes the mechanical process of the algorithm and how such decisions are made. Inference processing 456, assertions are logically understood by comparing properties. In rule processing 457, a subset of the inference processing, as derived result rules, is used to determine the scope of the current problem. The Critical Rule Scope Extender (CRSE) 458 utilizes the known scope of perception and upgrades it to include the scope of critical thinking. Correct Rule 459 indicates the correct rule derived using the scope of critical thinking. In Memory Web 460, the log of market variables (Market Performance 30 and Profile History 31) is scanned to implement the rules. Any applicable and implementable rules are executed to produce an investment allocation coverage decision. In Rule Execution (RE) 461, rules that have been identified as existing and implemented based on a scan of the chaotic field 613 using memory are executed to produce the desired and relevant critical thinking decision. This execution of rules necessarily produces a definite result. While chaotic and complex processes may lead to inconsistent results, the logically complex process of RE 461 always leads to the same deductive result, provided the rule set is consistent. In Critical Decision Output 462, the final logic for determining the overall output of CTMP is generated by comparing the conclusions drawn by both the Perceptual Observer Simulator (POE) 475 and Rule Execution (RE) 461. Critical Decision 463 is the final output; it is an opinion on a matter, attempting to be as objective as possible. Log 464 is the raw information used to make independent critical decisions without the influence or bias of subjective opinions from the input algorithm (MPG). Raw Perception Generation (RP2) 465 is the module that receives metadata logs from SPMA 526. Such logs are parsed to form a perception representing the perception of this algorithm. This perception is stored in a Perception Complex Format (PCF) and simulated by a Perception Observer Simulator (POE) 475. Applied Perception Angles 466 indicates the perception angles that have been applied and utilized by SPMA 526.Automatic Perception Discovery Mechanism (APDM) 467 instructs the use of a module of Creative Module 18, which generates (based on input provided by the applied perception angle 466) mixed perception, thereby increasing the scope of perception. Critical Thinking 469 instructs the jurisdiction of the outer shell of rule-based thinking. This results in the manifestation of rule execution (RE) 461, which manifests rules well established according to SPMA 526 but also manifests new correct rules 459 derived from within CTMP.
[0387] refer to Figure 70 The self-critical knowledge density 474 is derived from the raw log representing known technical knowledge in SPMA 526. This module 474 estimates the scope and type of potential unknown knowledge not available in the reportable log. Thus, subsequent critical thinking features of CTMP can utilize the potential scope of all involved knowledge, both directly known and unknown to the system. The Perceptual Observer Simulator (POE) 475 generates an observer simulation and tests / compares this change to all potential perceptual points. The input is all potential perceptual points in addition to the enhanced data log. The output is a security decision derived from this merging of the enhanced log based on the best, most relevant, and most cautious observer utilizing the selected perceptual data. Reference Implicit Derivation (ID) 477 derives the angle of potentially implicit perceptual data from the current application's perceptual angle 470. Reference Overlay Correction Action 476 is generated by the Perceptual Observer Simulator (POE) 475 to produce the final correction action / assertion critique.
[0388] Figure 71The dependency structure of CTMP is illustrated. Referring to Resource Management & Allocation (RMA) 479, an adjustable strategy indicates the perceptual quantities used to perform observer simulation. The priority of the selected perceptual quantities is chosen based on descending weights. The strategy then indicates the method of truncation, rather than choosing a percentage, a fixed number, or a more complex algorithm. Referring to Storage Search (SS) 480, CVF derived from the data augmentation log is used as a criterion in the database lookup of Perceptual Storage (PS) 478. Measurement Processing (MP) 489 reverse-engineers the variables from the selected Pattern Matching Algorithm (SPMA) 526 for investment allocation into intelligent 'help' perceptual data from such an algorithm. Perceptual Deduction (PD) 490 uses the investment allocation response and its corresponding system metadata to replicate the original perceptual data of the investment allocation response. Critical Decision Output (CDO) 462 indicates the final logic used to determine the CTMP output. Referring to Metadata Classification Module (MCM) 488, debugging and algorithmic tracking are categorized into different classes using information classification based on traditional grammar. This classification can then be used to organize and generate different investment allocation responses related to market / tax risks and opportunities. Reference system metadata separation (SMS) 487 separates the input system metadata 455 into meaningful investment allocation causal relationships. Reference filler logic 483 comprehensively categorizes all investment allocations with their associated market / tax risks, opportunities, and their respective responses. Subject navigator 481 scrolls through all applicable subjects. Subject filler 482 retrieves appropriate investment risks and allocations associated with each subject. In addition to their associated weights, perception storage (PS) 478 stores perceptions in comparable variable format (CVF) as its index. This means the database is optimized to receive CVFs as input queries, and the results will be perceptions of various types.
[0389] refer to Figure 72 Implicit Inference (ID) 477 derives the angles of the perception data that may be implicit from the currently known perception angles. Referring to Self-Critical Knowledge Density (SCKD) 492, the incoming raw log represents known knowledge. This module estimates the range and type of potential unknown knowledge that is not available from the reportable log. In this way, subsequent critical thinking features of CTMP can utilize the potential range of all involved knowledge, both directly known and unknown to the system. In Metric Combination 493, perception angles are categorized into metric categories. In Metric Transformation 494, individual metrics are inverted back to the entire perception angle. In Metric Extension (ME) 495, metrics for multiple and varying perception angles are stored by category in separate databases. The upper bound is represented by the peak knowledge of each individual metric DB. When augmented and enriched in complexity, metrics are returned as perception angles and utilized for critical thinking. In the case of a Comparable Variable Format Generator (CVFG) 491, the information flow is converted to a Comparable Variable Format (CVF).
[0390] Figure 73The dependency structure of CTMP is illustrated. In the Critical Rule Scope Expander (CRSE) 458, the critical thinking scope of the rule set is expanded using known perceptions. In Perception Matching 503, a variable variable format (CVF) is formed from perceptions received from Rule Syntax Derivation (RSD) 504. The newly formed CVF is used to look up related perceptions in the Perception Store (PS) 479 using similar indexes. Potential matches are returned to Rule Syntax Generation (RSG) 505. In Memory Recognition (MR) 501, a chaotic field 613 is formed from the input data. A field scan is performed to recognize known concepts. In Memory Recognition Indexing 500, the entire concept is individually optimized into independent parts called indexes. These indexes are used by a letter scanner to interact with the chaotic field 613. The Rule Implementation Parser (RFP) 498 receives the individual parts of the rules with recognition tags. Each part is marked as either discovered or undiscovered in the chaotic field 613 obtained through Memory Recognition 501. RFP logically deduces which overall rules (combinations of all their parts) should be obtained from rule execution (RE) 461 within the chaotic field 613. In Rule Syntax Format Separation (RSFS) 499, correct rules are separated and organized by type. Thus, all actions, properties, conditions, and objects are stacked separately. This allows the system to discern what parts have been found in the chaotic field 613 and what have not yet been found. In Rule Syntax Derivation 504, logical 'black and white' rules are converted into metric-based perceptions. The complex arrangement of multiple rules is transformed into a single unified perception expressed by multiple metrics via varying gradients. Rule Syntax Generation (RSG) 505 receives previously confirmed perceptions, which are stored in a perception format and participate in the internal metric composition of the perception. This gradient-based measurement of metrics is converted into binary and logical rule sets to simulate the input / output information flow of the original perception. Rule Syntax Format Separation (RSFS) 499 represents a precise representation of the rule set that conforms to the reality of the observed object. Correct rules are separated and organized by type. Thus, all actions, properties, conditions, and objects are stacked separately. This enables the system to identify which parts of the chaotic field 613 were found and which parts were not. The intrinsic logical deduction 506 uses logical principles to avoid fallacies, deducing what kind of rules will accurately represent the many metric gradients within the perception. To illustrate with an example, this is like taking an analog sine wave (such as radio frequency) and converting it into a digital step. The overall trend, position, and result are the same. However, the analog signal has been converted to digital. Metric context analysis 507 analyzes the interconnections within the metric perception. Some metrics may depend on other metrics with different degrees of magnitude. This contextualization is used to complement the mirrored interconnections of the rules within the 'digital' rule set format. Input / output analysis 508 performs differential analysis on the inputs and outputs of each perception (grey) or rule (black and white).The goal of this module is to ensure that the inputs and outputs remain as similar or identical as possible after transformation (from gray to black / white and vice versa). Criterion calculation 509 calculates the criteria and tasks of the input rules. This can be translated as the 'motivation' behind the rule set. There are reasons for implementing rules, which can be understood through implicit or explicit definitions. Therefore, by calculating the implicit reasons why 'digital' rules have been implemented, the same reasons can be used to justify the composition of measurements in perception that seeks the same input / output capabilities. Rule formation analysis 510 analyzes the overall composition / structure of the rules and how they interact with each other. This is used to complement the mirror interconnections within 'analog' perception. In the case of Rule Syntax Format Transformation (RSFC) 511, the rules are classified and separated to conform to the syntax of Rule Syntax Format (RSF) 538.
[0391] Figure 74 The final logic for processing intelligent information in CTMP is shown. This final logic receives intelligent information from both intuition / perception and thinking / logic modes (Perception Observer Simulator (POE) 475 and Rule Enforcement (RE) 461, respectively). In Direct Decision Comparison (DDC) 512, the two decisions from intuition and thinking are compared to examine further verification. A key distinction is that meta-data is not yet compared, as understanding why is redundant if they agree anyway. Terminal Output Control (TOC) 513 is the final logic for determining the CTMP output between mode intuition 514 and thinking 515. Intuition decision 514 is one of the two main parts of CTMP utilizing perception in critical thinking. See Perception Observer Simulator (POE) 475. Thinking decision 515 is the other of the two main parts of CTMP utilizing rules in critical thinking. See Rule Enforcement (RE) 461. Perception 516 is data received from intuition decision 158 according to the format syntax defined in internal format 518. Rule 517 is the data received from thought decision 515, which is a set of applicable (implementable) rules from rule execution (RE) 461. This data is transmitted according to the format syntax defined in internal format 518. By using internal format 518, the metadata classification module (MCM) 488 is able to recognize the syntax of both inputs, as they have been standardized according to a known and consistent format used internally by CTMP.
