Cyber-Data Management Node for Automated DDoS Remediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack the capability to automate and orchestrate the remediation of distributed denial of service (DDoS) and other cyber threats across heterogeneous network components through a single, integrated workflow-based action controller, resulting in inefficiencies in threat detection and response.

Innovation Solution

A cyber-data management node (CDMN) is introduced to provide real-time data ingestion, enrichment, and automated response capabilities, enabling the detection of security threats and executing predefined actions to mitigate these threats across network elements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If a single integrated workflow-based action controller is implemented to automate and orchestrate remediation across heterogeneous network components, then the extent of automation and productivity are improved, but the device complexity increases

Engineering Contradiction:
Improveautomation of threat remediationVSAvoidsystem complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The system segments the complex security orchestration function into modular components: a workflow engine that manages automation logic, a controller that coordinates actions across heterogeneous devices, and standardized interfaces that abstract device-specific complexities. This modular architecture enables high-level automation without proportionally increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The workflow-based action controller is designed as a universal platform that can orchestrate remediation across multiple types of network components (firewalls, intrusion detection systems, routers, etc.) through standardized interfaces. This multi-functionality allows a single controller to manage heterogeneous devices without requiring separate specialized systems for each device type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If real-time data ingestion and enrichment are implemented across multiple network sources, then the measurement precision and reliability of threat detection are improved, but the use of energy and processing resources increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidprocessing resources
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary data enrichment and normalization at the point of data ingestion, before analysis. By pre-processing data from multiple network sources (adding context, normalizing formats, enriching with threat intelligence) at the source, the system reduces the processing burden on downstream analytical components, achieving high detection accuracy without proportionally increasing overall energy consumption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies different levels of data enrichment and processing to different data sources based on their specific characteristics and relevance. High-priority or high-volume data sources receive optimized processing tailored to their specific format and importance, rather than applying uniform heavy processing to all sources, thus improving detection precision while managing resource consumption.

Inventive Principle:
Principle #3Local quality

3Speed

If automated response actions are executed without human intervention, then the speed of response and productivity are improved, but the reliability may be reduced due to lack of human judgment

Engineering Contradiction:
Improveresponse speedVSAvoidresponse accuracy
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The automated response system incorporates feedback loops where the results of automated actions are monitored and evaluated. The system learns from the outcomes of automated responses and adjusts its decision-making logic accordingly. This feedback mechanism enables the system to maintain high response speeds while improving reliability over time through continuous learning and adaptation, effectively compensating for the lack of human judgment.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11985160B2Dynamic adaptive defense for cyber-security threats
Publication Date: 2024.05.14 MAGENTA SECURITY HOLDINGS LLC
  • US11985160B2 patent drawing
  • US11985160B2 patent drawing
  • US11985160B2 patent drawing

AI summary

Disclosed is a cyber-security system that is configured to aggregate and unify data from multiple components and platforms on a network. The system allows security administrators to design and implement a workflow of device-actions taken by security individuals in response to a security incident. Based on the nature of a particular threat, the cyber-security system may initiate an action plan that is tailored to the security operations center and their operating procedures to protect potentially impacted components and network resources.