Cyber-Attack Summary Event Detection via Attack Tree Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting cyber-attacks on endpoints, such as malware, lack effective analysis and summarization of attack events, making it difficult to identify and respond to malicious activities in a timely and comprehensive manner.

Innovation Solution

The development of a system that analyzes attack trees to identify summary events, providing a summarized view of cyber-attacks through textual and graphical representations, focusing on damage and suspicious events, network activities, file modifications, and other predefined events, allowing for correlation and connection of relevant events.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If comprehensive analysis of all attack events is performed, then detection accuracy is improved, but analysis time and system complexity increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent extracts and identifies specific summary events from the complete attack tree that are most indicative of malicious activity. By selecting only certain key events (such as suspicious events, damage events, network events, file events, registry events, and process events) rather than analyzing all events comprehensively, the system achieves effective detection while reducing analysis time and computational resources required.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the attack tree into distinct event categories (suspicious events, damage events, network events, file events, registry events, process events). This segmentation allows the system to focus analysis on specific event types that are most relevant to detecting malicious activity, thereby improving detection accuracy for critical events while avoiding unnecessary analysis of less relevant events.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If detailed attack event analysis is performed, then understanding of attack is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveunderstanding of attackVSAvoidease of use
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent extracts only the most relevant summary events from the complete attack tree that directly indicate malicious activity. By presenting a curated subset of critical events rather than all detailed events, the system maintains comprehensive understanding of the attack while improving ease of operation through reduced complexity and focused information presentation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments attack events into categorized summaries (suspicious, damage, network, file, registry, and process events). This segmentation organizes detailed attack information into manageable categories, making it easier for operators to understand and analyze attacks without being overwhelmed by the full complexity of all individual events.

Inventive Principle:
Principle #1Segmentation

3Quantity of substance

If voluminous attack data is processed, then completeness of analysis is improved, but device complexity increases

Engineering Contradiction:
Improveamount of data analyzedVSAvoidsystem complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent extracts a representative subset of summary events from the voluminous attack data that captures the essential characteristics of malicious activity. By processing this extracted subset rather than all raw data, the system achieves effective analysis completeness while significantly reducing computational complexity and resource requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments voluminous attack data into organized event categories with specific focus areas (suspicious events, damage events, network events, file events, registry events, and process events). This segmentation structure enables the system to process large amounts of data in an organized manner, improving analytical completeness while managing system complexity through structured data organization and targeted analysis of each event type.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10291634B2System and method for determining summary events of an attack
Publication Date: 2019.05.14 CHECK POINT SOFTWARE TECH LTD
  • US10291634B2 patent drawing
  • US10291634B2 patent drawing
  • US10291634B2 patent drawing

AI summary

Computerized methods and systems determine summary events from an attack on an endpoint. The detection and determination of these summary events is performed by a machine, e.g., a computer, node of a network, system or the like.