Cyber-Attack Sequence Matching via Step-Value Lists
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security solutions fail to efficiently analyze the high volume of events generated by security devices, leading to missed cyber-attack detections and misallocation of resources, as they cannot identify patterns across different devices and perform real-time comparisons effectively.
Innovation Solution
A method and system for predictive cyber-attack detection that converts event sequences into step-value lists and matches them to identify optimal common patterns, using a processing circuitry and memory to receive and process reference and query event sequences, enabling early detection of cyber-attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If security devices generate and collect events from multiple sources, then the coverage of security monitoring is improved, but the volume of events to be analyzed increases significantly
Solution Approach 1:
The patent segments the large volume of security events into sequences grouped by common characteristics (e.g., source IP, destination IP, event type). This segmentation allows the system to process events in manageable chunks rather than as a monolithic dataset, reducing the analytical burden while maintaining comprehensive coverage across multiple security devices.
Solution Approach 2:
The patent merges events from multiple security devices into unified sequences based on shared attributes. By combining related events across different devices into coherent attack sequences, the system reduces redundancy and enables more efficient analysis of correlated events that span multiple security boundaries.
2Measurement precision
If a security administrator manually processes and analyzes security events, then detailed analysis can be performed, but the time and resources required increase significantly
Solution Approach 1:
The patent performs preliminary actions by automatically grouping events into sequences and identifying potential attack patterns before a security administrator needs to analyze them. This pre-processing reduces the workload for manual analysis while preserving the ability to perform detailed examination of suspicious sequences, thereby reducing analysis time without sacrificing precision.
Solution Approach 2:
The patent introduces an intermediary system that sits between raw security events and human analysis. This intermediary automatically processes events, identifies sequences, and highlights suspicious patterns, serving as a bridge that reduces the time required for manual analysis while maintaining the depth of analysis that security administrators can provide when needed.
3Productivity
If standard event analysis methods are used without pattern recognition, then individual events can be processed quickly, but attack sequences and patterns cannot be detected
Solution Approach 1:
The patent performs preliminary pattern recognition by automatically grouping events into sequences and identifying characteristic attack patterns before final detection decisions are made. This allows the system to maintain high processing speed for individual events while simultaneously performing comprehensive pattern analysis to ensure reliable attack detection.
Solution Approach 2:
The patent implements a dynamic analysis approach where the system adapts its processing depth based on the characteristics of event sequences. For clearly identifiable attack patterns, the system can make rapid detections, while for more complex or novel sequences, it performs deeper analysis. This dynamic approach maintains both high productivity and reliable detection accuracy across different scenarios.
Data Source
AI summary
A method and system for matching event sequences for predictive detection of cyber-attacks are discussed. The method comprises receiving a reference event sequence and a query event sequence; converting the reference event sequence to a first step-value list and the query event sequence to a second step-value list; and matching the first and second step-value lists to identify at least one optimal common pattern.


