Connected Security System for Multi-Domain Threat Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems lack effective methods to detect and respond to multi-domain, multi-step attacks across information technology (IT) and operational technology (OT) networks, which can lead to undetected malicious activity and inadequate protection of assets in industrial control systems.

Innovation Solution

A connected security system utilizing an event management module, threat intelligence module, and course of action module that processes and correlates data from both IT and OT domains using a standardized data structure like STIX, identifies malicious activity, enriches data with external sources, and implements courses of action to mitigate threats, including visualization tools for security administrators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security systems monitor only single domain activity, then detection simplicity is maintained, but detection capability against multi-domain attacks is insufficient

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments security monitoring into separate domain-specific modules (IT domain module, OT domain module, ICS domain module) that each handle specific domain data independently, then combines their outputs through a correlation engine. This allows comprehensive multi-domain detection while maintaining manageable module-level complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A correlation engine acts as an intermediary between domain-specific security modules and the central analysis system. This intermediary standardizes and correlates data from multiple domains using predefined relationships and patterns, enabling complex multi-domain attack detection without requiring direct complex integration between all domain modules.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive data collection from multiple domains is implemented, then detection accuracy improves, but data processing time increases

Engineering Contradiction:
Improvedetection accuracyVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-defining correlation patterns, relationships, and attack scenarios before actual security events occur. Domain-specific modules pre-process and normalize data according to predefined schemas, enabling faster real-time correlation and analysis when security events actually occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Different domain modules apply domain-specific processing qualities and rules appropriate to their data types. IT domain data receives different processing treatment than OT or ICS domain data, optimizing each processing pipeline for its specific data characteristics while maintaining overall system efficiency.

Inventive Principle:
Principle #3Local quality

3Speed

If automated response actions are implemented, then response speed improves, but risk of inappropriate actions increases

Engineering Contradiction:
Improveresponse speedVSAvoidaction appropriateness
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The response system dynamically adjusts between fully automated, semi-automated, and manual response modes based on threat severity, confidence levels, and pre-configured policies. Low-confidence or low-severity events may trigger automated responses, while high-severity events require human approval, creating a flexible adaptive response mechanism.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops where response actions are monitored and evaluated. Outcomes of automated responses are fed back into the learning system to improve future decision-making, and security administrators can adjust automation policies based on observed performance, balancing speed and appropriateness over time.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10944772B2Connected security system
Publication Date: 2021.03.09 ACCENTURE GLOBAL SOLUTIONS LTD
  • US10944772B2 patent drawing
  • US10944772B2 patent drawing
  • US10944772B2 patent drawing

AI summary

Systems, methods, and apparatus, including computer programs encoded on computer storage media, for obtaining, processing, and presenting data related to security events, and for implementing courses of action to protect assets in response to the security events. An event management module identifies malicious activity present on a first network domain and/or a second network domain based on received network domain activity. A threat intelligence module receives data identifying the malicious activity in first data constructs of a predefined data structure. The threat intelligence module obtains additional data related to the identified malicious activity and generates second data constructs that include enriched data regarding the malicious activity. The enriched data includes data describing a campaign in which at least a portion of the malicious activity is involved and one or more courses of action. A course of action module receives the second data constructs and implements a given course of action.