Action Verification Module for Cyber Intrusion Response
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Intrusion response systems (IRSs) face challenges in selecting appropriate actions to mitigate cyberattacks, as existing approaches either rely on expert knowledge or data-driven methods, which can lead to inappropriate or infeasible actions, especially as systems become more automated and human verification becomes impractical.
Innovation Solution
An intrusion response system with an action verification module that receives proposed mitigating actions, identifies verification tests, performs these tests, calculates a verification score, and determines if it exceeds a predetermined threshold, ensuring that selected actions are feasible and appropriate for the incident, particularly effective when combined with data-driven IRSs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If automated intrusion response systems are used to respond to cyberattacks in real time, then response speed is improved, but the reliability of action selection deteriorates due to inability to verify action appropriateness
Solution Approach 1:
The system performs verification tests on proposed mitigating actions before deploying them. The action verification module identifies relevant verification tests, executes them to obtain verification outcomes, and calculates verification scores to confirm action appropriateness before the action is actually deployed to mitigate the cyber intrusion.
Solution Approach 2:
The system implements a feedback loop where verification outcomes from testing proposed actions are fed back into the action selection process. The verification scores calculated from these outcomes inform whether actions should be deployed, allowing the system to learn and improve its action selection reliability while maintaining automated real-time response capability.
2Reliability
If expert knowledge driven approaches are used for action selection, then action appropriateness is improved, but the adaptability to new attack types deteriorates
Solution Approach 1:
The verification test framework is designed to be universal and applicable to multiple types of cyber intrusions and attack scenarios. Rather than relying on attack-type-specific expert knowledge, the system uses a generalized verification approach that can assess the appropriateness of actions across different intrusion contexts, thereby improving adaptability to new attack types while maintaining action appropriateness through systematic verification.
3Adaptability or versatility
If data driven approaches are used for action selection, then adaptability to various attack scenarios is improved, but the risk of selecting inappropriate actions increases
Solution Approach 1:
The action verification module serves as an intermediary between the data-driven action selection process and actual action deployment. It acts as a mediator that systematically verifies proposed actions through identified verification tests before they are executed, reducing the risk of deploying inappropriate actions while preserving the adaptability benefits of data-driven approaches.
4Measurement precision
If verification tests are performed on all proposed actions, then action verification quality is improved, but the response time deteriorates
Solution Approach 1:
The system performs verification tests selectively rather than on all proposed actions uniformly. The action verification module identifies and executes relevant verification tests based on the specific action and intrusion context, performing only the necessary verification to achieve adequate verification quality without unnecessarily extending response time for every single action.
Data Source
AI summary
An intrusion response system is disclosed and includes an action verification module. The action verification module is configured to receive an identifier associated with at least one proposed mitigating action to perform in response to a detected cyber intrusion and details of the detected cyber intrusion, identify one or more verification tests to be performed, perform each of the one or more verification tests to obtain a respective one or more verification outcomes, calculate a verification score associated with the at least one proposed mitigating action based on the respective one or more verification outcomes, and determine whether the verification score exceeds a predetermined threshold value. Also disclosed is a corresponding method of verifying a proposed mitigating action to perform in response to a detected cyber intrusion.


