Case-Based Cyber Defense for Unknown Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cyber defense technologies rely on single observations with high confidence for threat detection, which is inadequate for unknown threats, and lack integration of network and endpoint data, leading to blind spots and over-reporting.
Innovation Solution
A cyber defense platform that integrates network and endpoint data, using case-based analysis to associate events with common features, score cases, and render significant threats via a user interface, employing machine learning and real-time analytics to link and enhance events.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If single observations with high confidence are used for threat detection, then false positives are reduced, but detection capability for unknown threats is insufficient
Solution Approach 1:
The patent combines multiple low-confidence observations into a unified case structure that aggregates evidence from multiple sources (network events, endpoint events, threat intelligence). By merging these observations and applying collective scoring, the system achieves reliable detection of unknown threats that would not be detectable through single observations alone.
Solution Approach 2:
The patent introduces a temporal dimension by collecting observations over time and a contextual dimension by enriching events with additional information (threat intelligence, entity relationships). This multi-dimensional approach allows the system to build confidence in threat detection through accumulated evidence rather than relying on single-point observations.
2Reliability
If network and endpoint data are integrated, then comprehensive threat detection is achieved, but system complexity increases
Solution Approach 1:
The patent segments the complex integrated system into distinct modular components: event collectors (network and endpoint), event normalization module, case builder, scoring engine, and response orchestration. Each component handles specific tasks independently, making the overall complex system manageable and maintainable while achieving comprehensive threat detection.
Solution Approach 2:
The patent introduces an event normalization layer as an intermediary that standardizes data from diverse network and endpoint sources into a common format. This mediator component simplifies integration by handling data format variations and providing a unified interface for subsequent analysis, reducing the complexity of direct integration between heterogeneous systems.
3Adaptability or versatility
If multiple observations are associated into cases, then detection of unknown threats improves, but processing time increases
Solution Approach 1:
The patent applies partial action by initially creating cases with available evidence and continuously enriching them as additional observations become available. Rather than waiting for complete information before initiating analysis, the system begins threat assessment with partial data and incrementally adds more observations, reducing overall processing time while maintaining detection accuracy.
Solution Approach 2:
The patent performs preliminary actions by pre-establishing case structures, scoring models, and association rules before threat detection is needed. Event templates and correlation rules are configured in advance, allowing the system to rapidly process and associate observations into cases without performing complex analysis from scratch for each threat event.
Data Source
AI summary
In one aspect, a computer-implemented method of detecting network security threats comprises the following steps: receiving at an analysis engine events relating to a monitored network; analysing the received events to identify at least one event that meets a case creation condition and, in response, creating a case in an experience database, the case being populated with data of the identified at least one event; assigning a threat score to the created case based on the event data; matching at least one further event to the created case and populating the case with data of the at least one further event, the threat score assigned to that case being updated in response; and in response to the threat score for one of the cases meeting a significance condition, rendering that case accessible via a case interface.


