Cyber Behavioral Exchange for Threat Intelligence Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems face challenges in simulating comprehensive network scenarios and sharing information effectively among organizations to address the growing complexity and volume of cyber threats, leading to inefficiencies in manpower utilization and defensive capabilities.

Innovation Solution

A cybersecurity system incorporating a cyber behavioral space management module, interaction engine, analytic workflow engine, and visualization engine to compute and predict cyber behaviors, facilitate interactions between cyber actors, and share risk information securely across organizations using privacy-preserving distributed machine learning algorithms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional information sharing practices are used, then organizations can share cybersecurity data through policies and frameworks, but the volume and speed of attacks cannot be handled effectively

Engineering Contradiction:
Improveinformation sharing effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a cyber behavioral exchange as an intermediary system that enables automated sharing of cyber behavioral data between organizations. This mediator processes and standardizes information exchange, allowing organizations to share threat intelligence at scale without manual intervention, thus handling the volume and speed of attacks effectively while maintaining manageable system complexity through standardized protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system transforms cybersecurity information sharing by changing key parameters: transitioning from manual, policy-based sharing to automated, data-driven exchange; from fragmented information to standardized cyber behavioral data with consistent schemas; and from slow, batch processing to real-time or near-real-time information flow. These parameter changes enable the system to handle attack volume and speed while improving sharing effectiveness

Inventive Principle:
Principle #35Parameter changes

2Productivity

If companies work independently on cybersecurity, then each organization maintains its own defensive capabilities, but manpower cannot be fully leveraged across networks

Engineering Contradiction:
Improvemanpower utilizationVSAvoidinformation silos
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent merges defensive capabilities across multiple organizations by enabling them to participate in a shared cyber behavioral exchange system. Organizations combine their cyber behavioral data, threat intelligence, and defensive strategies into a collective knowledge base, allowing manpower and expertise to be leveraged across networks rather than remaining isolated. This merging eliminates information silos while maintaining each organization's operational independence

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The cyber behavioral exchange system provides universal functionality that serves multiple organizations simultaneously. A single data point or threat intelligence finding entered by one organization becomes available to all participants, maximizing the utility of each organization's defensive efforts and manpower. The system handles diverse data types and organizational needs through a unified platform, enabling full leverage of available resources across the cybersecurity ecosystem

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If traditional cybersecurity exercises are used, then defenders can play against each other, but not all possible scenarios are covered

Engineering Contradiction:
Improvescenario coverageVSAvoidtime to cover all scenarios
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-collecting and analyzing cyber behavioral data from multiple sources before actual cyber incidents occur. Organizations contribute historical behavioral patterns, threat actor methodologies, and attack signatures to the exchange, which are processed and stored as ready-to-use scenario templates. When a real incident occurs, these pre-prepared scenarios can be immediately applied and tested, covering a comprehensive range of possible attack vectors without requiring time-consuming ad hoc analysis

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The cyber behavioral exchange enables continuous collection, analysis, and refinement of cyber scenario data. Rather than periodic exercises, the system operates continuously, constantly updating the library of possible scenarios based on new threat intelligence, emerging attack patterns, and lessons learned from actual incidents. This continuous action ensures comprehensive scenario coverage keeps pace with the evolving threat landscape without significant time loss

Inventive Principle:
Principle #20Continuity of useful action

4Measurement precision

If the entire network is simulated to understand defensive maneuvers, then comprehensive analysis is possible, but it is extremely difficult and manpower intensive

Engineering Contradiction:
Improvedefensive analysis accuracyVSAvoidsimulation complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the complex task of network defense simulation into manageable components through the cyber behavioral exchange system. Instead of simulating the entire network at once, the system divides analysis into discrete behavioral patterns, threat actor types, attack vectors, and defensive responses. Each segment can be independently analyzed, tested, and refined, then integrated into the broader defensive strategy. This segmentation maintains high measurement precision while reducing the overwhelming complexity of full-network simulation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates simplified copies or representations of complex cyber behaviors and threat scenarios. Rather than simulating every detail of actual network infrastructure and traffic, the exchange uses abstracted behavioral models that capture essential attack patterns and defensive responses. These copied behavioral representations allow comprehensive defensive analysis with reduced complexity, maintaining analytical accuracy while making simulations more manageable and less manpower-intensive

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9910993B2Simulation and virtual reality based cyber behavioral systems
Publication Date: 2018.03.06 IRONNET CYBERSECURITY INC
  • US9910993B2 patent drawing
  • US9910993B2 patent drawing
  • US9910993B2 patent drawing

AI summary

A cybersecurity system for managing cyber behavior associated with cyber actors such that the cyber behavior can be computed and predicted and cyber interactions between the cyber actors can be created. The system includes a cyber behavioral space management module configured to receive input data, and data from the interaction engine and the analytic workflow engine, and to generate a plurality of cyber behavioral spaces based on the received data. The system includes an interaction engine configured to process cyber actor data to facilitate interactions with the cyber behavioral space, a cyber scene, a cyber map, and another cyber actor. The system includes an analytic workflow engine configured to analyze the cyber behavioral spaces and update cyber data based on the analyzed data and the interaction engine data. The system includes a visualization engine configured to compute visualizations and transmit the visualizations for display.