Cyber-Event Tree Analysis for Network Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber-security technologies are insufficient to address the growing complexity and evolution of cyber-attacks, as they often focus on detecting and preventing only a single step or aspect of a cyber-attack, lacking visibility into other critical phases such as persistence and privilege escalation, and fail to capture a comprehensive range of cyber-attack pathways.

Innovation Solution

A method and system involving a meshed network of sensors that monitor cyber-events, link them into cyber-event trees, compare these trees to a baseline, and score their anomaly probability to identify potential cyber-attacks, providing real-time monitoring and self-healing capabilities across node and network levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If current cyber-security technologies (AV, NIDS, Firewalls, etc.) are used, then specific aspects of cyber-attacks can be detected, but comprehensive visibility into all phases of cyber-attacks is lost

Engineering Contradiction:
Improvedetection accuracyVSAvoidvisibility into cyber-attack phases
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent combines multiple sensor types (process sensors, network sensors, registry sensors, WMI sensors, etc.) into a unified monitoring system that collects data from all phases of cyber-attacks. This merging allows the system to detect not only individual attack vectors but also the complete attack chain from initial access through persistence, privilege escalation, and lateral movement.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The monitoring system is designed with multi-functional sensors that can detect various types of cyber-events simultaneously. Each sensor can monitor multiple aspects of system activity (process execution, network connections, registry changes, WMI queries) and the system can adapt to detect different attack phases using the same infrastructure, providing universal coverage across all cyber-attack phases.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Device complexity

If traditional cyber-security technologies focus on single-step detection, then implementation is simpler, but detection of complete cyber-attack pathways is insufficient

Engineering Contradiction:
Improvesystem complexityVSAvoiddetection completeness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The monitoring system is segmented into specialized sensors for different cyber-event types (process sensors for execution monitoring, network sensors for communication detection, registry sensors for persistence detection, WMI sensors for lateral movement detection). Each sensor focuses on specific indicators while the unified system integrates them to provide complete attack pathway detection, managing complexity through modular specialization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system adds a new dimension of analysis by constructing cyber-event trees that map the temporal and causal relationships between different cyber-events. This transforms flat event detection into a multi-dimensional analysis that captures the progression of attacks through multiple phases, enabling detection of complete attack pathways rather than isolated incidents.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If comprehensive monitoring of all cyber-event phases is implemented, then detection capability improves, but data processing and analysis complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoiddata processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces intermediaries in the form of event correlation rules and analysis layers that process raw cyber-events before presenting them for detection. These intermediaries aggregate, filter, and contextualize the large volume of events from multiple sensors, reducing the complexity of analysis while maintaining comprehensive detection capability through structured event processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11489851B2Methods and systems for monitoring cyber-events
Publication Date: 2022.11.01 CYBER DEFENCE QCD CORP
  • US11489851B2 patent drawing
  • US11489851B2 patent drawing
  • US11489851B2 patent drawing

AI summary

The present invention provides a method of monitoring a computer network, the method comprising: providing a plurality of sensors, wherein said sensors form a meshed network of sensors which monitor cyber-event(s); detecting, by the plurality of sensors, cyber-event(s); linking cyber-event(s) to subsequent cyber-event(s) into branches to form/extend a cyber-event tree; comparing said cyber-event tree to a baseline cyber-event tree; determining if there is any differences in said cyber-event tree to said baseline cyber-event tree to identify a cyber-event tree or a branch thereof as anomalous and thereby identify potential anomalous event(s) and/or a cyber-attack.