Correlating Cyber and Physical Security Events for Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures fail to effectively detect intrusions into computer systems by separately analyzing cyber and physical security events, missing potential threats that involve unauthorized access both digitally and physically.

Innovation Solution

A method and system that correlate cyber security events, such as unauthorized access by malicious software, with physical security events, like unauthorized physical access, to identify and respond to intrusions by adjusting access control rules and predicting future threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If separate analysis of cyber and physical security events is used, then system simplicity is maintained, but intrusion detection capability deteriorates

Engineering Contradiction:
Improvesystem simplicityVSAvoidintrusion detection capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent combines separate cyber security event analysis and physical security event analysis into a unified intrusion detection system. The server correlates events from both domains by matching identifiers, timestamps, and spatial relationships, enabling comprehensive intrusion detection that leverages both digital and physical security data streams simultaneously.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If correlation of cyber and physical security events is implemented, then intrusion detection capability is improved, but system complexity increases

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the complex correlation task into distinct modular components: a receiving module that collects events from multiple sources, a correlation engine that matches events using identifiers and spatial-temporal parameters, and an output module that generates alerts. This segmentation manages complexity by organizing functions into discrete, manageable units with clear interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The server acts as an intermediary that receives, processes, and correlates security events from separate cyber and physical security systems. It mediates between the heterogeneous event sources by standardizing event formats, matching identifiers, and applying correlation rules, thereby simplifying the integration of diverse security systems without requiring direct modification of the source systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If multiple event sources are monitored and correlated, then detection precision is improved, but information processing load increases

Engineering Contradiction:
Improvedetection precisionVSAvoidinformation processing load
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary filtering and normalization of security events before correlation. Events are pre-processed to extract key identifiers, timestamps, and spatial information, and to validate basic criteria. This preliminary action reduces the complexity of subsequent correlation operations by eliminating obviously irrelevant events and standardizing data formats, thereby reducing overall processing load while maintaining detection precision.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2657880B1Systems and methods for combined physical and cyber data security
Publication Date: 2020.02.19 VERINT SYST LTD
  • EP2657880B1 patent drawingFigure 1
  • EP2657880B1 patent drawingFigure 2

AI summary

Methods and systems for protecting computer systems against intrusion. The disclosed techniques detect intrusions by jointly considering both cyber security events and physical security events. In some embodiments, a correlation subsystem receives information related to the computer system and its physical environment from various information sources in the cyber domain and in the physical domain. The correlation subsystem analyzes the information and identifies both cyber security events and physical security events. The correlation subsystem finds cyber security events and physical security events that are correlative with one another, and uses this correlation to detect intrusions.