[0392] Figure 75 This illustrates the two main inputs—intuition / perception and thought / logic—that are assimilated into a single terminal output representing the entire CTMP. Critical Decision Making + Meta-Metadata 521 is a digital carrier that transmits perception 516 or implemented rules 517 according to the syntax defined in the internal format 518.
[0393] Figure 76 This illustrates the scope of intelligent thinking that emerges in the original Selected Pattern Matching Algorithm (SPMA) 526. Input variables 524 are the initial financial / tax allocation variables considering cause and rule processing. CTMP intends to critique them and act as a second opinion for artificial intelligence. Variable inputs 525 receive input variables that define the security decision. These variables provide CTMP with criteria for discerning what constitutes a reasonable corrective action. If variables are added, subtracted, or changed, then the appropriate change must be reflected in the resulting corrective action. CTMP's key objective is to identify the correct, critical change that correctly and accurately reflects the changes in the input variables. With the Selected Pattern Matching Algorithm (SPMA) 526, the Selected Pattern Matching Algorithm attempts to discern the most appropriate action based on its own criteria. The resulting output form 527 is the result produced by SPMA 526 using the initial input variables 168. The rule derived from the SPMA 526 decision is considered the 'current rule,' but not necessarily the 'correct rule.' As attributes are merged based on log information provided by SPMA 526 528, cause processing 456 continues within the current scope of knowledge according to SPMA 526.
[0394] Figure 77 This illustrates a standard SPMA juxtaposed with critical thinking performed by CTMP via perception and rules. In the case of a misunderstood action 531, the selected pattern matching algorithm (SPMA) 526 fails to provide a fully accurate corrective action. This is because some fundamental assumptions are not checked in the original programming or data of SPMA 526. In this example, using a 3D object as the input variable and the correct appropriate action illustrates a dimension / vector not considered by SPMA 526. In the case of an appropriate action 532, critical thinking considers the third dimension, which is omitted by SPMA 526 as a vector to be checked. The third dimension is considered by critical thinking 469 because all additional perceptual angle checks are performed. Referring to the correct rule 533, the Critical Rule Range Expander (CRSE) expands the understanding of the rule set by utilizing the previously unconsidered perceptual angle (i.e., the third dimension). Referring to the current rule 534, the rule derived from the current corrective action decision reflects an understanding of SPMA 526 or its deficiencies (compared to the correct rule). The input rules are derived from the selected pattern matching algorithm (SPMA) 526, which describes the default scope of understanding provided by SPMA. This indicates that SPMA 526 only understands two dimensions of the planar concept of financial appropriations.
[0395] Figure 78This demonstrates how the correct rule 533 is generated compared to the regular current rule 534, which omits deep understanding and / or variables. In the case of Chaotic Field Parsing (CFP) 535, the log format is combined into a single scanable unit called a chaotic field 613. Additional rules 536 are generated from Memory Recognition (MR) 501 to supplement and establish the correct rule 533. Referring to the perception rule 537, perceptions considered relevant and popular have been converted into logical rules. If a perception (in its original perception format) has many complex metric relationships defining many 'gray areas', then the 'black and white' logical rules encompass such 'gray' areas through an n-level expansion of complexity. The rule syntax format 538 is a storage format optimized for efficient storage and querying of variables.
[0396] Figure 79 and 80 The Perceptual Matching (PM) module 503 is described. Regarding metric statistics 539, statistical information is provided from the Perceptual Storage (PS) 479. This statistics define the popularity trend of metrics, internal metric relationships, and metric growth rates, etc. Some general statistical queries (such as overall metric popularity ranking) are automatically executed and stored. Other more specific queries (how metrics X and Y are related) are requested in real-time from the PS 479. Metric Relationship Maintenance 540 maintains metric relationship data so that it can be pushed into a unified output. Error Management 541 resolves syntax and / or logical errors originating from any individual metrics. Separate Metrics 542 separates each individual metric because they were previously combined into a single unit as input perception 544. Input perception 544 is an example combination of perceptions consisting of metrics of vision, smell, touch, and hearing. The Node Comparison Algorithm (NCA) 546 receives nodes from two or more CVFs. Each node of the CVF represents the magnitude of a property. Similarity comparisons are performed on an individual node basis, and aggregate variance is calculated. This ensures accurate comparisons for efficient computation. A smaller variance (whether it's node-specific or aggregated weights) indicates a closer match. Comparable Variable Format (CVF) 547 is an intuitive representation used to illustrate the various configurations of CVF. Matches are submitted because output 550 is the terminal output of Perceptual Matching (PM) 503. Any node overlap in the Node Comparison Algorithm (NCA) 546 is preserved as a match result, and thus the overall result is submitted in stage 550.
[0397] Figures 81-85This illustrates the derivation / generation of rule syntax. The original perception-intuitive thinking (analog) 551 processes perception according to the 'analog' format. The original rule-logical thinking (digital) 552 processes rules according to the numerical format. The analog format 553 perception related to financial allocation decisions is stored in gradients on a smooth, orderless curve. The numerical format 554 original rules related to financial allocation decisions are stored in orders small enough to have no 'grey areas'. In terms of data content, the original rule 555 is identical to the correct rule 533. The difference is that the original rule 555 has been converted to a more dynamic format by Rule Syntax Format Separation (RSFS) 499, which allows cross-referencing with the chaotic field 613 via memory recognition 501. The identifiable rule segment 556 is a rule derived from the original rule 555 already recognized by memory recognition 501. This indicates that the individual segments constituting the original correct rule 533 (e.g., actions, attributes, conditions, and objects) have been identified in the chaotic field 613 and are therefore applicable to rules that potentially become logically realized. The security coverage decision 557 is the final result of rule execution (RE) 461, which allows for corrective actions to be performed. Such corrective actions are also channeled to Terminal Output Control (TOC) 513, a subset of the larger corrective action logic executed in Critical Decision Output (CDO) 462. Unimplemented rules 558 are sets of rules that have not yet been adequately identified in the chaotic field 613 based on their logical dependencies (according to rule implementation parser 498). Similarly, satisfied rules 517 are identified as adequately available in the chaotic field 613 based on the logical dependencies analyzed by CDO 462. The third-party database solution 559 is the hardware interface software that manages buffers, caches, disk storage, thread management, memory management, and other typical mechanical database functions. The debugger 560 attempts to find the cause of the unimplemented rules. Either the chaotic field 613 is not rich enough, or the rule set is inherently illogical. If the rule set is illogical, it can be checked immediately with a certain degree of accuracy. However, in order to establish the potential sparsity of the chaotic field 613, multiple investigations must be conducted in order to avoid falling into the fallacy of performing insufficient investigations.
[0398] Figures 86-87This illustrates the operation of the Rule Syntax Format Separation (RSFS) module 499. In this module, correct rules 502 are separated and organized by type. Therefore, all actions, properties, conditions, and objects are stacked separately. This allows the system to identify which parts of the chaotic field 613 have been found and which have not. Regarding actions 561, one of the four rule segment data types indicates an action that may have been executed, will be executed, be considered for activation, etc. Regarding properties 562, one of the four rule segment data types indicates a property-like attribute describing something else, which is an action, condition, or object. Regarding conditions 563, one of the four rule segment data types indicates a logical operation or operator (e.g., if x and y then z, if x or z then y, etc.). Regarding objects 564, one of the four rule segment data types indicates that attributes such as actions 561 and properties 562 are applied to their targets. In processing phase 565, the relations derived so far are submitted as output, and the program then terminates. Processing phase 566 iterates through one entry at a time by rule segment. Processing phase 567 interprets and records each individual relationship between rule segments (e.g., action 561, object 564, etc.). Therefore, in phase 565, each individual relationship is collected and prepared for output. Sequential scanning 568 splits each unit of RSF 538 at the '[split]' marker. Subjects and attachments from RSF 538 are also separated and parsed. Separation output 569 is where the individual subjects and their internal subject relationships are held by the scanner. They are immediately sent for output as the entire RSF 538 is sequentially scanned. Separation rule format 570 is the delivery mechanism for containing the individual rule segments (e.g., action 561, object 564, etc.) from separation output 569. Separation rule format 570 is highlighted in two key aspects of information delivery: firstly as output from Rule Syntax Format Separation (RSFS) 499 (considered the pre-memory recognition phase) and secondly as output from Memory Recognition (MR) 501 (post-memory recognition phase).
[0399] Figure 88This illustrates the operation of the Rule Implementation Parser (RFP) 498. This module receives individual segments of a rule with identification tags. Each segment is marked as either found or not found in the chaotic field by Memory Recognition (MR) 501. RFP 498 logically deduces which overall rules (i.e., combinations of all their parts) should be fully identified in the chaotic field 613 by Rule Execution (RE) 461. Queue Management (QM) 561 uses the Syntax Relation Reconstruction (SRR) 497 module to analyze each individual part in the most logical order. QM 561 accesses the results of Memory Recognition (MR) 501 so that it can answer binary yes / no flow questions and take appropriate actions. QM checks each rule segment in stages, and if a single segment is missing in the chaotic field 613 and has no appropriate relationship with other segments, the rule set is marked as unimplemented. If all check stages pass, the rule set is marked as implemented 522. QM stage 571 checks whether the rule segment 'object C' is found in the chaotic field 613. QM phase 572 checks whether the next appropriate segment is related to the original 'object C', and also finds the rule segment 'object C' in the chaotic field 613 based on memory recognition (MR) 501. The same logic is applied to QM phases 573 and 574 for condition B and action A, respectively. These segment representations (A, B, C, etc.) are not part of the core program logic, but rather reference consistent examples used to demonstrate expected and typical use. Receiving the fully reconstructed rule set 575 requires the satisfying rule set output of queue management 576, assuming that the rule set is found to be implementable, and that the association of rule segments is given by the syntactic relation reconstruction (SRR) module 497.
