Cyber-Attack Summary Event Detection via Attack Tree Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting cyber-attacks on endpoints, such as malware, lack effective analysis and summarization of attack events, making it difficult to identify and respond to malicious activities in a timely and comprehensive manner.
Innovation Solution
The development of a system that analyzes attack trees to identify summary events, providing a summarized view of cyber-attacks through textual and graphical representations, focusing on damage and suspicious events, network activities, file modifications, and other predefined events, allowing for correlation and connection of relevant events.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If comprehensive analysis of all attack events is performed, then detection accuracy is improved, but analysis time and system complexity increase
Solution Approach 1:
The patent extracts and identifies specific summary events from the complete attack tree that are most indicative of malicious activity. By selecting only certain key events (such as suspicious events, damage events, network events, file events, registry events, and process events) rather than analyzing all events comprehensively, the system achieves effective detection while reducing analysis time and computational resources required.
Solution Approach 2:
The patent segments the attack tree into distinct event categories (suspicious events, damage events, network events, file events, registry events, process events). This segmentation allows the system to focus analysis on specific event types that are most relevant to detecting malicious activity, thereby improving detection accuracy for critical events while avoiding unnecessary analysis of less relevant events.
2Loss of information
If detailed attack event analysis is performed, then understanding of attack is improved, but ease of operation deteriorates
Solution Approach 1:
The patent extracts only the most relevant summary events from the complete attack tree that directly indicate malicious activity. By presenting a curated subset of critical events rather than all detailed events, the system maintains comprehensive understanding of the attack while improving ease of operation through reduced complexity and focused information presentation.
Solution Approach 2:
The patent segments attack events into categorized summaries (suspicious, damage, network, file, registry, and process events). This segmentation organizes detailed attack information into manageable categories, making it easier for operators to understand and analyze attacks without being overwhelmed by the full complexity of all individual events.
3Quantity of substance
If voluminous attack data is processed, then completeness of analysis is improved, but device complexity increases
Solution Approach 1:
The patent extracts a representative subset of summary events from the voluminous attack data that captures the essential characteristics of malicious activity. By processing this extracted subset rather than all raw data, the system achieves effective analysis completeness while significantly reducing computational complexity and resource requirements.
Solution Approach 2:
The patent segments voluminous attack data into organized event categories with specific focus areas (suspicious events, damage events, network events, file events, registry events, and process events). This segmentation structure enables the system to process large amounts of data in an organized manner, improving analytical completeness while managing system complexity through structured data organization and targeted analysis of each event type.
Data Source
AI summary
Computerized methods and systems determine summary events from an attack on an endpoint. The detection and determination of these summary events is performed by a machine, e.g., a computer, node of a network, system or the like.


