Cyber Attack Prediction via Composite Signal Aggregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems face challenges in efficiently predicting and characterizing cyber attacks, often overwhelming human security personnel with disparate signals, leading to delayed and inaccurate responses due to the need for manual analysis of numerous alerts.

Innovation Solution

A method that aggregates and correlates signals from various sources based on asset identification tags, calculates composite risk scores, and automatically generates alerts and responses when thresholds are exceeded, reducing the burden on personnel and enhancing response times.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple signals from various sources are monitored and analyzed, then threat detection capability is improved, but the complexity of signal processing and manual analysis increases

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsignal processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple disparate security signals into unified composite alerts by aggregating signals related to the same asset or threat campaign. This merging process reduces the number of individual signals that require manual analysis while preserving comprehensive threat detection capability across multiple signal sources.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system introduces an intermediary processing layer that automatically correlates and aggregates signals before presenting them to human analysts. This intermediary layer processes raw signals through correlation rules and aggregation logic, transforming complex multi-source data into simplified composite alerts that maintain detection effectiveness.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all security signals are presented to human personnel for analysis, then comprehensive threat coverage is improved, but response time deteriorates due to manual analysis requirements

Engineering Contradiction:
Improvethreat coverageVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary aggregation and correlation of signals before human analysis is required. By pre-processing signals to identify related groups and calculate composite risk scores, the system reduces the time human personnel need to spend on initial signal triage while maintaining comprehensive threat coverage through automated signal relationships identification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service threat analysis through automated signal aggregation and composite alert generation. The automated system independently correlates signals, identifies threat patterns, and presents consolidated alerts, reducing reliance on manual analysis for routine signal processing while preserving comprehensive threat detection.

Inventive Principle:
Principle #25Self-service

3Productivity

If signals are aggregated and correlated automatically, then response speed is improved, but the complexity of the aggregation system increases

Engineering Contradiction:
Improveresponse speedVSAvoidaggregation system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The aggregation system is segmented into modular components including signal reception modules, correlation rule engines, aggregation logic, and alert generation modules. This segmentation allows the complex aggregation function to be implemented as independent, manageable components that can be configured and maintained separately, reducing overall system complexity while maintaining high response speed.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10949534B2Method for predicting and characterizing cyber attacks
Publication Date: 2021.03.16 SUMO LOGIC INC
  • US10949534B2 patent drawing
  • US10949534B2 patent drawing
  • US10949534B2 patent drawing

AI summary

One variation of a method for predicting and characterizing cyber attacks includes: receiving, from a sensor implementing deep packet inspection to detect anomalous behaviors on the network, a first signal specifying a first anomalous behavior of a first asset on the network at a first time; representing the first signal in a first vector representing frequencies of anomalous behaviors—in a set of behavior types—of the first asset within a first time window; calculating a first malicious score representing proximity of the first vector to malicious vectors defining sets of behaviors representative of security threats; calculating a first benign score representing proximity of the first vector to a benign vector representing an innocuous set of behaviors; and in response to the first malicious score exceeding the first benign score and a malicious threshold score, issuing a first alert to investigate the network for a security threat.