Cyber Event Detection Using Image-Based Neural Network Prediction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems fail to accurately detect unreported cyber events experienced by entities, leading to potential risks and uncertainties for businesses relying on the cyber health of their partners or suppliers, as these entities may not truthfully report cyber incidents.
Innovation Solution
A computer-implemented method using a neural network trained on historical cybersecurity data, transforming this data into images, and utilizing technical indicators to predict both reported and unreported cyber events by comparing predicted and reported numbers, enabling real-time detection and assessment of cyber health.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If entities report cyber events truthfully, then information accuracy is improved, but entities may suffer reputational damage and loss of business confidence
Solution Approach 1:
The patent introduces an intermediary system (the prediction model and analysis platform) that mediates between cyber event occurrence and entity reporting. This intermediary uses machine learning to predict expected report counts and compares them against actual reports, thereby inferring unreported events without directly exposing entities to reputational damage from disclosure.
Solution Approach 2:
The system implements feedback mechanisms by continuously comparing predicted cyber event counts against actual reported counts. This feedback loop enables the system to detect discrepancies indicating unreported events, allowing for proactive risk assessment without forcing entities to disclose their cyber event histories.
2Object-affected harmful factors
If entities do not report cyber events, then reputational damage is avoided, but detection accuracy of cyber health deteriorates
Solution Approach 1:
The patent replaces traditional mechanical reporting systems with an intelligent prediction system based on machine learning models. Instead of relying on entities to mechanically report all cyber events, the system uses neural networks to predict expected event counts and detect discrepancies, thereby maintaining detection accuracy without requiring truthful reporting.
Solution Approach 2:
The system enables self-service detection by automatically analyzing cyber health without requiring active participation or truthful disclosure from entities. The prediction model independently assesses cyber event likelihoods and compares them against reported data, allowing the system to self-detect unreported events without entity cooperation.
3Ease of operation
If reliance on entity reporting is increased, then operational simplicity is improved, but risk management effectiveness deteriorates
Solution Approach 1:
The patent applies preliminary action by using machine learning models to predict expected cyber event counts before actual reporting occurs. The system proactively identifies potential unreported events by comparing predictions against actual reports, thereby enhancing risk management effectiveness while maintaining operational simplicity through automated analysis.
Solution Approach 2:
The system achieves multi-functionality by serving multiple purposes: predicting cyber event counts, detecting unreported events, assessing cyber health, and providing risk management insights. This universal approach enhances risk management effectiveness while maintaining ease of operation through a single integrated platform that performs multiple functions simultaneously.
Data Source
AI summary
Systems and methods for detection of unreported cyber events experienced by an entity of interest include a server, processors, or software employing a machine learning algorithm having been trained on cybersecurity data for a plurality of entities, wherein each entity is a company or an organization. The cybersecurity data is provided by having been transformed into a plurality of images that convey the cybersecurity data for the plurality of entities. The machine learning algorithm is used for generating a predicted number of cyber events experienced by the entity of interest. A reported number of cyber events experienced by the entity of interest is monitored and compared to the predicted number of cyber events experienced by the entity of interest. Based on this comparison, a predicted unreported number of cyber events experienced by the entity of interest is generated.


