Cybersecurity System Micro-Segmentation Real-Time Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional cybersecurity systems are limited in their ability to account for device differences in large networks and fail to leverage real-time data effectively, as they rely on manual model building and batch processing, which does not capture individual device variations and is inefficient in processing real-time data.

Innovation Solution

The system integrates segmented analytic modeling with data center micro-segmentation, using multiple sensors and scoring engines connected via a high-performance Enterprise Service Bus (ESB) to process events in real-time, allowing for appropriate mitigation actions in each micro-segment, and updates models using a Model Interchange Format (MIF) like Portable Format for Analytics (PFA).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If a single behavior model is developed for the network or for each type of device, then the system complexity is reduced and ease of manufacture is improved, but the measurement precision and ability to capture individual device differences deteriorates

Engineering Contradiction:
Improveease of model developmentVSAvoiddevice behavior detection accuracy
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent segments the network into multiple micro-segments based on device types, locations, and behaviors. Each micro-segment has its own specialized behavior model, allowing the system to capture individual device differences while maintaining manageable complexity through modular model organization and automated generation processes.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If manual model building and batch analytics are used, then the device complexity and computational resources required are reduced, but the processing speed and real-time capability deteriorates

Engineering Contradiction:
Improvesystem architecture complexityVSAvoidreal-time data processing speed
Core Design Contradiction:
Device complexityVSSpeed

Solution Approach 1:

The system performs preliminary actions by pre-building behavior models for each micro-segment using historical data and automated model generation techniques. These pre-built models are then deployed to scoring engines that can rapidly evaluate new data in real-time, eliminating the need for manual model building during operation while maintaining high processing speeds.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual mechanical model-building processes with automated computational systems. Machine learning algorithms and automated model generation techniques substitute for human analysts, enabling the system to process data in real-time without the bottlenecks of manual exploration and model construction.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Quantity of substance

If distributed or disk based data processing is used, then the memory requirements are reduced, but the processing time and loss of time increases

Engineering Contradiction:
Improvememory storage capacityVSAvoiddata processing time
Core Design Contradiction:
Quantity of substanceVSLoss of time

Solution Approach 1:

The patent implements a nested architecture where behavior models are embedded within scoring engines, which are distributed across multiple processing nodes. Each node contains the necessary model logic and can process data locally, reducing the need for centralized disk-based processing while maintaining efficient memory utilization through selective data caching and streaming processing.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentEP3095034B1Cybersecurity system
Publication Date: 2019.05.29 IRONNET CYBERSECURITY INC
  • EP3095034B1 patent drawingFigure 1
  • EP3095034B1 patent drawingFigure 2
  • EP3095034B1 patent drawingFigure 3

AI summary

A cybersecurity system for processing events to produce scores, alerts, and mitigation actions. The system includes sensors for receiving and processing data to form events, distributed analytic platform for processing events to form analytic workflows, and scoring engines for processing events using analytic workflows to produce scoring engine messages. The system also includes real time analytic engine for processing scoring engine messages and distributed analytic platform messages using the analytic workflows and analytic workflow and event processing rules to form and transmit a threat intelligence message. Threat intelligence messages include broadcast messages, mitigation messages, and model update messages. The system also includes logical segments which associate an analytic model, a set of analytic models, or an analytic workflow; one or more sources of inputs about activity within the logical segment, and a set of actions for mitigating an impact of the anomalous activity occurring within the logical segment.