Cyber Adversary Behavior Identification via Threat Intelligence Framework

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security solutions are inadequate in protecting against advanced persistent threats, as they either focus on known attacks or identifying malicious behavior, failing to effectively counter sophisticated and evolving cyber adversary techniques.

Innovation Solution

A computer-implemented method that receives individual security events from multiple threat intelligence data sources, matches security incidents to defined cyber adversary objectives and techniques within a structured framework, and performs mitigation actions based on this mapping to identify and counter cyber adversary behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anti-virus and firewall solutions are used, then protection against known attacks is improved, but effectiveness against advanced persistent threats deteriorates

Engineering Contradiction:
Improveprotection effectivenessVSAvoidability to counter sophisticated attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts its detection and response mechanisms based on the sophistication and type of threat detected. It transitions from static rule-based detection to dynamic behavior analysis, adjusting its security posture in real-time to match the evolving nature of advanced persistent threats while maintaining protection against known attacks.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameters of security monitoring from simple signature matching to multi-dimensional analysis including behavior patterns, threat intelligence indicators, and contextual risk assessment. This parameter transformation enables the system to detect both known attacks and sophisticated advanced persistent threats using the same infrastructure.

Inventive Principle:
Principle #35Parameter changes

2Difficulty of detecting and measuring

If security monitoring is enhanced to detect sophisticated attacks, then detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The system introduces threat intelligence data and structured frameworks as intermediary layers between raw security events and detection logic. These intermediaries translate complex threat patterns into standardized indicators that can be processed by existing security infrastructure, enhancing detection capability without proportionally increasing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security monitoring system is segmented into modular components: event collection, threat intelligence integration, behavior analysis, and response execution. Each module handles specific aspects of sophisticated attack detection independently, allowing the system to achieve high detection capability while maintaining manageable complexity through clear separation of concerns.

Inventive Principle:
Principle #1Segmentation

3Speed

If real-time threat analysis is implemented, then response speed is improved, but computational resource consumption increases

Engineering Contradiction:
Improveresponse speedVSAvoidcomputational resource consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system applies partial analysis to most events and excessive (full) analysis only to suspicious events. It performs lightweight initial screening on all security events and escalates to computationally intensive behavior analysis only when indicators suggest potential advanced persistent threats, achieving fast response times while controlling overall resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system maintains continuous low-level monitoring and threat intelligence updates while performing intensive analysis only when needed. This continuous passive monitoring ensures rapid response capability without the constant computational overhead of full real-time analysis, balancing speed and resource consumption.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11228612B2Identifying cyber adversary behavior
Publication Date: 2022.01.18 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11228612B2 patent drawing
  • US11228612B2 patent drawing
  • US11228612B2 patent drawing

AI summary

Identifying cyber adversary behavior on a computer network is provided. Individual security events are received from multiple threat intelligence data sources. A security incident corresponding to an attack on at least one element of the computer network, the security incident being described by the individual security events received from the multiple threat intelligence data sources, is matched to a defined cyber adversary objective in a structured framework of a plurality of defined cyber adversary objectives and a related technique associated with the defined cyber adversary objective used by a cyber adversary in the attack. A set of mitigation actions is performed on the computer network based on matching the security incident corresponding to the attack on the computer network to the defined cyber adversary objective and the related technique.