Adaptive APT Detection via Dynamic Sensor and Trap Weighting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting advanced persistent threats (APTs) in information systems either incur high performance and maintenance costs or are inefficient due to the limited effectiveness of deploying many traps, which require extensive management.
Innovation Solution
A method and device that evaluate threat levels by activating sensors and deploying traps in an information system infrastructure, with adaptive rules for detection and mitigation, using sensors and traps to send notifications and lure attackers into false paths, thereby efficiently detecting and managing APTs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If sensors are activated on all resources to monitor and scrutinize everything, then detection precision is improved, but device complexity and operational maintenance increase prohibitively
Solution Approach 1:
The patent applies local quality by activating sensors selectively on specific resources based on their importance and risk profile rather than uniformly on all resources. The system evaluates threat levels and activates sensors on resources that are potential subsequent targets of ongoing attacks, creating a non-uniform, adaptive sensing strategy that optimizes detection precision while controlling complexity
Solution Approach 2:
The patent implements dynamics by making sensor activation dynamic and adaptive rather than static. Sensors are activated or deactivated based on changing threat levels, ongoing attack patterns, and risk assessments. This dynamic approach allows the system to concentrate monitoring resources when threats are detected while reducing complexity during normal operations
2Measurement precision
If many traps are deployed to detect attacks, then detection precision is improved, but ease of operation deteriorates due to extensive management requirements
Solution Approach 1:
The patent applies self-service by enabling the system to automatically deploy and manage traps without extensive human intervention. The trap deployment is driven by automated threat level evaluations and attack pattern recognition, allowing the system to self-adjust its trapping strategy based on detected threats while reducing the operational burden on security personnel
Solution Approach 2:
The patent implements preliminary action by pre-deploying traps on potential subsequent targets before attacks occur. The system identifies resources that are likely to be targeted based on attack patterns and pre-positiones traps there, so that when attacks occur, detection is already in place without requiring reactive deployment and management
3Measurement precision
If sensors are activated on potential subsequent targets, then detection precision is improved, but performance degradation increases
Solution Approach 1:
The patent applies partial action by activating sensors only on a subset of resources that are identified as potential subsequent targets rather than on all resources. This selective activation achieves sufficient detection precision for the most critical areas while minimizing the performance impact on the overall system
4Reliability
If traps are deployed as fake resources to mitigate attack progress, then reliability is improved, but device complexity increases
Solution Approach 1:
The patent applies the intermediary principle by using traps as fake resources that act as intermediaries between attackers and real system resources. These traps lure attackers away from genuine resources, providing an additional layer of security without requiring direct modification or protection of the critical assets themselves
Data Source
AI summary
A threat level is evaluated for an ongoing attack detected for a set of resources based on received notifications having low weight in the evaluation of the threat level. If the threat level is smaller than an entrapment threshold, sensors associated with resources of an information system infrastructure that are potential subsequent targets of the ongoing attack are activated, the weight of the notifications sent from the activated sensors are set as average weight in the evaluation of the threat level, and the threat level is further evaluated for the ongoing attack. If the threat level is greater than the entrapment threshold, traps are deployed in the information system infrastructure, the weight of the notifications sent from the deployed traps are set as high weight in the evaluation of the threat level, and the threat level is further evaluated for the ongoing attack.

