Autonomous Attack Identification System for Electronic Communication Platforms

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cyber attacks, particularly electronic message-borne attacks, often evade detection due to varying content, leading administrators to miss the scope of the attack within an organization's network, resulting in untold monetary and legal consequences.

Innovation Solution

A system and method for autonomous identification of similar and adjacent attacks, where incident creation is followed by automatic generation of insight events, which are searched across the electronic communication platform to identify and remediate un-remediated attacks, enabling administrators to look beyond the original scope of the attack and eliminate all related threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If administrators rely on user reporting for forensics analysis, then the system can identify reported attacks, but the scope of the attack is missed due to obfuscated detection

Engineering Contradiction:
Improveattack detection accuracyVSAvoidattack scope information
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The system performs self-service by automatically analyzing communication data to identify attack patterns without requiring user reporting. The autonomous attack identification system proactively searches for similar and adjacent attacks across the network, eliminating the dependency on user-initiated reports and comprehensive forensic analysis.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary action by proactively identifying similar and adjacent attacks before they are reported by users. The autonomous identification system continuously monitors communication data and can detect attack patterns in advance, enabling preemptive response before the full scope of the attack is discovered through traditional user-reporting mechanisms.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If the system only analyzes reported attacks, then the response process is simple, but the attack response time increases due to delayed detection

Engineering Contradiction:
Improveattack response speedVSAvoidattack detection delay
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system maintains continuous monitoring and analysis of communication data to identify attack patterns in real-time. The autonomous identification system operates continuously, eliminating gaps in detection that would occur with user-reporting-only approaches, thereby reducing detection delay and enabling faster response.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system performs preliminary detection of attack patterns before they are reported by users. By continuously analyzing communication data and identifying similar and adjacent attacks proactively, the system reduces the time between attack occurrence and detection, enabling faster response compared to reactive user-reporting mechanisms.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If administrators manually analyze each attack, then detailed analysis is possible, but the scope and extent of attacks cannot be fully comprehended

Engineering Contradiction:
Improveattack scope comprehensionVSAvoidanalysis system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system segments the complex task of attack analysis into distinct functional components: autonomous identification of similar attacks, identification of adjacent attacks, and comprehensive scope analysis. This segmentation allows the system to handle complex attack patterns systematically without requiring manual analysis of every individual attack, thereby improving comprehension while managing complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The autonomous identification system performs multiple functions within a single integrated platform: detecting similar attacks, identifying adjacent attacks, analyzing attack scope, and providing comprehensive threat intelligence. This multi-functionality eliminates the need for separate manual analysis processes, improving attack scope comprehension while consolidating complexity into a unified system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11558419B2Method and apparatus for autonomous identification of similar and adjacent attacks based on detected attacks
Publication Date: 2023.01.17 BARRACUDA NETWORKS INC
  • US11558419B2 patent drawing
  • US11558419B2 patent drawing
  • US11558419B2 patent drawing

AI summary

A new approach is proposed to support autonomous similar and adjacent attack identification. First, an incident is created for a detected suspicious electronic message-borne attack at one user account with one tenant on an electronic communication platform. A plurality of insight events for similar or adjacent attacks are then generated automatically based on the detected attack and inserted into an insights queue. For each of the insight events in the insights queue, a search is conducted in a repository to identify a set of un-remediated attacks against user accounts of the same or different tenants on the electronic communication platform, wherein the set of un-remediated attacks are similar or adjacent to the detected attack. Insights on the identified un-remediated attacks against the user accounts in the same or different tenants that are similar or adjacent to the detected attack are automatically generated for an administrator and are remediated accordingly.