Bayesian Model for Cyber Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cybersecurity methods rely on predefined rules and signatures, which are ineffective against novel cyber threats and socially engineered attacks, as they fail to detect subtle changes in behavior and patterns, especially in porous networks and mobile environments.

Innovation Solution

A Bayesian probabilistic model, referred to as the Hyper Cylinder, is used for automatic real-time detection of cyber threats by establishing a dynamic model of normal behavior based on network traffic data, user interactions, and other metrics, allowing for the identification of anomalous behavior without prior knowledge of threat types or updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional cybersecurity methods using predefined rules and signatures are used, then known threats can be detected, but novel cyber threats and socially engineered attacks cannot be detected

Engineering Contradiction:
Improvedetection effectivenessVSAvoidability to detect novel threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by transitioning from static predefined rules to a dynamic probabilistic model that continuously adapts to new threat patterns. The Bayesian model updates its understanding of normal behavior over time, enabling detection of novel threats without requiring explicit reconfiguration of detection rules.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the fundamental parameter of threat detection from deterministic rule-matching to probabilistic behavior modeling. By using Bayesian probability to model normal behavior patterns and detect deviations, the system can identify novel threats based on statistical anomalies rather than requiring known threat signatures.

Inventive Principle:
Principle #35Parameter changes

2Ease of manufacture

If conventional rule-based detection methods are used, then implementation is straightforward, but detection precision for subtle behavioral changes is insufficient

Engineering Contradiction:
Improveimplementation simplicityVSAvoiddetection precision
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent replaces the mechanical rule-matching system with a probabilistic modeling system. Instead of mechanically checking against predefined rules, the system uses Bayesian probability to model normal behavior and detect subtle deviations, significantly improving detection precision for nuanced behavioral changes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Object-affected harmful factors

If network perimeter control is enforced, then unauthorized access is prevented, but the network becomes vulnerable to internal threats and mobile workforce security

Engineering Contradiction:
Improveunauthorized accessVSAvoidsecurity in porous networks
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent inverts the traditional security approach by not focusing on preventing unauthorized access at perimeters, but rather on detecting and responding to actual harmful behavior regardless of location. This inversion allows security to adapt to porous networks where boundaries are blurred and threats can originate from anywhere within the organization.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentEP4033387A1Cyber security
Publication Date: 2022.07.27 DARKTRACE HLDG LTD
  • EP4033387A1 patent drawingFigure 1
  • EP4033387A1 patent drawingFigure 2
  • EP4033387A1 patent drawingFigure 3

AI summary

Disclosed herein is a method for use in detection of abnormal behavior of a group of a plurality of entities of a computer system (100). The method is arranged to be performed by a processing system and comprises: creating a model of normal behavior of the group of entities; and determining, in accordance with the model of normal behavior of the group of entities, a parameter indicative of abnormal behavior of the group of entities. Also disclosed is an equivalent computer readable medium and anomalous behavior detection system.