[0400] Figures 89-90The implementation debugger 560 attempts to find out why the rules are not implemented. Either the chaotic field 613 is not rich enough, or the rule set is inherently illogical. If the rule set is illogical, it can be checked immediately with a certain degree of accuracy. However, to establish the potential sparsity of the chaotic field 613, multiple investigations must be conducted to avoid the fallacy of performing insufficient investigations. The field sparsity investigation 577 specifically checks whether the chaotic field 613 is rich enough or insufficient to trigger the variable composition of the rule set. The scan 578 checks the presence of relevant rule components within the chaotic field 613. The investigation database 579 stores the investigation results for recent reference. If the investigation database 579 is saturated / filled, then condition 580 is checked. This means that any possible scans of the rule parts have been performed, even if the scans produce positive or negative results. If all possible scans have been performed, then conclusion 581 is implicit: the sparsity throughout the chaotic field 613 is why the rule set is classified as unimplemented. If not all possible scans have been performed, then conclusion 582 is implicit: the investigation is incomplete and more sectors of the chaotic field 613 need to be scanned to reliably determine whether the sparsity of the chaotic field 613 is the reason why the rules become unrealized. The logical impossibility test 583 checks whether there are inherently impossible logical dependencies within the rule set that would cause it to be classified as unrealized. For example, object 584 'bachelor' has been assigned property 585 'married,' leading to an inherent contradiction. Test 583 determines the dictionary definitions of items 584 and 585. The internal rule consistency check 588 checks whether all properties are consistent with and related to their object counterparts. 'bachelor' 584, in RSF 538 format, contributes to the partial definition of object 586 'man,' while the definition of 'married' 585 (also in RSF 538 format) contributes to the partial definition of object 587 'two people.' The conclusion of examination 588 is that definitions 586 and 587 are compatible in that subject 586 'male' potentially includes subject 587 'two people'. During the rule relevance transformation 589, the fairness term is transformed to perform a comparison test. Such a transformation allows the second definition ('married') to be understood within the context of the first definition ('bachelor'). This leads to the conclusion 591 that the rule contains an inherent contradiction: the same person is currently married 590 and simultaneously currently unmarried 592.
[0401] Figure 91The rule execution (RE) 461 is shown; the execution of rules that have been confirmed to exist and implemented based on a scan of the chaotic field 613 from memory to produce desired and relevant critical thinking decisions. A chessboard plane exists, which is used to track the transformations of the rule set. Objects on this board represent the complexity of any given security situation, and the movement of these objects across the 'security chessboard' indicates the evolution of the security situation managed by the response of the security rule set. Phase 1 593, RSF 538 information defines the initial starting positions of all relevant objects on the chessboard plane, thus defining the beginning of a dynamically cascading security situation. This is symbolically used to illustrate the logical 'position' of the rules that process dynamic security policies. Phases 2 594 and 6 598 indicate object transformations that illustrate the security rules being applied, which modify the position and scope of certain security situations. For example, object transformations in phases 2 and 6 could represent the encryption of critical documents. Phase 3 595 illustrates the movement of objects on the chessboard, which could correspond to the actual movement of sensitive documents to off-board positions as part of a security response policy. Phases 4596 and 5597 illustrate the process of merging two objects into a common third object. An example application of this rule is two independent and isolated local area networks being merged to facilitate the efficient and secure management of information transmission. The results of the correct rule 533 and the current rule 534 differ upon completion of rule execution (RE) 461. This illustrates the critical thinking advantage of CTMP execution, rather than the less critical results produced by the selected pattern matching algorithm (SPMA) 526. All shapes, colors, and positions symbolically represent security variables, occurrence rates, and responses (for simplicity of interpretation rather than actual security objects). SPMA has produced a final shape and position different from CTMP, as well as similar but distinct color differences (orange versus yellow) for the pentagon. This arises from complex conditional statements (consisting of a set of rules that process all input logs). This is analogous to how a billiards game can begin with varying player variables (height, strength, etc.) that can lead to entirely different ball positions. CTMP also transforms the purple square into a cube, symbolically representing (throughout the description of CTMP) its ability to consider SPMA 526 or even sizes and perceptions that humans never expect or consider. The final safety coverage decision is executed according to the correct rule 533 599.
[0402] Figure 92 and 93Sequential memory organization is described as an optimized information storage method that offers greater efficiency in reading and writing "chains" of sequential information, such as the alphabet. In memory access points 600, the width of each node (block) in node 601 represents the observer's direct accessibility to the object (node) being memorized. In the alphabetical order of memory, 'A' is the most accessible memory point because it is the first node in the sequence. The letters E, H, and L are also more easily accessed directly because they are the "leaders" of their own subsequences 'EFG', 'HIJK', and 'LMNOP'. Within the range of accessibility 602, each letter represents its direct memory access point to the observer. A wider range of accessibility indicates that more accessibility points exist for each sequential node, and vice versa. The more sequences are referenced 'in order' rather than from any randomly selected node, the narrower the range of accessibility (relative to the sequence size). This allows for more efficient memory recall based on the magnitude of orderliness. In the case of nested subsequence layers 603, sequences exhibiting strong non-uniformity consist of a series of interconnected smaller subsequences. The alphabet is a high-level indicator of this behavior, as each individual subsequence 'ABCD', 'EFG', 'HIJK', 'LMNOP' exists independently as a memory sequence, but they are interconnected and form the entire alphabet. This type of memory storage and referencing can be more efficient if there are occasional or frequent accesses to certain nodes of the main sequence. In this way, scanning from the entire sequence can be avoided for efficiency in terms of time and resources. This is similar to scanning a book by chapters rather than scanning the book from the first page in each search. In the extremely non-uniform range 605, there are inconsistent access points that pervade all nodes. This means it consists of a large number of nested subsequences that are interconnected like chains. A highly non-uniform sequence means it is moderately ordered, but should have multiple memory access points (nested subsequence layers). An example of highly non-uniform 605 is the alphabet, which is variable and difficult to memorize depending on which letter you start with. In the case of a highly uniform 607 range, there are consistent access points throughout all nodes. This means it is not composed of nested subsequences interconnected like a chain. A highly uniform sequence means it is either highly continuous (with almost no consistent access points throughout nodes) or highly discontinuous (with consistent large access points throughout nodes). An example of highly uniform 607 is a set of fruits, which has almost no specified or emphasized sequence when memorizing them, and no interconnected subsequences. A moderately uniform range 606 has initial large access nodes, meaning that memorizing the content from the beginning is most efficient. However, the main content is linear, which indicates that there are no nested subsequence layers and there are unusually large sequences. A moderately non-uniform range 604 does not deviate too much from linearity and therefore has consistent access points throughout.This indicates the existence of more subtle and less restrictive nested subsequence layers, while still conforming to a consistent and reversible set. An example of information exhibiting moderately non-uniform 604 behavior could be a catalogue of car manufacturers. There are categories that can be specified, such as sports cars, hybrid vehicles, and SUVs, but there is no strong bias in how the list should be memorized or remembered, as potential customers may still compare SUVs and sports cars, despite the separate category designations.
[0403] Figure 94 This illustrates a non-sequential memory organization that handles the storage of information about non-sequential related items. In the case of a set of fruits, there is no highly specified order in which they should be read, whereas an alphabet has a strong sequential order in how information should be read. Memory organization 608 shows a consistently uniform number of access points for all fruits, indicating a non-sequential organization. The organization in 608 illustrates how reversibility indicates a non-sequential arrangement and uniformity. In this case, it indicates that the memory of the fruits is non-sequential, as indicated by the relatively wide number of access points for each node. The same uniformity exists when the order of the fruits is shuffled, indicating that the order of the fruits is reversible. Conversely, sequential series like the alphabet are more difficult to memorize backwards than conventionally. Common fruit lists do not exhibit this phenomenon, indicating that references outside of sequential lists are more frequent than those within them. In core themes and associations 609, because there is no sequentiality in this fruit list, the same series of fruits are repeated but with different cores (central objects). The core represents the main theme, and the remaining fruits act as its memory neighbors, which are more easily accessed than if the defined core theme did not exist. In strong neighbor 610A, although apple is a common fruit, its strong association with pineapple is stronger than with other common fruits due to spelling overlap. Therefore, pineapple is considered a more associative memory. In weak neighbor 610B, because pineapple is a tropical fruit, it is less associated with oranges and bananas (common fruits). Pineapple is more likely to be identified as mango due to tropical overlap. Figure 612 illustrates how a very weak order in the fruit series leads to a very strong uniformity in the visits to node 601.
