Multi-dimensional Attack Detection via Weighted Bayesian Aggregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional attack detection systems are limited in their analysis capabilities, often relying on single-dimensional assessments and failing to effectively differentiate between actual attacks and benign communications, leading to high rates of false positives and false negatives, and are typically confined to a single network or site.

Innovation Solution

A multi-dimensional attack detection system that conducts multiple countermeasure assessments, weights the results based on historical attack profiles, and combines them to provide a composite probability score, utilizing a Bayesian network to improve false negative and false positive performance by leveraging attack information across diverse networks and clients.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single countermeasure assessment is used to determine whether a communication contains an attack, then the system complexity is reduced, but the measurement precision and reliability of attack detection deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoidattack detection precision
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent divides the attack detection system into multiple independent countermeasure assessments, each evaluating different aspects of a communication (e.g., content analysis, sender reputation, behavioral patterns). Each assessment operates separately and produces an individual score, which are then aggregated to form a comprehensive detection result. This segmentation allows the system to maintain low complexity in individual components while achieving high overall detection precision.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a single-dimensional assessment to a multi-dimensional evaluation framework by introducing multiple countermeasure assessments that evaluate communications from different perspectives (content, sender, recipient, timing, pattern). This dimensional expansion enables the system to capture the complexity of attack detection without increasing the complexity of individual assessment mechanisms.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If multiple countermeasure assessments are conducted and combined, then the reliability and measurement precision of attack detection improves, but the device complexity increases

Engineering Contradiction:
Improveattack detection reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the results of multiple countermeasure assessments through a weighted aggregation mechanism. Each assessment result is combined with others using predetermined weights that reflect their relative importance and reliability. This merging process consolidates multiple complex assessments into a single comprehensive detection score, improving reliability while managing system complexity through systematic integration.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent dynamically adjusts the weights of different countermeasure assessments based on historical performance data, communication characteristics, and attack patterns. By changing the parameters (weights) of each assessment, the system optimizes the combination of multiple assessments to maximize detection reliability while adapting to varying threat landscapes and communication types.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If conventional single-dimensional assessment methods are used, then the ease of operation is maintained, but the reliability of attack detection deteriorates due to high false positive and false negative rates

Engineering Contradiction:
Improveoperational simplicityVSAvoidattack detection reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements self-service mechanisms where the system automatically selects, weights, and combines countermeasure assessments based on historical data and performance metrics without requiring manual configuration. The system self-optimizes by learning from past attacks and adjusting assessment priorities automatically, maintaining ease of operation while significantly improving detection reliability through adaptive multi-dimensional analysis.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8931095B2System and method for assessing whether a communication contains an attack
Publication Date: 2015.01.06 SOPHOS INC
  • US8931095B2 patent drawing
  • US8931095B2 patent drawing
  • US8931095B2 patent drawing

AI summary

Communications can be processed with multiple countermeasures to identify attacks. Each countermeasure can compute a probability of a communication containing an attack and an accompanying confidence score indicating confidence in the probability. Combining the probabilities can produce a composite probability and associated confidence of the communication containing an attack. The composite probability and confidence scores can be produced from a weighted combination of the individual countermeasure probabilities and confidence scores. Weighting factors can be generated or obtained from a database that stores profiles of confirmed attacks.