Complex Application Attack Detection Using AI Learning Loops

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing software and web application security mechanisms fail to detect and prevent complex attacks, particularly those targeting business logic flaws, due to their reliance on syntactic code analysis and the impracticality of manual security testing, leading to vulnerabilities in software and web applications.

Innovation Solution

Implement an intelligent learning loop using artificial intelligence to create an ontology-based knowledge base from application request and response sequences, applying stochastic probabilistic measures for real-time prediction of malicious user actions and detecting anomalies through a Markov Logic Network (MLN) to protect against complex application attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If syntactic code analysis and manual security testing are used, then existing security mechanisms can operate with current methods, but they fail to detect complex attacks targeting business logic flaws

Engineering Contradiction:
Improvedetection capabilityVSAvoidability to detect complex attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces traditional syntactic code analysis and manual testing mechanisms with an AI-based semantic analysis system. The intelligent learning loop uses machine learning models to analyze application behavior, request sequences, and response patterns, enabling detection of complex business logic attacks that syntactic methods cannot identify.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The security system implements self-service through automated learning and adaptation. The intelligent learning loop continuously learns from application behavior patterns, automatically updates detection models, and generates test cases without human intervention, enabling the system to adapt to new attack types and business logic complexities autonomously.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If manual security testing is performed to validate attack surfaces, then comprehensive validation is possible, but it becomes impractical for complex applications

Engineering Contradiction:
Improvevalidation comprehensivenessVSAvoidtesting efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system performs preliminary action by pre-generating comprehensive test cases and attack scenarios through the intelligent learning loop before actual security testing. The AI model prepares validated test sequences, predicted attack paths, and potential vulnerability scenarios in advance, enabling efficient execution without manual intervention during the actual testing phase.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies parameter changes by transforming the testing approach from manual, step-by-step validation to automated, parameter-driven testing. The system varies test parameters such as request sequences, input data patterns, and user behavior models to comprehensively validate attack surfaces, achieving both precision and productivity through systematic parameter exploration.

Inventive Principle:
Principle #35Parameter changes

3Ease of manufacture

If traditional security mechanisms are used, then implementation is straightforward, but they cannot protect against business logic-based attacks, privilege escalation, and session hijacking

Engineering Contradiction:
Improveimplementation simplicityVSAvoidprotection effectiveness
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent introduces an intermediary layer between the application and users through the intelligent learning loop and AI-based analysis system. This intermediary monitors, analyzes, and validates user interactions, requests, and responses, providing protection against complex attacks while maintaining ease of implementation by integrating as a separate module rather than requiring fundamental application changes.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If stochastic probabilistic measures and Markov Logic Networks are implemented for real-time prediction, then malicious user actions can be detected, but system complexity increases

Engineering Contradiction:
Improveattack prediction accuracyVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the complex AI system into modular components: the intelligent learning loop for data collection, the Markov Logic Network for probabilistic reasoning, and the detection engine for real-time analysis. Each module handles specific functions independently, making the overall complex system manageable, maintainable, and implementable through standardized interfaces.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12380374B2Complex application attack quantification, testing, detection and prevention
Publication Date: 2025.08.05 IVANTI INC
  • US12380374B2 patent drawing
  • US12380374B2 patent drawing
  • US12380374B2 patent drawing

AI summary

An apparatus and method for cyber risk quantification calculated from the likelihood of a cyber-attack on the target enterprise and/or cyber ecosystem based on its security posture. The cyber-attack likelihood can be derived as a probability-based time-to-event (TTE) measure using survivor function analysis. The likelihood probability measure can also be passed to cyber risk frameworks to determine financial impacts of the cyber-attacks. Embodiments of the present invention also relate to an apparatus and method {1) to identify and validate application attack surfaces and protect web applications against business logic-based attacks, sensitive data leakage and privilege escalation attacks; and/or {2) that protects web applications against business logic-based attacks, sensitive data leakage and privilege escalation attacks. This can include implementing an intelligent learning loop using artificial intelligence that creates an ontology-based knowledge base from application request and response sequences. Stochastic probabilistic measures are preferably applied to a knowledge base for predicting malicious user actions in real time.