Cyber Profiling Engine for Adversary Attribution via Quantitative Metrics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods lack effective means to identify and profile cyber-attackers, focusing on attack analysis rather than adversary characterization, which hinders swift and accurate counter-measures.

Innovation Solution

A system and method for analyzing cyber-attacks by extracting quantitative data from attack data, comparing it with a database of known adversary metrics, and determining if the attack is associated with a known adversary or behavior, using a cyber profiling engine and database to create actionable insights.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If focus is placed on analyzing attack technologies and actions, then immediate emergency care for cyber attacks can be provided, but the ability to identify and profile adversaries is compromised

Engineering Contradiction:
Improveresponse speedVSAvoidadversary identification capability
Core Design Contradiction:
SpeedVSLoss of information

Solution Approach 1:

The system segments cyber attack analysis into two distinct modules: attack analysis for immediate response and adversary profiling for identification. The attack analysis module processes attack data to provide rapid response, while the adversary profiling module separately analyzes adversary behavior patterns, tools, and tactics to identify responsible parties. This segmentation allows both functions to operate independently at their optimal speeds without compromising either capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary database of adversary profiles and behavioral patterns that mediates between attack data collection and adversary identification. This intermediary storehouse contains pre-profiled adversary characteristics, attack methodologies, and behavioral signatures that enable the system to quickly match attack patterns against known adversary profiles, thereby maintaining both rapid response and accurate identification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If quantitative data extraction and adversary profiling are implemented, then adversary identification accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveadversary identification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system transforms qualitative adversary profile data into quantitative parameters and metrics that can be systematically extracted, stored, and compared. By converting adversary characteristics into measurable parameters such as attack frequency, tool usage patterns, temporal behaviors, and resource allocation metrics, the system enables precise quantitative analysis while maintaining manageable complexity through standardized parameter definitions and extraction protocols.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If a database of adversary metrics is created, then attribution capability is enhanced, but data processing requirements increase

Engineering Contradiction:
Improveattribution reliabilityVSAvoiddata processing volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system performs preliminary action by pre-processing and storing adversary profile data, attack methodologies, and behavioral patterns in a structured database before actual attacks occur. This pre-established database contains standardized metrics and templates that enable rapid matching and attribution during real-time attack analysis, thereby enhancing attribution reliability without requiring extensive data processing during the actual incident response.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9661003B2System and method for forensic cyber adversary profiling, attribution and attack identification
Publication Date: 2017.05.23 PARKER THOMAS W
  • US9661003B2 patent drawing
  • US9661003B2 patent drawing
  • US9661003B2 patent drawing

AI summary

A system and method is provided for identifying and analyzing cyber-attacks and profiling adversaries responsible for such attacks. The system and method allows for the quantitative measurement of adversary attack behavior. The system and method is able to extract quantitative data from raw attack data and compare the quantitative data to a database of quantifiable metrics associated with known adversaries. This allows for the possible linking of a cyber-attack to a known adversary or known adversary behavior.