Connected Security System for Multi-Domain Threat Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security systems lack effective methods to detect and respond to multi-domain, multi-step attacks across information technology (IT) and operational technology (OT) networks, which can lead to undetected malicious activity and inadequate protection of assets in industrial control systems.
Innovation Solution
A connected security system utilizing an event management module, threat intelligence module, and course of action module that processes and correlates data from both IT and OT domains using a standardized data structure like STIX, identifies malicious activity, enriches data with external sources, and implements courses of action to mitigate threats, including visualization tools for security administrators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If security systems monitor only single domain activity, then detection simplicity is maintained, but detection capability against multi-domain attacks is insufficient
Solution Approach 1:
The system segments security monitoring into separate domain-specific modules (IT domain module, OT domain module, ICS domain module) that each handle specific domain data independently, then combines their outputs through a correlation engine. This allows comprehensive multi-domain detection while maintaining manageable module-level complexity.
Solution Approach 2:
A correlation engine acts as an intermediary between domain-specific security modules and the central analysis system. This intermediary standardizes and correlates data from multiple domains using predefined relationships and patterns, enabling complex multi-domain attack detection without requiring direct complex integration between all domain modules.
2Measurement precision
If comprehensive data collection from multiple domains is implemented, then detection accuracy improves, but data processing time increases
Solution Approach 1:
The system performs preliminary actions by pre-defining correlation patterns, relationships, and attack scenarios before actual security events occur. Domain-specific modules pre-process and normalize data according to predefined schemas, enabling faster real-time correlation and analysis when security events actually occur.
Solution Approach 2:
Different domain modules apply domain-specific processing qualities and rules appropriate to their data types. IT domain data receives different processing treatment than OT or ICS domain data, optimizing each processing pipeline for its specific data characteristics while maintaining overall system efficiency.
3Speed
If automated response actions are implemented, then response speed improves, but risk of inappropriate actions increases
Solution Approach 1:
The response system dynamically adjusts between fully automated, semi-automated, and manual response modes based on threat severity, confidence levels, and pre-configured policies. Low-confidence or low-severity events may trigger automated responses, while high-severity events require human approval, creating a flexible adaptive response mechanism.
Solution Approach 2:
The system incorporates feedback loops where response actions are monitored and evaluated. Outcomes of automated responses are fed back into the learning system to improve future decision-making, and security administrators can adjust automation policies based on observed performance, balancing speed and appropriateness over time.
Data Source
AI summary
Systems, methods, and apparatus, including computer programs encoded on computer storage media, for obtaining, processing, and presenting data related to security events, and for implementing courses of action to protect assets in response to the security events. An event management module identifies malicious activity present on a first network domain and/or a second network domain based on received network domain activity. A threat intelligence module receives data identifying the malicious activity in first data constructs of a predefined data structure. The threat intelligence module obtains additional data related to the identified malicious activity and generates second data constructs that include enriched data regarding the malicious activity. The enriched data includes data describing a campaign in which at least a portion of the malicious activity is involved and one or more courses of action. A course of action module receives the second data constructs and implements a given course of action.


