Forecasting Network Security Incidents Using CGLV Model

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Accurately predicting future security incidents in modern network environments is challenging due to the high number of network devices and potential threats, making it difficult for organizations to plan and mitigate against such incidents, which can result in costly damage.

Innovation Solution

A computer-implemented method using a Coupled Gaussian Latent Variable (CGLV) model to forecast future security incidents by analyzing past inside-in and outside-in security features, employing dynamic time warping to generate similarity scores, and performing security actions on network devices based on the forecasts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security monitoring methods are used to track every potential security incident, then comprehensive security coverage is achieved, but the system complexity and computational resources required become unmanageable due to the high number of network devices and threats

Engineering Contradiction:
Improvesecurity incident detection accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a CGLV model as an intermediary between raw security data and security predictions. This model includes a latent variable that captures the underlying security state, mediating between observed security features and future security incidents. This intermediary structure simplifies the monitoring system by focusing on key latent factors rather than tracking every individual threat across all devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms the security monitoring approach by changing parameters from tracking individual security incidents to modeling temporal dynamics of security features. The CGLV model uses time-series analysis of security features (such as vulnerability counts, patch levels, threat landscape metrics) to predict future security states, shifting from event-based monitoring to parameter-based forecasting.

Inventive Principle:
Principle #35Parameter changes

2Loss of information

If comprehensive monitoring of all network devices is performed, then complete security visibility is achieved, but the time and computational resources required become prohibitively large

Engineering Contradiction:
Improvesecurity information completenessVSAvoidanalysis time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent extracts the essential security information by identifying and modeling key security features that drive future security incidents. Rather than analyzing all security data from all devices, the CGLV model extracts temporal patterns from representative security features (vulnerability metrics, patching rates, threat intelligence) to infer the security state of the entire network, significantly reducing information processing requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

3Measurement precision

If accurate prediction of future security incidents is achieved, then effective security planning and mitigation become possible, but the complexity of the prediction model increases significantly

Engineering Contradiction:
Improvesecurity incident prediction accuracyVSAvoidprediction model complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the security prediction problem into distinct components: observed security features, latent security state variables, and future security incident predictions. The CGLV model separates the temporal dynamics of different security features and their relationships through the latent variable structure, allowing accurate predictions while maintaining model interpretability and manageable complexity through modular computation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10547623B1Security network devices by forecasting future security incidents for a network based on past security incidents
Publication Date: 2020.01.28 GEN DIGITAL INC
  • US10547623B1 patent drawing
  • US10547623B1 patent drawing
  • US10547623B1 patent drawing

AI summary

Securing network devices by forecasting future security incidents for a network based on past security incidents. In one embodiment, a method may include constructing past inside-in security features for a network, constructing past outside-in security features for the network, and employing dynamic time warping to generate a similarity score for each security feature pair in the past inside-in security features, in the past outside-in security features, and between the past inside-in security features and the past outside-in security features. The method may further include generating a Coupled Gaussian Latent Variable (CGLV) model based on the similarity scores, forecasting future inside-in security features for the network using the CGLV model, and performing a security action on one or more network devices of the network based on the forecasted future inside-in security features for the network.