[0404] Figures 95-97The illustration shows Memory Recognition (MR) 501, where a chaotic field 613 scan is performed to identify known concepts. The chaotic field 613 is a 'field' of concepts arbitrarily immersed in 'white noise' information. This is made known to the CTMP system on a spontaneous basis, and it is considered "in its natural state" and unpredictable. The purpose of Memory Recognition is to efficiently scan the field to identify known concepts. With Memory Concept Retention 614, identifiable concepts are stored and ready to be indexed and checked against the reference field. The illustration uses a simplified example of vegetable name spelling for ease of understanding of the system. However, this example can be used as an analogy to much more complex scenarios. For a real-life security example, this could include identifying and distinguishing between civilians and military personnel in a camera feed. For a cybersecurity example, this could include identifying known and remembered Trojans, backdoors, and detecting them in a lot of security white noise (logs). In the case of a 3-letter scanner 615, the chaotic field 613 is scanned and the 3-letter segment corresponding to the target is examined. For example, 'PLANT' is the target, and the scanner moves along the field incrementally in increments of 3 characters. With each advancement of the scanner, the segments 'PLA', 'LAN', and 'ANT' are examined because they are subsets of the word 'PLANT'. Nevertheless, the words 'LAN' and 'ANT' are independent words that happen to be the target as well. Therefore, when one of these three letter segments is found in the field, it can imply that the entire target of 'LAN' or 'ANT' has been found, or perhaps a subset of 'PLANT' has been found. The same concept applies to the 5-letter scanner 616, but this time the segment examined with each advancement across the entire field is the entire word 'PLANT'. Targets such as 'LAN' and 'ANT' are omitted because at least 5 letter targets are required using a 5-letter scanner. The chaotic field 613 is segmented to allow scanning at different ratios (3, 5, or more letter scans) because this ratio provides different levels of scanning efficiency and power. As the scanning range shrinks (smaller number of letters), accuracy increases (and vice versa). Larger letter scanners are more efficient at performing recognition as the scanner's field size increases, at the cost of accuracy (which depends on how small the target is). Within the Memory Concept Index (MCI) 500, stage 617 alternates the size of the scanner (3, 5, or more) in response to the unprocessed memory concepts they leave behind. MCI 500 begins with the largest available scanner and gradually decreases in stage 617, allowing more computational resources to be discovered to examine the potential presence of smaller memory concept targets. Stage 618 cycles through the available memory concepts so that their indices (smaller segments of appropriate length, such as 3 or 5) can be derived in stage 620. If a memory concept does not yet exist in the concept index hold 624, stage 619 creates it according to the logistics of the action.Then, stage 621 assigns the derived index from stage 620 to hold 624. As the full cycle of programming the MCI 500 continues, if the MCI runs out of unprocessed letter scanners, it reaches a fork where an empty (equal to zero) result 622 is committed if hold 624 is empty, or a non-empty hold 624 is committed as modular output 623. The range of segments in the chaotic field 613 varies from the number 625 to 628. Segments 625 and 626 represent scans performed by a 5-letter scanner, while segments 627 and 628 represent 3-letter scans. Scan 625 has a 5-letter width when examining the 6-letter target 'TOMATO'. The two 5-letter segments match at 'TOMAT' and 'OMATO', which were previously indexed at MCI 500. Each of these corresponds to a 5-letter match in a 6-letter word, which further corresponds to 83%. This score / percentage is accumulated to benefit from a 167% match for memory concept 637, thus successfully finding the concept 'TOMATO' in chaotic field 613. Scan 626 has a memory concept target of 'EGGPLANT', where two important segments are 'GGPLA' and 'PLANT'. Although 'GGPLA' specifically refers to a true match for 'EGGPLANT', the segment 'PLANT' introduces the possibility of a false positive, as 'PLANT' is in the memory concept target and is itself a memory concept target. For a system that identifies 'PLANT' as existing in chaotic field 613, and 'EGGPLANT' is the only truly identifiable memory concept in the field, this would be classified as a false positive. However, the system is programmed to avoid the case scenario of a false positive, as 'GGPLA' contributes 63% of the matches. 'PLANT' in the context of 'EGGPLANT' also contributes 63%, while 'PLANT' in the context of the target 'PLANT' contributes 100%. When the matching aggregation was added, the target 'EGGPLANT' received an aggregation score of 125% (63% + 63%) 638, while the target 'PLANT' received 100% 639. Therefore, the scanner successfully maintained the correct interpretation of the chaotic field 613. Scan 627, with a width of 3 letters, identified the segment 'TOM,' resulting in a 50% aggregation match 640. This is the same target present in the field as in scan 625, but due to the difference in scan width (3 instead of 5), a weaker confidence (50% vs. 167%) match was found. Therefore, the MCI 500 is designed with multiple scan width layers to achieve the right balance between accuracy and computational resource expenditure. Scan 628 also merged with a 3-letter width, this time with two potential false positive tangents 636. Although the actual concept in the field is 'CARROT', the concepts 'CAR' and 'ROT' are considered to exist in the field and are themselves present in the field.The scanner must now determine which concept is correct in the chaotic field 613. This will be checked using a subsequent scan of nearby letters. Ultimately, the scanner identifies the concept as 'CARROT' and not 'CAR' or 'ROT', due to further evidence from other locating indices. Both the 100% composite match of 'CAR'641 and the 100% composite match of 'ROT'643 lose to the 200% composite match of 'CARROT'642.
[0405] Figures 98-99 Field Interpretation Logic (FIL) 644 and 645 are shown, which operate the logic for managing scanners of different widths using appropriate results. General range scan 629 begins with a large letter scan. This type of scan can examine a large range of fields with fewer resources, at the cost of small-scale accuracy. Therefore, smaller letter scanners are delegated to more specific field ranges to improve accuracy when needed. Specific range scan 630 is used when meaningful regions have been located and need to be 'zoomed in'. A general correlation is that the smaller the field range chosen for scanning, the smaller the type of scanner (fewer letters). This ensures that expensive, accurate scans are not performed in redundant and non-bent locations. Segment 645 of the FIL displays conservative logic to the scanner results. If a particular scanner receives additional recognition of a memory concept in a chaotic field 613, this indicates that field range 631 (segment 613) contains a dense saturation of memory concepts and warrants "zooming in" on that particular range with a smaller width scan. Therefore, a 5-letter scanner with a field range of 30% 632 will activate a 3-letter scanner with a field range of 10% 633, depending on the initial result returned by what is considered "additional" recognition 634. "Additional" in 634 means that the recognition is supplementary to the preliminary recognition performed in FIL segment 644.
[0406] Figure 100-101The Automatic Perception Discovery Mechanism (APDM) 467 is illustrated. Observer 646, while representing a digital or human observer, can perceive the same object through multiple senses. The observable object is used to illustrate potential cybersecurity case scenarios. Perception angle A 647 produces a limited range of information about the observable object because it is rendered in two dimensions. Perception angle B 648 produces a more informed range because it includes a third dimension. The result of perception angle C 649 is unknown to our limited thinking abilities because the creative mixing process 18 is being utilized by modern parallel processing capabilities. Critical thinking algorithms have the potential to generate more forms of perception by mixing the metrics of angles A and B and thus forming new iterations 653, which may exceed human understanding of auditory perception or the exponential relationship (not a plateau) between iterative complexity + performance and CPU time and capability. Perception angle 650 is defined by a variety of metrics, including but not limited to range, type, intensity, and consistency 651. These may become more complex in range than the examples given above, and therefore there may be many complex perceptual variations generated by the creative module. Perception weight 652 defines the relative impact of perception on the perception when simulated by the Perception Observer Emulator (POE) 475. The weights of these two input perceptions are considered when defining the weights of the new iterative perception 653. This new iterative perception 653 incorporates a hybrid metric influenced by the previous generation of perception: A+B. Such a new perception perspective may potentially provide a productive new advantage for security software in detecting covert exploits. Several generations of perception are selected for hybrid use through a combination of trial / error and intelligent selection. If a perception (especially a new iterative perception) proves useless in providing insights into security issues, then it can be de-emphasized in its use, but it is rarely removed because it is never fully known whether it will provide useful insights. Therefore, the trade-off between computational resources and security intelligence is something that must be experienced firsthand.
[0407] Figure 102 The original perception generation (RP2) 465 is shown, which is a module that receives metadata logs from the selected pattern matching algorithm (SPMA) 526. Such logs are parsed to form a perception representing the perception of this algorithm. This perception is stored in a perception complexity format (PCF) and simulated by a perception observer simulator (POE). System metadata separation (SMS) 487 provides the output of security response / variable pairs 654, which establishes security causality because appropriate corrective actions are coupled with triggering variables such as subject, location, behavioral analysis, etc. Comparable variable format 547 is represented by non-graphical terms 655. Each of these perception sets contains various types of perceptions with specific weighted effects used to form CVF 547.
[0408] Figure 103 The logic flow of a comparable variable format generator (CVFG) 491 is shown. The input to the CVFG is a data batch 658, which is an arbitrary set of data that must be represented by the nodes of the generated CVF 547. Stage 659 performs sequential progression by each of the individual units defined by the data batch 658. At stage 660, the data units are transformed into a node format, which has the same informational components as referenced in the final CVF 547. Nodes are the building blocks of the CVF and allow for efficient and accurate comparative evaluation of other CVFs. CVFs are similar to irreversible MD5 hash sums, but with the comparison-optimized properties (nodes). These transformed nodes are then temporarily stored in node holding 661 while the existence of these nodes is checked in stage 665. If they are not found, they are created in stage 662 and updated with statistics such as occurrence rate and usage in stage 663. In stage 664, all nodes with holding 661 are assembled and pushed as modular output to CVF 547. If the generator runs and keeps 661 empty, it returns a zero result 618.
[0409] exist Figure 104 In the algorithm, Node Comparison (NCA) 667 compares two nodes read from the original CVF 547, forming 666 and 668. Each node in the CVF represents the magnitude of a property. Similarity comparisons are performed on an individual node basis, and aggregated variance is calculated. This ensures accurate comparisons for efficient computation. Smaller variance numbers (whether node-specific or aggregated weights) indicate closer matches. Two comparison modes exist that can occur: Partial Matching Mode (PMM) and Whole Matching Mode (WMM). For PMM, if an active node exists in a CVF and is not found in its comparison candidates (the node is latent), the comparison is not penalized. Example of mode applicability: When comparing tree A with forest A, tree A will find its closest matching tree B existing within forest A. For WMM, if an active node exists in a CVF and is not found in its comparison candidates (the node is latent), the comparison is penalized. Example of pattern applicability: When comparing tree A with forest A, no match will be found because tree A and forest A are directly compared and have significant variations in overlap and structural similarity.
[0410] Figures 105 to 106The system metadata separation (SMS) 487 is shown, which separates the input system metadata 484 into meaningful security causal relationships. When outputting from the MCM 488, programming elements of the log are retrieved individually at stage 672. At stage 673, various categories from the MCM are used to obtain a more detailed combination of the relationships between security responses and security variables (security logs), and such classification 674 is then assimilated in stages 669, 670, and 671. With subject scanning / assimilation 669, subjects / suspects of security situations are extracted from the system metadata using pre-made category containers and raw analysis from the classification module. Subjects are used as primary reference points for deriving security response / variable relationships. The scope of subjects can range from people, computers, executable code segments, networks, or even enterprises. This parsed subject 682 is stored in subject storage 679. With risk scanning / assimilation 670, risk factors of security situations are extracted from the system metadata using pre-made category containers and raw analysis from the classification module. Risks are associated with target subjects that exhibit or are exposed to such risks. Risks can be defined as potential attack points, types of attack vulnerabilities, etc. Such risks are stored in risk storage device 680 associated with their relevant subjects at subject index 683. With response scanning / assimilation 671, responses to security situations obtained by the input algorithm are extracted from system metadata using pre-made category containers and raw analysis from the classification module. These responses are associated with the security subjects that supposedly deserve such responses. The range of responses can be from approval / blocking / flagging / isolation / obfuscation / signal emulation / punishment, etc. Such responses are stored in response storage device 681 associated with their relevant subjects at subject index 683. This stored information is then processed by filler logic (PL) 483, which comprehensively classifies all security subjects with their associated risks and responses.
