Configurable Cyber-Attack Trackers for Threat Data Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Monitoring and analyzing cyber-attack signals in a high-volume data environment to identify targeted attacks and compromises efficiently is challenging for security personnel, as existing systems struggle to filter relevant information and take timely remedial actions amidst a deluge of data.

Innovation Solution

A computing system with a processor and memory that provides a user interface module for generating and executing trackers, allowing security administrators to select threat parameters and values, access a threat data store, and automatically identify and remediate cyber-attacks by filtering and aggregating threat information, enabling intent-driven analysis and notification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security personnel manually monitor and analyze cyber-attack signals in high-volume data environments, then they can identify targeted attacks and compromises, but the process becomes inefficient and time-consuming amidst a deluge of data

Engineering Contradiction:
Improvethreat identification accuracyVSAvoidthreat analysis efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent introduces an automated tracker system as an intermediary between the threat data store and security personnel. The tracker automatically queries, filters, and aggregates threat signals according to defined parameters, producing curated results that security personnel can analyze. This mediator handles the volume and filtering work, allowing human analysts to focus on interpretation and response while maintaining high identification accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If existing systems attempt to filter and analyze all threat data, then comprehensive security monitoring is achieved, but the system complexity and computational resources required increase significantly

Engineering Contradiction:
Improvesecurity monitoring coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the threat monitoring function into distinct components: a tracker definition module that specifies query parameters, a threat data store that organizes signals, and an execution engine that processes queries. This segmentation allows the system to handle comprehensive monitoring through modular, manageable components rather than a monolithic complex system, reducing overall system complexity while maintaining reliable coverage.

Inventive Principle:
Principle #1Segmentation

3Reliability

If security personnel review all raw threat data to ensure no attacks are missed, then detection completeness is improved, but the time required for remedial action increases

Engineering Contradiction:
Improvedetection completenessVSAvoidremedial action time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-defining tracker parameters and query criteria before threat analysis begins. The system is configured in advance with specific threat parameters, data sources, and aggregation rules. When threats occur, the pre-configured tracker immediately executes the defined queries and filters, eliminating the need for security personnel to manually configure analysis parameters during incident response, thus reducing remedial action time while maintaining detection completeness.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11856009B2Configurable cyber-attack trackers
Publication Date: 2023.12.26 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11856009B2 patent drawing
  • US11856009B2 patent drawing
  • US11856009B2 patent drawing

AI summary

A computing system includes a processor and memory coupled to the processor and storing instructions that, when executed by the processor provide a user interface module. The user interface module is configured to generate a tracker definition user interface having a threat parameter selection user interface element configured to receive a selection of at least one threat parameter, the tracker definition user interface also having a threat value user interface element configured to receive input specifying a threat value to match for the specified at least one threat parameter. The processor is configured to save a tracker based on the selection of at least one threat parameter and the threat value, and wherein the processor is configured to access a threat data store and execute the tracker against the threat data store to provide a tracker result.