Anomaly Sensor Framework for Advanced Persistent Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current threat detection methods for advanced persistent threats (APTs) in computer systems are labor-intensive, non-scalable, and prone to high false positive rates, especially when dealing with 'low-and-slow' attacks, relying heavily on human specialists and volume-based outliers that fail to detect stealthy anomalies effectively.
Innovation Solution
An automated threat detection system utilizing anomaly sensors and correlators to identify behavioral deviations by building activity histories and comparing them to detect new patterns, correlating events across different stages of threat activity, with a framework that allows human analysts to define templates for known attack patterns and generate alerts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If human security specialists manually interrogate systems for APT presence, then detection capability for known attack patterns is improved, but labor intensity increases and scalability deteriorates
Solution Approach 1:
The system enables self-service through automated anomaly detection where the system monitors itself and detects threats without requiring continuous human intervention. The automated sensors and correlators perform detection functions that previously required manual security specialist interrogation, allowing the system to scale independently of human resources.
Solution Approach 2:
The patent replaces the mechanical system of human security specialists manually analyzing systems with an automated electronic system comprising sensors, correlators, and processing components. This substitution eliminates labor intensity while maintaining detection capability through automated behavioral analysis and pattern recognition.
2Measurement precision
If volume-based outlier detection is used, then detection of obvious anomalies is improved, but false positive rate increases and detection of stealthy APTs deteriorates
Solution Approach 1:
The system applies local quality by analyzing specific local behaviors and patterns of individual sensors rather than relying on global volume-based outliers. Each sensor examines local activity patterns (user login behaviors, host communication patterns, application usage patterns) and generates alerts based on localized anomalies, reducing false positives while improving detection accuracy for stealthy attacks.
Solution Approach 2:
The system implements dynamics through continuous learning and adaptation where sensor behaviors are updated over time based on observed patterns. The correlators dynamically adjust detection parameters and alert thresholds based on evolving attack patterns and baseline behaviors, enabling the system to adapt to changing threat landscapes while reducing false positives.
3Productivity
If automated anomaly detection is implemented, then scalability is improved, but complexity of the detection system increases
Solution Approach 1:
The system applies segmentation by dividing the complex detection function into independent modular components: multiple types of sensors (user-activity sensors, host-activity sensors, application-activity sensors), correlators that combine sensor outputs, and alert generation mechanisms. This modular architecture enables scalability through selective deployment of specific sensor types while managing complexity through standardized interfaces and clear functional separation.
Data Source
AI summary
A threat detection system for detecting threat activity in a protected computer system includes anomaly sensors of distinct types including user-activity sensors, host-activity sensors and application-activity sensors. Each sensor builds a history of pertinent activity over a training period, and during a subsequent detection period the sensor compares current activity to the history to detect new activity. The new activity is identified in respective sensor output. A set of correlators of distinct types are used that correspond to different stages of threat activity according to modeled threat behavior. Each correlator receives output of one or more different-type sensors and applies logical and/or temporal testing to detect activity patterns of the different stages. The results of the logical and/or temporal testing are used to generate alert outputs for a human or machine user.