[0411] Figures 107 to 108Metadata Classification Module (MCM) 488 is shown. In Format Separation 688, metadata is separated and classified according to rules and syntax for recognizable formats. Such metadata must have been assembled according to a recognizable format; otherwise, the metadata will be rejected. Local Format Rules and Syntax 689 contains definitions that enable the MCM module to recognize pre-formatted metadata streams. Local means the previously selected 'format' due to relevance and presence in the metadata. Debug Trace 485 is a code-level trace that provides the variables, functions, methods, and kinds used, as well as their respective input and output variable types / contents. It provides the full function call chain (functions that call other functions). Algorithm Trace 486 is a software-level trace that provides security data combined with algorithm analysis. It provides the resulting security decision (approval / blocking) along with a trace of how it was achieved (justification), and the appropriate weight of each factor in making that security decision. At stage 686, this algorithm trace 486 causes the MCM to iterate through patterns of each of these security decision justifications. Such justifications define how and why a certain security response should be made using computer log syntax (rather than being written directly by humans). Recognizable Format 687 is a pre-defined and standardized syntax format compatible with CMTP. Therefore, if the format declaration from the input system metadata 484 is not recognized, a modular zero result 618 is returned. Programmers of SPMA 526 are obligated to encode the metadata 484 in a standardized format recognizable by CTMP. Such formats do not need to be proprietary and exclusive to CTMP, such as JSON and XML. Variable Preservation 684 is where variables are processed and categorized and preserved 674 so that they can be submitted simultaneously as a final and uniform output 685. Stage 675 performs a comparison check between two main branches of information that serves as input to debug traces 485 and algorithm traces 486. Such comparison tracing presents justifications at the coding level to better understand why such security justifications arise and whether they are worthy of being output by the MCM. This step is preventative to ensure that the reasoning behind each security justification and decision is well understood even at the coding level, further validating any potential critiques of CTMP as a whole. At phase 676, similar risk evidence is examined for verification using debug trace data. At phase 677, metadata is examined for any functions invoked by SPMA, and these applicable functions are subsequently examined to see if their functional purpose and the justification for their use are defined in accordance with the specification of Recognizable Format 687.
[0412] Figure 109The diagram illustrates Measurement Processing (MP) 489, which reverse-engineers variables from the security response of a selected pattern matching algorithm (SPMA) 526 into a 'rescue' perception of intelligence derived from such an algorithm. Security Response X 690 represents a set of factors that contribute to the security response (i.e., approval / blocking / confusion, etc.) produced by the outcome selected by SPMA. Each shape represents a security response from the selected pattern matching algorithm (SPMA). Initial weights are determined by SPMA, thus its intelligence is utilized. Such decisions are then extensively referenced to model the perception. Perception Inference (PD) 490 uses a portion of the security response and its corresponding system metadata to replicate the original perception of the security response. The perception interpretation of dimension series 699 shows how PD will adopt the security response of SPMA and correlate it with the relevant input system metadata 484 to recreate the full range of intelligent 'digital perception' initially used by SPMA. This gives CTMP a deep understanding of the input algorithms and allows for the reuse and cross-referencing of intelligence from multiple algorithms and variable algorithms, thus achieving a significant milestone in artificial intelligence. Such shapes are symbolic representations of the complex rules, behaviors, and correlations implemented by SPMA. Shapefill 697, stacking amount 698, and dimension 699 are digital perceptions that capture the “perspective” of intelligent algorithms. The perception of dimension 699 represents a three-dimensional shape, which can be a symbolic representation used in language learning algorithms to decipher internal emails of company employees and attempt to detect and / or predict security vulnerabilities in sensitive company information. While the dimension type may be a single intelligent algorithm with minor variations (i.e., variation 694C is circular, while 695C / 696C are rectangular, representing subtle differences in the intelligent algorithm), there may be multiple initial security responses that might not be exhibited at the face value by such an algorithm. At face value 694A, it appears to have more in common with 692A than with 696A. Despite this counterintuitive point, 692A is a security response performed by the algorithm Shapefill 697, which is completely different from dimension 699. While perceptions 695C and 696C are identical, their security responses correspond to subtle differences between 695A and 696A. Security response 695A is darker and represents dimensional perception from side 695B, while 696A represents the exact same perception, albeit from front 696B. These differences illustrate how different security responses to different security threats / suspicions can be reverse engineered and found to be the same intelligent algorithm. All three instances of dimensional 699 perception (two of which are identical) are combined into a single unit subsequently referenced internally within CTMP as perception angle B 702. The weight of the perception angle's influence within CTMP is calculated based on the initial weights of the security responses 694A, 695A, and 696A used.In the case of stacked quantity perception 698, instead of receiving the third dimension depth by dimension 699, security response 693A is found to be part of a set of multiple quantities. This could be a symbolic representation of a profiled algorithm that builds a security profile on a new company employee to avoid external penetration. While CTMP initially only receives a single security profile represented as security response 693A, it is actually part of a set of mutually referencing profiles known as (after reverse engineering by MP 489) perceiving stacked quantity 698. Such perception can be referenced in CTMP as perception angle A 701, providing MP 489 with a security response 701 symbolically represented as an incomplete shape for security responses 691A and 692A. PD490 uses input system metadata to discover the origin of this security response, and the intelligent algorithm is looking for the absence of expected security variables. For example, this could be an algorithm that notices the absence of a rule / expected behavior rather than the presence of suspicious behavior. This could be a company employee who did not sign in an email as usual. This could indicate a sudden change in habits or that the employee's email account has been compromised by a malicious actor who is not yet accustomed to signing emails like a genuine employee. The algorithm was reverse-engineered to a digitally perceptual shapefill 697, which can be referenced within CTMP as a perceptual angle C700 with appropriate influence weights.
[0413] Figure 110 and 111The internal design of Perceptual Deduction (PD) 490 is shown, which is primarily used by Measurement Processing (MP) 489. The security response X is forwarded as input to Justification / Reasoning Calculation 704. This module determines the justification for the security response of the SPMA by utilizing the intent supply from the Input / Output Reduction (IOR) module 706, such as that stored in the Intent DB 705. Such an IOR module interprets the input / output relationships of the function to determine the justification and intent for the function's purpose. The IOR module uses the separated inputs and outputs of various function calls listed in the metadata. This metadata separation is performed by the Metadata Classification Module (MCM) 488, where output categories appear as sets 672 and 674. In JRC 704, the functional intents stored in the Intent DB 705 are examined against the security response provided as input 690. If the functional intents confirm the security decision of the SPMA, they are submitted as valid justifications for the Measurement Transformation JMC 703. In the JMC module, the verified justifications for the security response are converted into a metric that defines the perceived characteristic. The measurement is analogous to human senses, and the justification for a safe response indicates the justification for using that sense. When a person crosses a road, their senses (or measurements) of sight and sound are heightened, while their senses of smell and touch are latent. This set of senses, along with their respective intensity values, represents the perception of 'crossing the road'. The justification for this analogy would be 'vehicles on the road can be dangerous, and you can see and hear them'. Thus, the rationale for the perception is justified, forming the example perception angle C 543. I / O (input / output) relationships are defined as a single set of functional inputs and corresponding outputs provided by such a function. IOR 706 first checks whether the function's I / O relationships and the function's 'intent' have been previously analyzed by referring to an internal database. If information is found in the database, it is used as a supplement to the current I / O data at stage 708. The supplemented (if applicable) I / O data is then checked to ensure it is sufficiently saturated to reach a sufficiently meaningful level of analysis at stage 714. This quantity is quantified in technical terms, and the minimum level is limited by a pre-existing CTMP strategy. If there is insufficient I / O information for analysis, the specific function analysis is cancelled at stage 711 and IOR module 706 proceeds to the next available function. When the I / O relationship is sufficient for analysis, it is categorized based on similarity 709. For example, one I / O relationship is found to convert one currency to another (i.e., USD to EUR), while another I / O relationship is found to convert one unit of weight to another (i.e., pounds to kilograms). These two I / O relationships are categorized as data conversions because the triggering concept is associated with a classification index. For example, such an index could reference USD, EUR, and pounds, kilograms to refer to the data conversion category.Therefore, once these units are found in the I / O relationships, IOR 706 is able to correctly classify them. Thus, the intent of the function is suspected to be a currency and unit conversion function. When classifying all available I / O relationships, these categories are ordered according to the number of I / O relationship weights they contain at stage 710, with the most popular appearing first. At stage 715, if the categories of the I / O data can reliably show a pattern of the function's intent, they are examined. This is done by checking the consistency of the input-to-output conversions performed by the function. If a certain information category is persistent and distinct (such as converting currency to one category and units to another), then these categories become those describing the function's 'intent'. Therefore, the function will be described as having the intent to convert currencies and units. Reducing this function to its intended purpose through IOR 706 has important security analysis implications, as CTMP can verify the actual purpose of the function present in the code and can intelligently scan for malicious behavior before any damage has been caused by the execution of such code. If IOR 706 has a good understanding of the 'intent' with sufficient confidence, it is submitted as modular output 712. If the 'intent' categories do not strongly confirm each other, and the 'intent' of the function is not confidently established, the 'intent' of the function is declared as unknown and IOR 706 proceeds to the next available function for analysis at stage 711.
