Cyber-Hardening via Adversarial Simulation and Machine Learning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cyber-attacks pose a significant threat to computer systems, particularly for small to medium-sized businesses, with limited defense capabilities, leading to increased costs and frequency of attacks.

Innovation Solution

A computer-implemented method using a simulated environment with adversarial systems to train a machine learning model by applying various cyber-attack and defense techniques, allowing for the improvement of cyber-attack resistance by logging and updating defense mechanisms in a repeating simulation sequence.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional cyber-attack defense techniques are used, then basic security protection is provided, but the system cannot adapt to evolving and complex cyber-attacks

Engineering Contradiction:
Improveadaptability to evolving cyber-attacksVSAvoideffectiveness of defense mechanisms
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by conducting simulated cyber-attacks and training defense mechanisms in advance within a controlled environment. The machine learning model is trained beforehand on various attack scenarios, enabling the actual defense system to respond effectively to evolving cyber-attacks without waiting for real-time analysis during an actual attack.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The defense system employs self-service through autonomous machine learning that continuously improves its own performance. The system automatically logs training instances, updates its knowledge base, and refines its defense mechanisms without human intervention, enabling it to adapt to new attack vectors and maintain high reliability in the face of evolving threats.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If comprehensive cyber-attack simulation and training is performed, then the machine learning model becomes more accurate, but the time required for training increases

Engineering Contradiction:
Improveaccuracy of cyber-attack detectionVSAvoidtraining time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system implements continuous training by continuously logging training instances from simulated attacks and continuously updating the machine learning model. This ongoing process allows the model to accumulate knowledge from numerous attack scenarios over time, achieving high accuracy without requiring periodic lengthy retraining cycles, thus reducing time loss while maintaining precision.

Inventive Principle:
Principle #20Continuity of useful action

3Quantity of substance

If multiple cyber-attack techniques and variations are applied in simulation, then the training data becomes more comprehensive, but the complexity of the simulation system increases

Engineering Contradiction:
Improvevolume of training dataVSAvoidcomplexity of simulation environment
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The system uses copying by creating virtual replicas of cyber-attack scenarios within a simulated environment. Instead of implementing every possible attack variation directly in the physical system, the system copies attack patterns into a controlled simulation space, allowing comprehensive data collection while maintaining simulation complexity at manageable levels through virtualization.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20240214413A1Cyber-hardening using adversarial simulated attacking and defender systems and machine learning
Publication Date: 2024.06.27 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US20240214413A1 patent drawing
  • US20240214413A1 patent drawing
  • US20240214413A1 patent drawing

AI summary

In one general embodiment, a computer-implemented method includes applying a plurality of known cyber-attack techniques and variations thereof against a simulated defender system using a simulated attacking system. Known cyber-attack defense techniques are applied to the defender system. Instances of the defender system are logged in association with various combinations of respective cyber-attack techniques, various cyber-attack defense techniques, simulated system configurations, and simulated system outcomes as training instances. A machine learning model is trained using the logged training instances. A production product configuration is input to the trained machine learning model. Information related to cyber-hardening of the production product is output from the trained machine learning model.