Attack Classification System for Premium Cyber Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity measures fail to reliably detect premium attacks, which are difficult to distinguish from commodity attacks and often evade detection through signature-based approaches due to their customized nature and manual operator involvement.

Innovation Solution

A system and method that utilizes an attack classification system to differentiate premium attacks from commodity attacks by performing data modeling on incoming analytic information, generating a nodal graph, filtering incidental relationships, clustering related objects, and analyzing cluster features to identify indicators of manual activity and customization, thereby providing alerts and detailed analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If signature-based approaches are used to detect attacks, then detection speed is improved, but detection accuracy deteriorates because premium attacks are customized and evade signature matching

Engineering Contradiction:
Improvedetection speedVSAvoiddetection accuracy
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The patent transforms the detection approach by changing from signature-based parameters to behavioral and contextual parameters. Instead of matching known attack signatures, the system analyzes command-line parameters, file system activities, registry modifications, and process behaviors to identify premium attacks, thereby maintaining detection speed while improving accuracy for customized attacks

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements dynamic analysis by monitoring real-time system behaviors and activities rather than relying on static signatures. The behavioral analysis engine continuously observes and evaluates process executions, file operations, and system changes, enabling the detection of premium attacks through their dynamic behavioral patterns rather than static characteristics

Inventive Principle:
Principle #15Dynamics

2Measurement precision

If behavioral analysis is performed to detect premium attacks, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the complex detection system into distinct functional modules: data collection module, behavioral analysis engine, pattern recognition module, and response mechanism. Each module performs a specific function, making the overall complex system manageable and maintainable while achieving high detection accuracy through coordinated operation of these specialized components

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces intermediary components such as the behavioral analysis engine that acts as a mediator between raw system events and detection conclusions. This intermediary layer processes and interprets complex behavioral data, transforming it into actionable intelligence without requiring the entire system to handle full complexity at once

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If comprehensive data collection is performed to identify premium attacks, then detection reliability is improved, but processing time increases

Engineering Contradiction:
Improvedetection reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-defining behavioral patterns, command-line parameter signatures, and file system activity templates that are characteristic of premium attacks. During runtime, the system matches observed behaviors against these pre-established patterns, enabling reliable detection without requiring exhaustive analysis of all possible behaviors, thus reducing processing time while maintaining high reliability

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10121000B1System and method to detect premium attacks on electronic networks and electronic devices
Publication Date: 2018.11.06 MAGENTA SECURITY HOLDINGS LLC
  • US10121000B1 patent drawing
  • US10121000B1 patent drawing
  • US10121000B1 patent drawing

AI summary

A computerized method for detecting premium attacks by an attack classification system is described. Based on received analytic information, the attack classification system generates logical representations for different portions of the analytic information represented as a nodal graph. The logical representations include objects, properties, and relationships between the objects and the properties. The attack classification system filters at least one relationship from the relationships and forms a first cluster further filtering the relationships. Being a logical representation of objects, properties and the remaining relationships, the first cluster is analyzed to determine features and introduce the features into the nodal graph. An analysis of the features determines whether the objects, properties and relationships forming the first cluster are associated with a premium attack by at least applying rule-based constraints to the features of the first cluster to determine whether they correspond to cluster features commonly present in premium attacks.