Cybersecurity System Micro-Segmentation Real-Time Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional cybersecurity systems are limited in their ability to account for device differences in large networks and fail to leverage real-time data effectively, as they rely on manual model building and batch processing, which does not capture individual device variations and is inefficient in processing real-time data.
Innovation Solution
The system integrates segmented analytic modeling with data center micro-segmentation, using multiple sensors and scoring engines connected via a high-performance Enterprise Service Bus (ESB) to process events in real-time, allowing for appropriate mitigation actions in each micro-segment, and updates models using a Model Interchange Format (MIF) like Portable Format for Analytics (PFA).
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If a single behavior model is developed for the network or for each type of device, then the system complexity is reduced and ease of manufacture is improved, but the measurement precision and ability to capture individual device differences deteriorates
Solution Approach 1:
The patent segments the network into multiple micro-segments based on device types, locations, and behaviors. Each micro-segment has its own specialized behavior model, allowing the system to capture individual device differences while maintaining manageable complexity through modular model organization and automated generation processes.
2Device complexity
If manual model building and batch analytics are used, then the device complexity and computational resources required are reduced, but the processing speed and real-time capability deteriorates
Solution Approach 1:
The system performs preliminary actions by pre-building behavior models for each micro-segment using historical data and automated model generation techniques. These pre-built models are then deployed to scoring engines that can rapidly evaluate new data in real-time, eliminating the need for manual model building during operation while maintaining high processing speeds.
Solution Approach 2:
The patent replaces manual mechanical model-building processes with automated computational systems. Machine learning algorithms and automated model generation techniques substitute for human analysts, enabling the system to process data in real-time without the bottlenecks of manual exploration and model construction.
3Quantity of substance
If distributed or disk based data processing is used, then the memory requirements are reduced, but the processing time and loss of time increases
Solution Approach 1:
The patent implements a nested architecture where behavior models are embedded within scoring engines, which are distributed across multiple processing nodes. Each node contains the necessary model logic and can process data locally, reducing the need for centralized disk-based processing while maintaining efficient memory utilization through selective data caching and streaming processing.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A cybersecurity system for processing events to produce scores, alerts, and mitigation actions. The system includes sensors for receiving and processing data to form events, distributed analytic platform for processing events to form analytic workflows, and scoring engines for processing events using analytic workflows to produce scoring engine messages. The system also includes real time analytic engine for processing scoring engine messages and distributed analytic platform messages using the analytic workflows and analytic workflow and event processing rules to form and transmit a threat intelligence message. Threat intelligence messages include broadcast messages, mitigation messages, and model update messages. The system also includes logical segments which associate an analytic model, a set of analytic models, or an analytic workflow; one or more sources of inputs about activity within the logical segment, and a set of actions for mitigating an impact of the anomalous activity occurring within the logical segment.