Case-Based Cyber Defense for Unknown Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber defense technologies rely on single observations with high confidence for threat detection, which is inadequate for unknown threats, and lack integration of network and endpoint data, leading to blind spots and over-reporting.

Innovation Solution

A cyber defense platform that integrates network and endpoint data, using case-based analysis to associate events with common features, score cases, and render significant threats via a user interface, employing machine learning and real-time analytics to link and enhance events.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If single observations with high confidence are used for threat detection, then false positives are reduced, but detection capability for unknown threats is insufficient

Engineering Contradiction:
Improvethreat detection accuracyVSAvoiddetection capability for unknown threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent combines multiple low-confidence observations into a unified case structure that aggregates evidence from multiple sources (network events, endpoint events, threat intelligence). By merging these observations and applying collective scoring, the system achieves reliable detection of unknown threats that would not be detectable through single observations alone.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a temporal dimension by collecting observations over time and a contextual dimension by enriching events with additional information (threat intelligence, entity relationships). This multi-dimensional approach allows the system to build confidence in threat detection through accumulated evidence rather than relying on single-point observations.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If network and endpoint data are integrated, then comprehensive threat detection is achieved, but system complexity increases

Engineering Contradiction:
Improvethreat detection comprehensivenessVSAvoiddata integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex integrated system into distinct modular components: event collectors (network and endpoint), event normalization module, case builder, scoring engine, and response orchestration. Each component handles specific tasks independently, making the overall complex system manageable and maintainable while achieving comprehensive threat detection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an event normalization layer as an intermediary that standardizes data from diverse network and endpoint sources into a common format. This mediator component simplifies integration by handling data format variations and providing a unified interface for subsequent analysis, reducing the complexity of direct integration between heterogeneous systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple observations are associated into cases, then detection of unknown threats improves, but processing time increases

Engineering Contradiction:
Improveunknown threat detectionVSAvoidthreat analysis time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent applies partial action by initially creating cases with available evidence and continuously enriching them as additional observations become available. Rather than waiting for complete information before initiating analysis, the system begins threat assessment with partial data and incrementally adds more observations, reducing overall processing time while maintaining detection accuracy.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent performs preliminary actions by pre-establishing case structures, scoring models, and association rules before threat detection is needed. Event templates and correlation rules are configured in advance, allowing the system to rapidly process and associate observations into cases without performing complex analysis from scratch for each threat event.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250294035A1Cyber defense system
Publication Date: 2025.09.18 SENSEON TECH LTD
  • US20250294035A1 patent drawing
  • US20250294035A1 patent drawing
  • US20250294035A1 patent drawing

AI summary

In one aspect, a computer-implemented method of detecting network security threats comprises the following steps: receiving at an analysis engine events relating to a monitored network; analysing the received events to identify at least one event that meets a case creation condition and, in response, creating a case in an experience database, the case being populated with data of the identified at least one event; assigning a threat score to the created case based on the event data; matching at least one further event to the created case and populating the case with data of the at least one further event, the threat score assigned to that case being updated in response; and in response to the threat score for one of the cases meeting a significance condition, rendering that case accessible via a case interface.