Attack Classification System for Premium Cyber Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity measures fail to reliably detect premium attacks, which are difficult to distinguish from commodity attacks and often evade detection through signature-based approaches due to their customized nature and manual operator involvement.
Innovation Solution
A system and method that utilizes an attack classification system to differentiate premium attacks from commodity attacks by performing data modeling on incoming analytic information, generating a nodal graph, filtering incidental relationships, clustering related objects, and analyzing cluster features to identify indicators of manual activity and customization, thereby providing alerts and detailed analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If signature-based approaches are used to detect attacks, then detection speed is improved, but detection accuracy deteriorates because premium attacks are customized and evade signature matching
Solution Approach 1:
The patent transforms the detection approach by changing from signature-based parameters to behavioral and contextual parameters. Instead of matching known attack signatures, the system analyzes command-line parameters, file system activities, registry modifications, and process behaviors to identify premium attacks, thereby maintaining detection speed while improving accuracy for customized attacks
Solution Approach 2:
The system implements dynamic analysis by monitoring real-time system behaviors and activities rather than relying on static signatures. The behavioral analysis engine continuously observes and evaluates process executions, file operations, and system changes, enabling the detection of premium attacks through their dynamic behavioral patterns rather than static characteristics
2Measurement precision
If behavioral analysis is performed to detect premium attacks, then detection accuracy is improved, but system complexity increases
Solution Approach 1:
The patent segments the complex detection system into distinct functional modules: data collection module, behavioral analysis engine, pattern recognition module, and response mechanism. Each module performs a specific function, making the overall complex system manageable and maintainable while achieving high detection accuracy through coordinated operation of these specialized components
Solution Approach 2:
The system introduces intermediary components such as the behavioral analysis engine that acts as a mediator between raw system events and detection conclusions. This intermediary layer processes and interprets complex behavioral data, transforming it into actionable intelligence without requiring the entire system to handle full complexity at once
3Reliability
If comprehensive data collection is performed to identify premium attacks, then detection reliability is improved, but processing time increases
Solution Approach 1:
The system performs preliminary actions by pre-defining behavioral patterns, command-line parameter signatures, and file system activity templates that are characteristic of premium attacks. During runtime, the system matches observed behaviors against these pre-established patterns, enabling reliable detection without requiring exhaustive analysis of all possible behaviors, thus reducing processing time while maintaining high reliability
Data Source
AI summary
A computerized method for detecting premium attacks by an attack classification system is described. Based on received analytic information, the attack classification system generates logical representations for different portions of the analytic information represented as a nodal graph. The logical representations include objects, properties, and relationships between the objects and the properties. The attack classification system filters at least one relationship from the relationships and forms a first cluster further filtering the relationships. Being a logical representation of objects, properties and the remaining relationships, the first cluster is analyzed to determine features and introduce the features into the nodal graph. An analysis of the features determines whether the objects, properties and relationships forming the first cluster are associated with a premium attack by at least applying rule-based constraints to the features of the first cluster to determine whether they correspond to cluster features commonly present in premium attacks.


