Adaptive Cyber Security System for APT Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions are inadequate in detecting and mitigating advanced persistent threats (APT) due to their inability to adapt to evolving threats, lack of programmability, and reliance on non-zero-day attack technologies, leading to high false positive alerts and prolonged security policy implementation cycles.

Innovation Solution

A cyber security system that adaptively secures networks by probing resources for APT activity, generating security events, and determining actions based on workflow rules, allowing for programmable security applications and services to detect and mitigate multi-vector APT campaigns across virtualized and software-defined networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current security solutions use sandbox and reputation based detection mechanisms, then zero-day malware activity can be detected, but the system generates high false positive alerts and requires complex implementation

Engineering Contradiction:
Improvedetection accuracyVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud-based security platform as an intermediary that hosts sandbox environments and reputation services. This externalizes the complex detection infrastructure from individual enterprise networks, allowing sophisticated zero-day detection capabilities while keeping local implementations simple. The cloud platform manages the complexity of sandbox orchestration, malware execution environments, and reputation database maintenance centrally.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates virtual copies of malware in sandbox environments for safe analysis. Instead of running malware directly on production systems, the system copies suspicious files into isolated sandbox instances, executes them there, and analyzes their behavior. This copying approach enables zero-day detection without risking production systems, while the sandboxed copies contain any harmful effects.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If security systems are designed to be highly secure and adaptive, then they can detect evolving APT threats, but they lack programmability and take prolonged time to implement security policies

Engineering Contradiction:
Improveadaptability to evolving threatsVSAvoidsecurity policy implementation time
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements dynamic security policies that automatically adapt to new threats through continuous learning from sandbox analysis results and reputation data. The system updates detection rules, blocklists, and security configurations in real-time based on emerging threat patterns, eliminating the need for manual policy updates. This dynamic adaptation maintains high security while reducing implementation time for new threat responses.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent establishes feedback loops where sandbox analysis results, reputation service updates, and threat intelligence continuously inform and refine security policies. The system learns from detected APT behaviors and automatically adjusts detection thresholds, rules, and configurations. This feedback mechanism enables rapid adaptation to evolving threats without manual intervention, reducing policy implementation time while maintaining adaptability.

Inventive Principle:
Principle #23Feedback

3Reliability

If security solutions rely on cloud-based sandbox and reputation services, then detection capabilities are enhanced, but transporting content outside the organization network creates privacy and security concerns

Engineering Contradiction:
Improvedetection capabilityVSAvoidprivacy and security risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the security architecture into cloud-based detection services and on-premises deployment options. Enterprises can choose to host sandbox environments and reputation services locally within their own networks, keeping all content analysis and threat detection entirely within organizational boundaries. This segmentation allows organizations to maintain enhanced detection capabilities while eliminating the need to transport content outside their controlled network environment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an on-premises security appliance or gateway as an intermediary that provides sandbox and reputation services locally. This local intermediary performs all malware analysis and reputation checking within the organization's network perimeter, eliminating the need to send content to external cloud services. The intermediary maintains detection capabilities while ensuring all content remains within the secure organizational network.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11115437B2Cyber-security system and methods thereof for detecting and mitigating advanced persistent threats
Publication Date: 2021.09.07 CYBEREASON INC
  • US11115437B2 patent drawing
  • US11115437B2 patent drawing
  • US11115437B2 patent drawing

AI summary

A method and system for adaptively securing a protected entity against a potential advanced persistent threat (APT) are provided. The method includes probing a plurality of resources in a network prone to be exploited by an APT attacker; operating at least one security service configured to output signals indicative of APT related activity of each of the plurality of probed resources; generating at least one security event respective of the output signals; determining if the at least one security event satisfies at least one workflow rule; and upon determining that the at least one security event satisfies the at least one workflow rule, generating at least one action with respect to the potential APT attack.