Cyber Adversary Behavior Identification via Threat Intelligence Framework
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security solutions are inadequate in protecting against advanced persistent threats, as they either focus on known attacks or identifying malicious behavior, failing to effectively counter sophisticated and evolving cyber adversary techniques.
Innovation Solution
A computer-implemented method that receives individual security events from multiple threat intelligence data sources, matches security incidents to defined cyber adversary objectives and techniques within a structured framework, and performs mitigation actions based on this mapping to identify and counter cyber adversary behavior.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional anti-virus and firewall solutions are used, then protection against known attacks is improved, but effectiveness against advanced persistent threats deteriorates
Solution Approach 1:
The system dynamically adapts its detection and response mechanisms based on the sophistication and type of threat detected. It transitions from static rule-based detection to dynamic behavior analysis, adjusting its security posture in real-time to match the evolving nature of advanced persistent threats while maintaining protection against known attacks.
Solution Approach 2:
The system changes the parameters of security monitoring from simple signature matching to multi-dimensional analysis including behavior patterns, threat intelligence indicators, and contextual risk assessment. This parameter transformation enables the system to detect both known attacks and sophisticated advanced persistent threats using the same infrastructure.
2Difficulty of detecting and measuring
If security monitoring is enhanced to detect sophisticated attacks, then detection capability is improved, but system complexity increases
Solution Approach 1:
The system introduces threat intelligence data and structured frameworks as intermediary layers between raw security events and detection logic. These intermediaries translate complex threat patterns into standardized indicators that can be processed by existing security infrastructure, enhancing detection capability without proportionally increasing system complexity.
Solution Approach 2:
The security monitoring system is segmented into modular components: event collection, threat intelligence integration, behavior analysis, and response execution. Each module handles specific aspects of sophisticated attack detection independently, allowing the system to achieve high detection capability while maintaining manageable complexity through clear separation of concerns.
3Speed
If real-time threat analysis is implemented, then response speed is improved, but computational resource consumption increases
Solution Approach 1:
The system applies partial analysis to most events and excessive (full) analysis only to suspicious events. It performs lightweight initial screening on all security events and escalates to computationally intensive behavior analysis only when indicators suggest potential advanced persistent threats, achieving fast response times while controlling overall resource consumption.
Solution Approach 2:
The system maintains continuous low-level monitoring and threat intelligence updates while performing intensive analysis only when needed. This continuous passive monitoring ensures rapid response capability without the constant computational overhead of full real-time analysis, balancing speed and resource consumption.
Data Source
AI summary
Identifying cyber adversary behavior on a computer network is provided. Individual security events are received from multiple threat intelligence data sources. A security incident corresponding to an attack on at least one element of the computer network, the security incident being described by the individual security events received from the multiple threat intelligence data sources, is matched to a defined cyber adversary objective in a structured framework of a plurality of defined cyber adversary objectives and a related technique associated with the defined cyber adversary objective used by a cyber adversary in the attack. A set of mitigation actions is performed on the computer network based on matching the security incident corresponding to the attack on the computer network to the defined cyber adversary objective and the related technique.


