Cyber Clone for Zero-Day Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber-attack detection solutions are largely signature-based, requiring human intervention to collect and analyze attack data, leading to significant delays in detecting and preventing zero-day attacks.

Innovation Solution

A cyber clone of a computing entity is created, comprising a processor and memory that stores a plurality of states and associated recorded requests and responses. The cyber clone receives external requests, determines indicators of attack, and responds by matching recorded responses or providing deceiving or live responses, thereby maintaining interaction with attackers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If signature-based detection is used, then known attacks can be detected, but detection of zero-day attacks is delayed due to human intervention

Engineering Contradiction:
Improveattack detection accuracyVSAvoiddetection delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically collecting, analyzing, and generating detection signatures from attack data before human intervention is needed. The automated signature generation is prepared in advance, allowing immediate detection of zero-day attacks as soon as attack patterns are observed, eliminating the time delay between attack occurrence and detection capability establishment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by implementing automated processes that collect attack data, analyze patterns, and generate detection signatures without requiring human intervention. The automated signature generation system serves itself by continuously learning from new attacks and updating detection rules, thereby reducing both time loss and dependency on manual analysis while maintaining high reliability in detecting both known and zero-day attacks.

Inventive Principle:
Principle #25Self-service

2Productivity

If automated signature generation is implemented, then detection speed improves, but system complexity increases

Engineering Contradiction:
Improvedetection speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system achieves universality by designing a multi-functional automated signature generation platform that performs multiple tasks: collecting attack data from various sources, analyzing attack patterns, generating detection signatures, and updating detection rules. This single system handles the entire detection pipeline, improving productivity across all detection activities while managing complexity through integrated design rather than separate specialized systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces an intermediary automated signature generation layer between raw attack data and detection operations. This intermediary component processes and transforms attack data into usable detection signatures, thereby improving detection speed without directly complicating the core detection infrastructure. The intermediary handles the complexity of pattern analysis and signature formulation, allowing the detection system to operate efficiently with standardized inputs and outputs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12284211B2Cyber clone of a computing entity
Publication Date: 2025.04.22 ADVANCED SECURITY TECH ASIA PTE LTD
  • US12284211B2 patent drawing
  • US12284211B2 patent drawing
  • US12284211B2 patent drawing

AI summary

A cyber clone of a computing entity stores a request received at the computing entity and a response sent from the computing entity. An external request from an attacker is compared with the recorded request. In response to a match the associated recorded response is sent to the attacker. In response to the external request not matching the recorded request, a false, deceiving response is provided. Alternatively the external request is forwarded to the computing entity, and a live response is forwarded to the attacker. The external request and live response for the current state are optionally stored.