Action Verification Module for Cyber Intrusion Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Intrusion response systems (IRSs) face challenges in selecting appropriate actions to mitigate cyberattacks, as existing approaches either rely on expert knowledge or data-driven methods, which can lead to inappropriate or infeasible actions, especially as systems become more automated and human verification becomes impractical.

Innovation Solution

An intrusion response system with an action verification module that receives proposed mitigating actions, identifies verification tests, performs these tests, calculates a verification score, and determines if it exceeds a predetermined threshold, ensuring that selected actions are feasible and appropriate for the incident, particularly effective when combined with data-driven IRSs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If automated intrusion response systems are used to respond to cyberattacks in real time, then response speed is improved, but the reliability of action selection deteriorates due to inability to verify action appropriateness

Engineering Contradiction:
Improveresponse speedVSAvoidaction selection reliability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system performs verification tests on proposed mitigating actions before deploying them. The action verification module identifies relevant verification tests, executes them to obtain verification outcomes, and calculates verification scores to confirm action appropriateness before the action is actually deployed to mitigate the cyber intrusion.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements a feedback loop where verification outcomes from testing proposed actions are fed back into the action selection process. The verification scores calculated from these outcomes inform whether actions should be deployed, allowing the system to learn and improve its action selection reliability while maintaining automated real-time response capability.

Inventive Principle:
Principle #23Feedback

2Reliability

If expert knowledge driven approaches are used for action selection, then action appropriateness is improved, but the adaptability to new attack types deteriorates

Engineering Contradiction:
Improveaction appropriatenessVSAvoidadaptability to new attack types
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The verification test framework is designed to be universal and applicable to multiple types of cyber intrusions and attack scenarios. Rather than relying on attack-type-specific expert knowledge, the system uses a generalized verification approach that can assess the appropriateness of actions across different intrusion contexts, thereby improving adaptability to new attack types while maintaining action appropriateness through systematic verification.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If data driven approaches are used for action selection, then adaptability to various attack scenarios is improved, but the risk of selecting inappropriate actions increases

Engineering Contradiction:
Improveadaptability to attack scenariosVSAvoidaction appropriateness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The action verification module serves as an intermediary between the data-driven action selection process and actual action deployment. It acts as a mediator that systematically verifies proposed actions through identified verification tests before they are executed, reducing the risk of deploying inappropriate actions while preserving the adaptability benefits of data-driven approaches.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Measurement precision

If verification tests are performed on all proposed actions, then action verification quality is improved, but the response time deteriorates

Engineering Contradiction:
Improveverification qualityVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs verification tests selectively rather than on all proposed actions uniformly. The action verification module identifies and executes relevant verification tests based on the specific action and intrusion context, performing only the necessary verification to achieve adequate verification quality without unnecessarily extending response time for every single action.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20240160736A1Verification method for intrusion response system
Publication Date: 2024.05.16 BRITISH TELECOM PLC
  • US20240160736A1 patent drawing
  • US20240160736A1 patent drawing
  • US20240160736A1 patent drawing

AI summary

An intrusion response system is disclosed and includes an action verification module. The action verification module is configured to receive an identifier associated with at least one proposed mitigating action to perform in response to a detected cyber intrusion and details of the detected cyber intrusion, identify one or more verification tests to be performed, perform each of the one or more verification tests to obtain a respective one or more verification outcomes, calculate a verification score associated with the at least one proposed mitigating action based on the respective one or more verification outcomes, and determine whether the verification score exceeds a predetermined threshold value. Also disclosed is a corresponding method of verifying a proposed mitigating action to perform in response to a detected cyber intrusion.