[0414] Figures 112-115The Perceptual Observer Simulator (POE) 475 is displayed. This module generates a simulation of the observer and tests / compares all potential perceptual points under these variations in the observer simulation. The input is all potential perceptual points plus an enhanced data log; the output is a safety decision derived from this enhanced log based on the combined results of the best, most relevant, and most cautious observer utilizing the selected perceptual points. The input system metadata 484 is the initial input used by the Original Perceptual Generation (RP2) 465 to generate perceptual points in a comparable variable format CVF 547. With Storage Search (SS) 480, the CVFs derived from the data augmentation log are used as criteria in the database lookup of Perceptual Storage (PS) 478. PS provides the highest-matching CVFs 547 from all available CVFs 547 from the database. Their relevant perceptual composition and weights are referenced and used in the successful match events in the results 716. Similarity overlap is proposed as 60% match 719 and 30% match 720. These results are calculated by Storage Search 480. With result 716, matches 719 and 720 are stored and then individual perception ranking is calculated at weight calculation 718. This calculation takes the overall similarity (or matching) value of the database CVF compared to the input CVF and multiplies this value by the weight of each individual perception. These weights are stored and associated with the CVF, as initially determined by the metric processing (MP) 489. In ranking 717, perceptions are ranked according to their final weights. This ranking is part of the selection process that uses the most relevant perceptions (as weighted in weight calculation 718) to understand the security situation and thus output the final block 730 or approval 731 command. Once the perceptions have been ranked, they are forwarded to application 729, where data augmentation log 723 is applied to the perceptions to generate block / approval recommendations. Log 723 is the system's input log with the original security events. Self-critical knowledge density (SCKD) 492 labels the log to limit the expected upper limit range of unknown knowledge. This means that perceptions can take into account data labeled with unknown data ranges. This means that perception can perform a more accurate assessment of security incidents, taking into account how much it knows and how much it doesn't. Data parsing 724 performs a basic interpretation of the data-enhanced logs 723 and input system metadata 484 to output an original approval or blocking decision 725, as determined by the original Selected Pattern Matching (SPMA) algorithm 526. Therefore, there are two potential case scenarios: either SPMA or the selected scenario 727 (block 730) for security-related events (i.e., preventing program downloads), or the selected scenario 726 (block 731) for such events. At this point, CTMP 22 has made progress to date and is ready to perform its core and most critical task: critical decision-making (including but not limited to cybersecurity).The critique occurs twice within the CTMP in two distinct ways: once in the Perception Observer Emulator (POE) based on perception, and once in the Rule Execution (RE) based on logically defined rules, where it participates in the coverage logic of 732 when a block command is received from the SPMA. At stage 732A, the default action of block 730 is assumed, and the blocking average (BLOCK-AVG) and approval average (APPROVE-AVE) 732B are calculated by finding the average of the blocking / approval confidence values stored in case scenario 727. Stage 732C checks whether the average confidence of case scenario 727 is greater than a predefined confidence margin (by the policy). If the scenario's confidence is low, this indicates that the CTMP rejects the critique due to insufficient information / understanding. In the event of such a low-confidence situation, the RMA feedback module 728 participates at stage 732D to attempt to re-evaluate the security scenario by including more perception. This additional consideration of perception may increase the confidence margin. Therefore, the RMA feedback will communicate with Resource Management and Allocation (RMA) 479 itself to check whether a reassessment is permitted according to the resource management policy. If such a reassessment is rejected, the algorithm has reached its peak confidence potential, and the initial approval / blocking decision is permanently suspended for this PoE session. Phase 732E instructs the RMA feedback module 728 to receive permission from RMA 479 to reallocate more resources and therefore more senses to the computation. In this situation, the rewrite attempt (CTMP critique) is suspended at phase 732F to allow a new evaluation of case scenario 727 with additional senses (and therefore increased computer resource load). Phase 732G instructs the approval average to have sufficient confidence (according to the policy) to override the default blocking action 730 / 732A to the approval action 731 at phase 732H. The same logic applies to the approval logic 733 that occurs at case scenario 726. At phase 733A, the default action is set to approve as requested by SPMA 526. The blocking average and approval average 733B are calculated by finding the average blocking / approval confidence values for the size in case scenario 726. Stage 733C checks whether the average confidence of case scenario 726 is greater than a predefined confidence margin (by the policy). When such a confidence condition increases, the RMA feedback module 728 intervenes at stage 733D to attempt a reassessment of the security situation, which includes more awareness. Stage 733E instructs the RMA feedback module 728 to receive permission from RMA 479 to reallocate more resources and therefore more awareness to computation. In this situation, the rewrite attempt (CTMP critique) is aborted at stage 733F to allow a new evaluation of case scenario 726 with additional awareness (and therefore increased computer resource load).Phase 733G indicates that the average approval is confident (according to the strategy) that the default approval action 731 / 733A will override the blocking action 730 at phase 733H.
[0415] Figure 116 and 117 The implicit derivation (ID) 477 is shown, which derives the angles of the perception data that may be implicit from the currently known perception angles. The applied perception angle 470 is the range of known perceptions stored in the CTMP storage system. This type of perception 470 has been applied and used by SPMA 526 and is collected as a set of perceptions 734 and forwarded to metric combination 493. The module 493 converts the angles in the format of perceptions 734 into metric categories in the format identified by the implicit derivation (ID) 477. In the case of metric complexity 736, the outer edge of the circle represents the peak of known knowledge about individual metrics. Therefore, the outer edge of the circle represents more metric complexity, while the center represents less metric complexity. The light gray center represents the current batch of metric combinations of the applied perception angles, and the dark gray outer edge represents the metric complexity that is generally stored and known by the system. The goal of ID 477 is to increase the complexity of the associated metrics so that the perception angles can be multiplied in terms of complexity and quantity. In cases where the known metric complexity from the current batch does not yet contain such details / complexity, it is added to the associated metric DB 738. Thus, the system has become a complete circle, and the newly stored metric complexity can be used to implicitly derive a batch of potential future perceptual angles. This complex metric composition 736 is passed as input to metric extension (Me) 495, where multiple metrics and different perceptual angles are stored categorically in individual databases 738. The dark gray surface area represents the total range of the current batch of applied perceptual angles, and the number of ranges remaining exceeds a known upper bound. The upper bound is represented by the peak knowledge of each individual metric DB. Therefore, the previously known details / complexities of those metrics are used to augment the metrics of the current batch (which have already been derived from the perceptual angles of the current batch). The metric is returned as perceptual complexity 737 when augmentation and complexity are rich. As seen in graph 737, the light gray area has become larger than in all four sectors of metric range 739, consistency 740, type 741, and intensity 742. This indicates that it has become more detailed and complex in all four metric sectors. This augmented metric complexity 737 is then passed as input to metric transformation 494, which reverses the individual to the entire perceptual angle 735. Therefore, the final output is assembled into the implicit angle 471 of perception, which is an extended version of the original input of perception applied to angle 470.
[0416] Figures 118-120The self-critical knowledge density (SCKD) 492 is shown, which estimates the range and types of potential unknown knowledge that cannot be obtained from reportable logs. Thus, the subsequent critical thinking features of CTMP 22 can utilize the potential range of all involved knowledge, both known and unknown, within the system. Below is an example use case demonstrating the intended functionality and capabilities of SCKD 492:
[0417] 1) This system has established a strong reference range for nuclear physics.
[0418] 2) The system has performed nuclear physics and quantum physics in categories that are clearly and systematically similar in complexity and type.
[0419] 3) However, compared to nuclear physics, this system has far less reference knowledge in quantum physics.
[0420] 4) Therefore, this system limits the upper bound of potentially attainable quantum physical knowledge through an analogy with nuclear physics.
[0421] 5) This system defines the scope of unknown knowledge in the context of quantum physics.
[0422] Known Data Classification (KDC) 743 separates the confirmed (known) information from the input 746 by category so that an appropriate DB analogy query can be performed. This information is separated into categories A, B, and C 750, after which the separated categories are individually fed into a Comparable Variable Format Generator (CVFG) 491. The CVFG then outputs the classification information in CVF 547 format, which is used by Storage Search (SS) 480 to check the similarity within the known data range DB 747. In the case of DB 747, the upper bound of the known data is constrained based on the data category. Comparisons are made between similar types and structures of the data to estimate the confidence of the knowledge range. If SS 480 cannot find any results for knowledge analogy at scenario 748, the current data is stored so that future analogies can be made. According to the use case example, this would be an event that allows the scope of nuclear physics to be defined. Then, when referencing quantum physics in the future, its knowledge range can be compared with the current storage of the nuclear physics knowledge range. Scenario 749 describes the results of the scenario discovery, where, based on the results of SS 480, each category is labeled with its relevant range of known data. Subsequently, at the Unknown Data Combiner (UDC) 744, the labeled ranges of unknown information for each category are reassembled back into the same original data stream (input 746). At output 745, the original input data is returned and combined with the unknown data range definition. Figure 119The Known Data Classification (KDC) module 743 is illustrated in more detail below. Known data 752 is the main input and contains information blocks 755, which represent defined ranges of data, such as individual entries from an error log. Stage 756 examines the identifiable definitions within the blocks, which will show that it is labeled as nuclear physics information based on the use case. If a category exists that fits the information label of the block in category reservation 750, it is augmented with details at stage 748 by supplementing it with processed information blocks 755. If no such category exists, it is created at stage 749 so that information blocks 755 can be stored appropriately and correctly. Basic logic 759 sequentially loops through these blocks essentially until all of them have been processed. After all of them have been processed, if no minimum number (defined by the strategy) is submitted to category reservation 750, then KDC 743 submits the modularized output as a zero result 618. If a sufficient number of processed blocks exist, category reservation 750 is submitted to intermediate algorithm 751 (which is primarily SCKD 492). The Unknown Data Combiner (UDC) 744 receives known data that has been labeled with unknown data points 757 from the intermediate algorithm 751. This data is initially stored in the category hold 750, and the basic logic 760 sequentially cycles through all data units from there. Stage 754 checks whether the categories defined from the hold 750 contain original metadata describing how to reconstruct the individual categories into a matching information flow. This metadata is initially found in the input known data 752 from the KDC 743, because at this stage, the data has not yet been categorized and an initial single matching structure exists to hold all the data. After stage 754 re-associates the metadata with their corresponding data, the labeled blocks are transferred to the block reorganization hold 753. If no matching metadata is found at stage 754, hold 753 will inevitably remain empty and a modular zero result 618 will be returned. Upon successful metadata matching, hold 753 is populated and the modular output for UDC 744 is known data + labeled unknown data 757. Block 755 in the modular output represents the original information block found in known data 752 from KDC 743. Pentagon 758 represents the definition of the unknown data range, which is coupled to each block of known data 755.
