Correlating Cyber and Physical Security Events for Intrusion Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security measures fail to effectively detect intrusions into computer systems by separately analyzing cyber and physical security events, missing potential threats that involve unauthorized access both digitally and physically.
Innovation Solution
A method and system that correlate cyber security events, such as unauthorized access by malicious software, with physical security events, like unauthorized physical access, to identify and respond to intrusions by adjusting access control rules and predicting future threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If separate analysis of cyber and physical security events is used, then system simplicity is maintained, but intrusion detection capability deteriorates
Solution Approach 1:
The patent combines separate cyber security event analysis and physical security event analysis into a unified intrusion detection system. The server correlates events from both domains by matching identifiers, timestamps, and spatial relationships, enabling comprehensive intrusion detection that leverages both digital and physical security data streams simultaneously.
2Reliability
If correlation of cyber and physical security events is implemented, then intrusion detection capability is improved, but system complexity increases
Solution Approach 1:
The system segments the complex correlation task into distinct modular components: a receiving module that collects events from multiple sources, a correlation engine that matches events using identifiers and spatial-temporal parameters, and an output module that generates alerts. This segmentation manages complexity by organizing functions into discrete, manageable units with clear interfaces.
Solution Approach 2:
The server acts as an intermediary that receives, processes, and correlates security events from separate cyber and physical security systems. It mediates between the heterogeneous event sources by standardizing event formats, matching identifiers, and applying correlation rules, thereby simplifying the integration of diverse security systems without requiring direct modification of the source systems.
3Measurement precision
If multiple event sources are monitored and correlated, then detection precision is improved, but information processing load increases
Solution Approach 1:
The system performs preliminary filtering and normalization of security events before correlation. Events are pre-processed to extract key identifiers, timestamps, and spatial information, and to validate basic criteria. This preliminary action reduces the complexity of subsequent correlation operations by eliminating obviously irrelevant events and standardizing data formats, thereby reducing overall processing load while maintaining detection precision.
Data Source
Figure 1
Figure 2
AI summary
Methods and systems for protecting computer systems against intrusion. The disclosed techniques detect intrusions by jointly considering both cyber security events and physical security events. In some embodiments, a correlation subsystem receives information related to the computer system and its physical environment from various information sources in the cyber domain and in the physical domain. The correlation subsystem analyzes the information and identifies both cyber security events and physical security events. The correlation subsystem finds cyber security events and physical security events that are correlative with one another, and uses this correlation to detect intrusions.