Cyber Attack Counteraction System Using Service-Device Data Clustering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems fail to effectively prevent data leakage from online services, leading to subsequent cyber attacks on users' devices, such as intrusive calls, spam emails, and phishing links, as they cannot comprehensively counter targeted attacks across different hardware and software platforms.

Innovation Solution

A computer-implemented method and system that collects service and device data to detect data breaches and cyber attacks, identifies attack vectors, and determines counteractions, which are then transmitted to affected devices, using heuristic rules and user feedback to enhance security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security systems focus on preventing data leakage from online services, then data breach prevention is improved, but subsequent cyber attacks on users' devices cannot be effectively countered

Engineering Contradiction:
Improvedata breach preventionVSAvoidcross-platform attack countermeasure capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security system is designed to perform multiple functions: detecting data breaches at online services, identifying subsequent cyber attacks on user devices, determining attack vectors, and transmitting countermeasures across different platforms. This multi-functional approach allows the system to address both data breach prevention and cross-platform attack countermeasures through a unified security infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements a feedback mechanism where information about data breaches and cyber attacks is continuously collected from multiple sources, analyzed to identify attack vectors, and used to generate and transmit updated countermeasures to user devices. This closed-loop feedback enables the system to adapt and improve its protective capabilities based on emerging threats.

Inventive Principle:
Principle #23Feedback

2Reliability

If security systems are designed to counter targeted attacks on specific services, then service-specific security is improved, but attacks on user devices through leaked data cannot be prevented

Engineering Contradiction:
Improveservice-specific attack detectionVSAvoiddevice-level cyber attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system merges service-level security monitoring with device-level attack detection by integrating data collection from both online services and user devices. This combination allows the system to trace the connection between data breaches at services and subsequent attacks on devices, enabling comprehensive security coverage that addresses both layers of the attack chain.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system transitions from a single-dimension service-focused security approach to a multi-dimensional approach that encompasses both service infrastructure and end-user devices. By adding the device dimension to security monitoring and response, the system can identify attack vectors that originate from service breaches and manifest as attacks on user devices across multiple platforms.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If comprehensive data collection is performed to identify attack vectors, then attack detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveattack vector identification accuracyVSAvoidsecurity system architecture
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The security system is segmented into distinct functional modules: data collection from services and devices, breach detection, attack identification, vector determination, and countermeasure transmission. This segmentation allows each module to focus on specific tasks, improving attack vector identification accuracy while managing system complexity through modular architecture that can be implemented and maintained independently.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11546371B2System and method for determining actions to counter a cyber attack on computing devices based on attack vectors
Publication Date: 2023.01.03 AO KASPERSKY LAB
  • US11546371B2 patent drawing
  • US11546371B2 patent drawing
  • US11546371B2 patent drawing

AI summary

Disclosed are systems and methods for countering a cyber-attack on computing devices by means of which users are interacting with services, which store personal data on the users. Data is collected about the services with which the users are interacting by means of the devices, as well as data about the devices themselves. The collected data is analyzed to detect when a cyber-attack on the devices is occurring as a result of a data breach of personal data on users from the online service. A cluster of the computing devices of different users of the online service experiencing the same cyber attack is identified. Attack vectors are identified based on the characteristics of the cyber attack experienced by the computing devices in the cluster. Actions are selected for countering the cyber-attack based on the identified attack vector and are sent to the devices of all users of the corresponding cluster.