Cyber-Attack Sequence Matching via Step-Value Lists

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions fail to efficiently analyze the high volume of events generated by security devices, leading to missed cyber-attack detections and misallocation of resources, as they cannot identify patterns across different devices and perform real-time comparisons effectively.

Innovation Solution

A method and system for predictive cyber-attack detection that converts event sequences into step-value lists and matches them to identify optimal common patterns, using a processing circuitry and memory to receive and process reference and query event sequences, enabling early detection of cyber-attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If security devices generate and collect events from multiple sources, then the coverage of security monitoring is improved, but the volume of events to be analyzed increases significantly

Engineering Contradiction:
Improvesecurity monitoring coverageVSAvoidevent volume
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent segments the large volume of security events into sequences grouped by common characteristics (e.g., source IP, destination IP, event type). This segmentation allows the system to process events in manageable chunks rather than as a monolithic dataset, reducing the analytical burden while maintaining comprehensive coverage across multiple security devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges events from multiple security devices into unified sequences based on shared attributes. By combining related events across different devices into coherent attack sequences, the system reduces redundancy and enables more efficient analysis of correlated events that span multiple security boundaries.

Inventive Principle:
Principle #5Merging (Combining)

2Measurement precision

If a security administrator manually processes and analyzes security events, then detailed analysis can be performed, but the time and resources required increase significantly

Engineering Contradiction:
Improveevent analysis detailVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by automatically grouping events into sequences and identifying potential attack patterns before a security administrator needs to analyze them. This pre-processing reduces the workload for manual analysis while preserving the ability to perform detailed examination of suspicious sequences, thereby reducing analysis time without sacrificing precision.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary system that sits between raw security events and human analysis. This intermediary automatically processes events, identifies sequences, and highlights suspicious patterns, serving as a bridge that reduces the time required for manual analysis while maintaining the depth of analysis that security administrators can provide when needed.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If standard event analysis methods are used without pattern recognition, then individual events can be processed quickly, but attack sequences and patterns cannot be detected

Engineering Contradiction:
Improveevent processing speedVSAvoidattack detection accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent performs preliminary pattern recognition by automatically grouping events into sequences and identifying characteristic attack patterns before final detection decisions are made. This allows the system to maintain high processing speed for individual events while simultaneously performing comprehensive pattern analysis to ensure reliable attack detection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a dynamic analysis approach where the system adapts its processing depth based on the characteristics of event sequences. For clearly identifiable attack patterns, the system can make rapid detections, while for more complex or novel sequences, it performs deeper analysis. This dynamic approach maintains both high productivity and reliable detection accuracy across different scenarios.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11483321B2System and method for attack sequence matching
Publication Date: 2022.10.25 RADWARE LTD
  • US11483321B2 patent drawing
  • US11483321B2 patent drawing
  • US11483321B2 patent drawing

AI summary

A method and system for matching event sequences for predictive detection of cyber-attacks are discussed. The method comprises receiving a reference event sequence and a query event sequence; converting the reference event sequence to a first step-value list and the query event sequence to a second step-value list; and matching the first and second step-value lists to identify at least one optimal common pattern.