Cyber-Attack Detection via ML Segmentation and Reinforcement Learning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting cyber-attacks on networks are inefficient due to their reliance on manual analysis, high false positive rates, and inability to differentiate between natural and adversarial behavior, leading to delayed detection and limited scalability.

Innovation Solution

A system utilizing machine learning for network segmentation, behavioral modeling, and reinforcement learning to detect and identify cyber-attacks, providing real-time alerts and feedback to improve detection accuracy, while minimizing human intervention and model bias.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual analysis techniques are used to detect cyber-attacks, then detection accuracy can be maintained with available resources, but detection speed is too slow and cannot scale with the shortage of cyber talent

Engineering Contradiction:
Improvedetection speedVSAvoiddetection accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent replaces manual mechanical analysis with automated machine learning systems. The ML model automatically segments networks, scores data points for anomalous behavior, and performs behavioral modeling without human intervention, thereby increasing detection speed while maintaining accuracy through algorithmic consistency.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system implements self-service through automated feedback loops where detection results and analyst assessments continuously train and improve the ML model. The system serves itself by automatically learning from new data and adapting to evolving threats without requiring manual reconfiguration or extensive human expertise.

Inventive Principle:
Principle #25Self-service

2Productivity

If Machine Learning/AI techniques are incorporated into cyber security products, then automation and detection speed improve, but false positive rates increase significantly

Engineering Contradiction:
Improveautomation levelVSAvoidfalse positive rate
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies segmentation by dividing the network into multiple segments and analyzing data points within each segment context. This localized analysis reduces false positives by understanding normal behavior patterns specific to each segment rather than applying blanket rules across the entire network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically changes parameters by continuously adjusting scoring thresholds and behavioral models based on feedback from analyst assessments and new threat data. This adaptability allows the system to maintain high automation while reducing false positives by learning from actual operational performance.

Inventive Principle:
Principle #35Parameter changes

3Loss of time

If batch training or pre-training of cyber security models is performed, then initial model deployment is faster, but the models become outdated quickly due to rapid advancement in cyber threats

Engineering Contradiction:
Improvemodel deployment timeVSAvoidmodel currency
Core Design Contradiction:
Loss of timeVSAdaptability or versatility

Solution Approach 1:

The patent implements continuous learning through feedback loops where analyst assessments and new threat data continuously train the ML model in real-time. This continuous action ensures the model remains current with evolving threats rather than becoming outdated between batch training cycles.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system incorporates feedback mechanisms where analyst assessments of detection accuracy and new threat intelligence continuously feed back into the ML model. This feedback loop enables the model to adapt and update its behavioral models continuously, maintaining relevance against rapidly evolving cyber threats.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10931706B2System and method for detecting and identifying a cyber-attack on a network
Publication Date: 2021.02.23 BOOZ ALLEN HAMILTON INC
  • US10931706B2 patent drawing
  • US10931706B2 patent drawing

AI summary

A method for detecting and/or identifying a cyber-attack on a network can include segmenting the network using a segmentation method with machine learning to generate one or more network segments; assigning a score to a data point within each network segment based on a presence or absence of an identified anomalous behavior of the data point; analyzing network data flow, via behavioral modeling, to provide a context for characterizing the anomalous behavior; combining, via a reinforcement learning agent, outputs of the segmentation method with behavioral modelling and assigned score to detect and/or identify a cyber-attack; providing one or more alerts to an analyst; receiving an analyst assessment of an effectiveness of the detection and/or identification; and providing the analyst assessment as feedback to the reinforcement learning agent.