Abduction Inference Apparatus for Cybersecurity Evidence Ordering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing abduction methods in cybersecurity struggle to represent numerical relationships, such as temporal relationships between evidence events, which are crucial for determining the relevance and order of events, due to the limitations of logical formulas in handling numerical values and continuous variables.
Innovation Solution
An inference apparatus and method that generate additional logical formulas to express numerical relationships between observation literals, allowing for the inclusion of new literals and rules that reflect these relationships, and apply weighted abduction to prioritize hypotheses based on these relationships.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If logical formulas are used in abduction to represent observation facts and inference rules, then the formal reasoning capability is improved, but the ability to represent numerical relationships deteriorates
Solution Approach 1:
The patent merges logical formulas with numerical expressions by allowing observation literals to contain both logical predicates and numerical terms. The generation unit creates observation logical formulas that combine logical structure with numerical relationships, enabling the abduction process to simultaneously handle formal reasoning and numerical comparisons.
Solution Approach 2:
The patent introduces a new dimension to traditional logical formulas by incorporating numerical expressions as literals within the logical structure. This allows the system to reason about both logical relationships and numerical relationships in a unified framework, extending the capability of abduction beyond pure logical reasoning.
2Device complexity
If traditional abduction methods are used without numerical relationships, then the simplicity of the inference process is maintained, but the accuracy of hypothesis derivation deteriorates
Solution Approach 1:
The patent changes the parameters of observation literals to include numerical expressions that capture temporal and quantitative relationships. By modifying the structure of observation facts to include numerical parameters, the abduction process can prioritize hypotheses based on numerical criteria such as temporal proximity, thereby improving accuracy while maintaining the overall abduction framework.
3Reliability
If numerical relationships are added to observation logical formulas, then the relevance of evidence selection is improved, but the complexity of formula generation increases
Solution Approach 1:
The generation unit performs preliminary action by automatically generating observation logical formulas with numerical relationships before the abduction process begins. This preprocessing step incorporates numerical expressions into observation facts, enabling the abduction unit to directly use these enhanced formulas without requiring complex real-time processing during inference.
Data Source
AI summary
An inference apparatus includes: a generation unit that generates, based on first observation literals included in a first observation logical formula that represents an observation fact using a logical formula, a second observation logical formula including second observation literals expressing a numerical relationship of the first observation literals, and adds the second observation logical formula to the first observation logical formula: and an abduction unit that executes abduction by applying inference knowledge including a plurality of rules that are represented by logical formulas to the first observation logical formula and the second observation logical formula.