[0423] Lexical objectivity mining (LOM)
[0424] Figure 121This illustrates the main logic used for Lexical Objectivity Mining (LOM). LOM attempts to approach objective answers to a wide range of questions and / or assertions as closely as possible. It engages human subjects 800 to allow them to acknowledge or refine their arguments against LOM. Acknowledging or refining arguments is a core philosophy of LOM, as it must be able to acknowledge its errors, allowing it to learn from human knowledge (where it initially acquired its knowledge). LOM is an extremely large database (and therefore CPU, RAM, and disk are all key players) and will benefit from a central Knowledge Retention (CKR) 806 centralized in a single (but replicated for redundancy and backup) master instance. Third-party applications can be facilitated via paid or free APIs connecting to such a central master instance. LOM activity begins with human subjects 800 entering the main LOM visual interface with assertion questions or assertions 801. Such a question / assertion 801A is transferred to Initial Query Reasoning (IQR) 802 for processing, which utilizes Central Knowledge Retention (CKR) 806 to decipher key missing details in the process of understanding and answering / responding to the question / assertion [...]. Subsequently, the question / assertion 801, along with supplementary query data, is transferred to Investigation Clarification (SC) 803A, which engages the human subject 800 to obtain supplementary information, allowing the question / assertion 801A to be analyzed objectively and using all necessary context. Thus, a clarified question / assertion 801B is formed, which takes the original question / assertion 801 as posed by the human subject 800 but supplements details learned from 800 via SC 803A. Assertion Construction (AC) 808A receives propositions in the form of assertions or questions (such as 801B) and provides outputs of concepts associated with such propositions. Response Presentation 809 is an interface for presenting the conclusions drawn from LOM (specifically AC 808) to both Human Subject 800 and Rational Appeal (RA) 811; it presents the conclusions drawn from LOM (especially AC 808) to both Human Subject 800 and Rational Appeal (RA) 811. This interface is presented visually to Human 800 and in a purely numerical syntax format to RA 811. Hierarchical Mapping (HM) 807A maps related concepts to identify confirmations or conflicts in the consistency of issues / assertions. It then calculates the benefits and risks of taking a certain position on that subject. Central Knowledge Retention 806 is a primary database for referencing knowledge against LOM. Query efficiency and the logical classification and separation of concepts are optimized, enabling the construction of strong arguments and defenses in response to critique from Human Subject 800. Knowledge Verification (KV) 805A receives high-confidence and pre-critiqued knowledge that needs to be logically separated for query capabilities and assimilation in CKR 806. Accepting the response 810 is to give the human subject 800 a choice to either accept the response of LOM or to appeal with criticism.If the response is accepted, it is processed by KV805A to store it as confirmed (high-confidence) knowledge in CKR 806. If the human subject 800 does not accept the response, it is forwarded to the Reason Appeal (RA) 811A, which examines and critiques the reasons given by the human subject 800. RA 811A can critique statements, whether self-criticism or critique of the human response (from the 'no' response at the accepted response 910).
[0425] Figures 122-124 The diagram illustrates a managed Artificial Intelligence Service Provider (MAISP) 804A. MAISP runs an Internet of Things (LOM) instance with a master instance of a Central Knowledge Retention (CKR) 806. MAISP 804A connects the LOM to front-end services 861A, back-end services 861B, third-party application dependencies 804C, information sources 804B, and the MNSP 9 cloud. Front-end services 861A include AI personal assistants (e.g., Apple's Siri, Microsoft's Cortana, Amazon's Alexa, Google Assistant), communication applications and protocols (i.e., Skype, WhatsApp), home automation (i.e., refrigerators, garages, doors, thermostats), and medical applications (e.g., alternative doctor's opinions, medical history). Back-end services 861B include online shopping (e.g., Amazon.com), online delivery (e.g., Uber), medical prescription ordering (e.g., CVS), and more. These front-end 861A and back-end 861B services interact with the LOM via a documented API infrastructure 804F, which standardizes information delivery and protocols. LOM retrieves knowledge from external information sources 804B via the Automated Research Mechanism (ARM) 805B.
[0426] Figures 125-128The dependency structure of the LOM is illustrated, indicating how modules depend on each other. Language Construction (LC) 812A interprets the original question / assertion input from the human subject 800 and parallel modules to produce a logical separation of the language syntax that can be understood by the LOM system as a whole. Concept Discovery (CD) 813A receives points of interest within the clarified question / assertion 804 and derives related concepts using CKR 806. Concept Prioritization (CP) 814A receives relevant concepts and ranks them in logical layers representing specificity and generality. The top layer is assigned the most general concepts, while lower layers are assigned increasingly specific concepts. Response Separation Logic (RSL) 815A utilizes LC 812A to understand human responses and associates relevant and valid responses with the initial clarification request, thus achieving the goal of SC 803A. LC 812A is then reused during the output phase to modify the original question / assertion 801 to include supplementary information received by SC 803. The Human Interface Module (HIM) 816A provides clear and logically separate hints to the human subject 800 to address the knowledge gaps specified by the Initial Query Reasoning (IQR) 802A. Context Construction (CC) 817A uses metadata from the Assertion Construction (AC) 808A and latent evidence from the human subject 800 to present the original facts to the CTMP for critical thinking. Decision Comparison (DC) 818A identifies the overlap between pre-criticism and post-criticism decisions. Concept Compatibility Detection (CCD) 819A compares conceptual derivations from the original question / assertion 801 to determine logical compatibility results. Such concepts can represent situations, states of being, obligations, etc. The Benefit / Risk Calculator (BRC) 820A receives the compatibility results from CCD 819A and weighs benefits and risks to form a unified decision that includes a gradient of variables implicit in the conceptual construction. Concept Interaction (CI) 821A assigns attributes related to the concept of AC 808A to various parts of the information collected from the human subject 800 via Investigation Clarification (SC) 803A.
[0427] Figure 129 and 130The internal logic of Initial Query Reasoning (IQR) 802A is shown. Language Construction (LC) 812A, a subset of IQR 802, receives the initial question / assertion 801 from human subject 800. 801 is linguistically separated so that IQR 802A processes each individual word / phrase sequentially. The auxiliary verb “should” 822 suggests a lack of clarity regarding the time dimension 822. Therefore, rhetorical questions are formed to achieve clarity such as ‘daily?’, ‘weekly?’, etc. The subject ‘I’ 823 suggests a lack of clarity regarding who the subject is, thus the follow-up question verb ‘eat’ 824, to be presented to human subject 800, is not necessarily unclear but can supplement other analytical points lacking clarity. IQR 802 links the concept of food with the concepts of health and money in stage 824 by utilizing CKR 806DB. This informs the query ‘subject asks a question’ 823, making more appropriate and relevant follow-up questions such as ‘male or female?’, ‘diabetes?’, etc. 'Exercise?' 'Purchasing power?' The noun 'fast food' 825 suggests a lack of clarity in how the word should be interpreted. In a technical sense 827, it can be interpreted as its most primitive form of 'food served very quickly,' or a more colloquial understanding of 'deep-fried savory food' that is cheap and made very quickly at a place of order. A salad bar is technically a means of obtaining food quickly because it is pre-made and readily available. However, this technical definition does not align with the colloquial understanding of the more general meaning of 'fast food.' By referring to CKR 806, IQR 802 takes into account the potential options that may be considered in the process of considering the ambiguity of the term 'fast food.' Ambiguous options such as 'burger joint?' and 'salad bar?' can be forwarded to human subject 800 via the Human Interface Module (HIM) 816. However, there may be sufficient information at CKR 806 to understand that the general context of question 801 indicates a reference to the colloquial meaning 826. CKR 806, having gradually come to understand the degree of controversy surrounding fast food and health, is able to articulate this general context. Therefore, it is highly likely that Question 801 refers to this controversy, and thus HIM 816 does not need to be raised to further clarify Human Subject 800. Therefore, IQR 802 attempts to decipher the obvious yet subtle nuances in the definitional sense. Question 828 indicates to the entire LOM that Human Subject 800 is posing a question, not making an assertion.
[0428] Figure 131The Investigation Clarification (SC) 803 is shown, which receives input from the IQR 802. This input contains a series of requested clarifications 830 that must be answered by the human subject 800 in response to an objective answer to the original question / assertion 801. Therefore, the requested clarifications 830 are forwarded to the Human Interface Module (HIM) 816B. Any response provided to such clarifications is forwarded to the Response Separation Logic (RSL) 815A, which then associates the response with the clarification request. In parallel with the processing of the requested clarifications 830, a clarification language association 829 is provided to the Language Construction (LC) 812A. This association 829 contains the internal relationship between the requested clarifications 830 and the language construction, which in turn allows the RSL 815A to modify the original question / assertion 801 so that the LC 812A can output a clarified question 804, which has incorporated the information learned via 816.
[0429] Figure 132 The assertion construction (AC) 808 is shown, which receives the clarified question / assertion 804 generated by the investigation clarification (SC) 803. The LC 812A then decomposes the question into points of interest 834 (key concepts), which are passed to the concept discovery (CD) 813. The CD then derives related concepts 832 by utilizing the CKR 806. Concept prioritization (CP) 814A then sorts the concepts 832 into logical layers representing specificity and generality. The top layer is designated as the most general concepts, while lower layers are assigned increasingly specific concepts. This sorting is facilitated using data provided by the CKR 806. This top layer is transferred as modular input to the hierarchy map (HM) 807. In the parallel transfer of information in the HM 807, the HM 807 receives the points of interest 834, which are processed by their dependent module concept interaction (CI) 821. The CI assigns attributes to such points of interest 834 by accessing index information at the CKR 806. While HM 807 completes its internal process, its final output is returned to AC 808 after the derived concept has undergone compatibility testing, and the benefits / risks of the situation are weighted and returned. This is called the modular output feedback loop 833, because AC 808 and HM 807 have reached a full circle and continue to send modular outputs to each other until the analysis has fully saturated the concept complexity, and until CKR 806 becomes a bottleneck due to knowledge limitations (whichever comes first).
