Adaptive Bot System for Social Engineering Attack Prediction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing approaches for information inference and elicitation in cyber defense heavily rely on Out-Of-Band (OOB) information extraction, resulting in poor accuracy and scalability issues, especially when dealing with social engineering attackers, where cognitive modeling has not been effectively developed for this context.

Innovation Solution

A system comprising a global bot controlling processor unit with a multi-layer network (MLN) for extracting attacker features, an adaptive behavioral game theory (GT) for determining optimal strategies, and a cognitive model (CM) with generative adversarial networks (GANs) to predict attacker behavior and actions, enabling continuous adaptation and disruption of attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If Out-Of-Band (OOB) information extraction is used for information inference and elicitation, then information can be obtained from multiple sources, but accuracy and scalability are poor

Engineering Contradiction:
Improveability to extract information from diverse media sourcesVSAvoidaccuracy of information elicitation
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent introduces cognitive models as intermediary components that mediate between diverse OOB information sources and the information elicitation process. These cognitive models process and interpret information from multiple media sources, transforming raw data into actionable insights while maintaining accuracy. The cognitive models act as intelligent intermediaries that bridge the gap between heterogeneous information sources and the elicitation objectives, resolving the contradiction by enabling both diverse source utilization and high accuracy through sophisticated information processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical information extraction methods with cognitive modeling approaches. Instead of using simple keyword matching or rule-based extraction from OOB sources, the system employs cognitive models that simulate human reasoning and understanding. This substitution enables the system to handle diverse media sources with high accuracy by applying intelligent processing rather than mechanical extraction, thereby resolving the contradiction between versatility and precision.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of manufacture

If traditional information extraction methods are used, then implementation is simple, but scalability with respect to network size is poor

Engineering Contradiction:
Improvesimplicity of implementationVSAvoidscalability to network size
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent segments the information elicitation system into modular components including cognitive models, information extraction modules, and analysis components. Each module can be independently developed, tested, and deployed. This segmentation enables scalable implementation across networks of varying sizes, as modules can be replicated and distributed according to network requirements. The modular architecture maintains implementation simplicity while enabling scalability, resolving the contradiction between ease of deployment and adaptability to different network scales.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent designs universal cognitive models and information extraction components that can function across different network sizes and configurations. The same core modules can be applied whether the network is small or large, maintaining consistency in implementation while adapting to scale. This universality allows the system to be deployed simply in small networks and scaled up to large networks without requiring fundamentally different approaches, thereby resolving the contradiction between simplicity and scalability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If cognitive modeling is applied to cyber defense, then understanding of attacker behavior improves, but it has not been effectively developed for social engineering attackers

Engineering Contradiction:
Improveunderstanding of attacker behaviorVSAvoidapplicability to social engineering attackers
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic cognitive models that can adapt to different attacker types, including social engineering attackers. The models are designed to learn and evolve based on observed attacker behavior, allowing them to effectively model both traditional cyber attackers and social engineering attackers. This dynamic adaptability enables the system to maintain reliable behavioral understanding across different attack vectors, resolving the contradiction between reliability and versatility by making the cognitive models flexible enough to handle diverse attacker profiles while maintaining their analytical rigor.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11494486B1Continuously habituating elicitation strategies for social-engineering-attacks (CHESS)
Publication Date: 2022.11.08 HRL LAB
  • US11494486B1 patent drawing
  • US11494486B1 patent drawing
  • US11494486B1 patent drawing

AI summary

Described is a system for continuously predicting and adapting optimal strategies for attacker elicitation. The system includes a global bot controlling processor unit and one or more local bot controlling processor units. The global bot controlling processor unit includes a multi-layer network software unit for extracting attacker features from diverse, out-of-band (OOB) media sources. The global controlling processing unit further includes an adaptive behavioral game theory (GT) software unit for determining a best strategy for eliciting identifying information from an attacker. Each local bot controlling processor unit includes a cognitive model (CM) software unit for estimating a cognitive state of the attacker and predicting attacker behavior. A generative adversarial network (GAN) software unit predicts the attacker's strategies. The global bot controlling processor unit and the one or more local bot controlling processor units coordinate to predict the attacker's next action and use the prediction to disrupt an attack.