[0430] Figure 133 and 134 This illustrates the internal details of how the Hierarchical Mapping (HM) 807 works. The AC 808 provides two types of input to the HM 807 in parallel. One is called the concept interest point 834, and the other is the top-level (most general) priority concept 837. (As shown in...) Figure 128As shown, Conceptual Interaction (CI) 821 uses these two inputs to associate contextualized conclusions with points of interest 834. CI 821 then provides input to Conceptual Compatibility Detection (CCD), which identifies the level of compatibility / conflict between two concepts. This provides HM 807 with a general understanding of consistency and inconsistency between the assertions and / or propositions of human subject 800 and the high-confidence knowledge indexed in Central Knowledge Retention (CKR) 806. Such compatibility / conflict data is forwarded to Benefit / Risk Calculator (BRC) 820 (a module that translates these compatibility and conflict into benefits and risks for taking an overall consistent stance on the issue). For example, depending on the use case (based on the criteria set by human subject 800), three main stances will emerge: fast food is generally not recommended, fast food is permissible but not emphasized, or fast food is generally recommended. These stances, along with their risk / benefit factors, are forwarded to AC 808 as module output 836. This is one of several points where the information flow within the LOM becomes a complete loop, as the AC 808 will attempt to facilitate the expansion of assertions forwarded by the HM 807. The system contains an information flow loop that indicates an intelligent gradient that is progressively supplemented as an objective response to the subjective nature of the question / assertion.
[0431] One analogy is how bees find nectar from flowers, inadvertently collecting their pollen and spreading it to other flowers. This fertilization of the flower produces more flowers, which in the long run attracts more bees. This is similar to the interconnected information ecosystems that emerge within LOM (Lesson on Earth) to gradually 'pollinate' assertions and maturing concepts until the system achieves strong confidence in its stance on the topic. Figure 128 The above shows the internal workings of Concept Interaction (CI) as a subset of HM 807. CI 821 receives points of interest 834 and interprets each point of interest based on the top-level prioritized concepts 837. In this example, the two top-level prioritized concepts are 'health' and 'budget constraint' 837. Therefore, when CI attempts to interpret point of interest 834, it interprets it through the perspective of these topics. Point of interest 'diabetes' 838 ...
Claims
1. An artificial intelligence-based computer security system, wherein the computer security system has: a memory; a processor coupled to the memory, wherein the computer security system includes critical infrastructure protection and punishment of CIPR through cloud & layered information security (CTIS), further comprising: a) Trusted platforms, including networks of spies that report hacking activities; b) Managed network and security service provider MNSP, which provides managed cryptographic security, connectivity and compliance solutions and services; The Virtual Private Network (VPN) connects the MNSP and the Trusted Platform. The VPN provides a communication channel with the Trusted Platform, and the MNSP is adapted to analyze all services within the enterprise network, which are then routed to the MSNP. The MNSP includes: a) LIZARD, a real-time defense based on logical inference zero database, derives its purpose and function from foreign code and thus blocks it in the presence of malicious intent or the absence of legitimate reasons, and analyzes the threats contained therein and in themselves without reference to prior historical data; b) Human-caused security threats (AST), which provide hypothetical security scenarios for testing the effectiveness of a set of security rules; c) The creative module, which performs the process of intelligently creating new hybrid forms beyond a priori forms; d) Conspiracy detection identifies patterns of information collaboration and security-related behaviors, provides routine background checks for multiple conspiracy security incidents, and attempts to determine patterns and correlations between seemingly unrelated security incidents; e) Security behaviors, their stored events, and their security responses and characteristics, and indexing them, where the response includes blocking / approval decisions; f) Iterative intelligent growth / intelligent evolution 2 GE utilizes big data and malware signature identification, and simulates potential future changes in malware by leveraging AST and creative modules; and g) Critical thinking, memory, and perception CTMP, whose critical thinking prevents / approves decision-making and acts as a supplementary layer of security, and utilizes I 2 Cross-reference intelligence from GE, LIZARD, and trusted platforms, where CTMP estimates its own ability to form objective decisions about matters and will avoid maintaining decisions made in situations of low internal confidence.
2. The system of claim 1, wherein the LIZARD Lite client is adapted to operate in devices on an enterprise network and to securely communicate with LIZARD in the MNSP.
3. The system of claim 1 further includes a demilitarized zone (DMZ) comprising a subnetwork containing an HTTP server with higher security responsibilities than a normal computer, so that the remainder of the enterprise network does not assume such security responsibilities.
4. The system according to claim 1, wherein I 2 GE involves iterative evolution, in which parallel evolutionary paths mature and are selected, iterative generations are applicable to the same human security threat AST, and the path with the best personality traits is ultimately the most resistant to security threats.
5. The system of claim 1, wherein the LIZARD comprises: a) The syntax module provides a framework for reading and writing computer code; b) The purpose module, which uses the syntax module to derive the purpose from the code and outputs the purpose in its complex purpose format; c) Virtual obfuscation, in which the enterprise network and database are cloned in a virtual environment and sensitive data is replaced with fake (false) data, where the environment can be dynamically changed in real time to include more fake elements or more real elements of the entire system, depending on the target’s behavior. d) Signal simulation, which provides a form of penalty when a virtual confusion analysis conclusion has been reached; e) Internal consistency check, which examines all internal functions containing meaningful external code; f) Foreign code rewriting, which uses syntax modules and target modules to reduce foreign code to a complex target format; g) Hidden code detection, which detects code hidden in data and transmission packets; h) Mapping matching is required, which is a hierarchy of mappings of needs and purposes and is referenced to determine whether foreign code fits the overall goals of the system; For writing, the syntax module receives complex-formatted targets from the target module, then writes code using arbitrary code syntax, and then the help function translates the arbitrary code into actual executable code; For reading, the syntax module provides the target module with a syntactic interpretation of the code so as to derive the purpose of such code; The signal simulation uses a syntax module to understand the communication syntax between the malware and its hacker, and then hijacks such communication to give the malware the false impression that it has successfully sent sensitive data back to the hacker, while the hacker also sends the malware's error code through LIZARD, making it appear as if it came from the malware. Foreign code rewriting uses the exported purpose to build the code set, thereby ensuring that only the expected and understood purpose of the foreign code is executed within the enterprise, and that no unintended function execution can gain access to the system.
6. The system of claim 5, wherein, in order to enable the rewriting of foreign code to syntactically reproduce the foreign code to mitigate potential undetected malicious exploitation, the composition method compares and matches the declared purpose with the derived purpose, wherein the purpose module is used to operate on complex purpose formats, wherein, in the case of derived purpose, the mapping match needs to maintain the hierarchy to maintain jurisdiction over all enterprise needs, so that the purpose of the code block is defined and proven reasonable, depending on the gaps in the need mapping oriented by jurisdiction, wherein the input purpose is the introduction of a recursive debugging process.
7. The system of claim 6, wherein the recursive debugging loop tests for errors and applies error fixes through code segments, wherein if an error persists, the entire code segment is replaced with the original foreign code segment, wherein the original code segment is subsequently tagged for virtual obfuscation and behavioral analysis, wherein in the case of foreign code, the original state of the code is interpreted by the target module and syntax module for code rewriting, wherein in the case where the original foreign code segment needs to be installed because of a permanent error in the rewritten version, the foreign code is directly referenced by the debugger, wherein at the rewritten code location, the segment is tested by the virtual runtime environment to check for coding errors, wherein the virtual runtime environment executes the code segment and checks for runtime errors, wherein in the case of coding errors, the errors generated in the virtual runtime environment are defined in scope and type, wherein in the case of target alignment, potential solutions to coding errors are formulated by re-deriving code from the stated target, wherein the scope of the coding error is rewritten in an alternative format to avoid such errors, wherein potential solutions are output, and wherein if no solution is retained, the code rewriting of that code segment is lost and the original code segment directly from the foreign code is used in the final code set.
8. The system of claim 6, wherein for operations requiring mapping matching, the LIZARD Cloud and LIZARD Lite reference the hierarchical mapping of the enterprise jurisdiction branch, wherein regardless of whether the input purpose is declared or exported via the destination module, the mapping matching verifies the legitimacy of executing code / function within the enterprise system, wherein a master copy of the hierarchical mapping is stored on the LIZARD Cloud in the MNSP, wherein the requirement index within the required mapping matching is calculated by referencing the master copy, wherein the pre-optimized requirement index is distributed across all accessible endpoint clients, wherein the required mapping matching receives the requirement request that is most appropriate for the entire system, and wherein the corresponding output is a complex destination format representing the appropriate requirement.
9. The system of claim 1, wherein the entire LAN infrastructure of the enterprise is substantially reconstructed within the MNSP, wherein a hacker, while performing behavioral analysis on the system, is exposed to elements of both the real LAN infrastructure and the virtual clone version, wherein, If such analysis indicates a risk, then hackers increase their exposure to virtual clone infrastructure in order to reduce the risk of real data and / or devices being compromised.
10. The system of claim 1, wherein a malware root signature is provided to the AST to form an iteration / variant of the malware root signature, wherein a polymorphic variant of the malware is provided as a result of I 2 GE's output is then transferred to malware detection.
11. The system of claim 10, wherein malware detection is deployed at all three levels of the computer's composition, including user space, kernel space, and firmware / hardware space, all of which are monitored by Lizard Lite spyware.
Citation Information
Patent Citations
Procurement System
US20130262104A1
System and method for a cloud computing abstraction with self-service portal
US20140278623A1