Cyber Threat Detection System Context Adaptation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The dissemination and feedback stage of cyber threat intelligence is challenging due to the difficulty in translating intelligence into concrete surveillance and security actions, often resulting in false positives when the context of the information system is not considered.

Innovation Solution

A method involving a detection system with an information system monitoring system, an intelligence information database, and a recommendation module that collects observation data, extracts relevant intelligence information, and generates proposals for monitoring and mitigating cyber threats, incorporating feedback to refine and update these proposals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cyber threat intelligence is translated into concrete monitoring and security actions without considering the specific context of the information system, then security actions can be deployed, but false positives increase and reliability decreases

Engineering Contradiction:
Improvespeed of deploying security actionsVSAvoidaccuracy of threat detection
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies local quality by adapting generic cyber threat intelligence to the specific local context of each information system. The system analyzes system-specific characteristics, architecture, and operational patterns to customize threat detection rules and security actions, ensuring that intelligence is not applied universally but tailored to each system's unique context, thereby reducing false positives while maintaining deployment speed

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements feedback mechanisms where the results of security actions and threat detections are continuously fed back into the system. This feedback loop allows the system to learn from actual system behavior and outcomes, refining its understanding of what constitutes a real threat versus a false positive, thereby improving reliability over time without sacrificing the ability to quickly deploy actions

Inventive Principle:
Principle #23Feedback

2Reliability

If comprehensive analysis of system context is performed before deploying security actions, then false positives are reduced, but the time required to deploy actions increases

Engineering Contradiction:
Improveaccuracy of threat detectionVSAvoidtime to deploy security actions
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-analyzing and storing system context information, architecture details, and operational patterns before threats occur. This preparatory work creates a baseline understanding of normal system behavior and context, enabling rapid threat assessment when incidents occur without requiring comprehensive re-analysis each time, thus reducing deployment time while maintaining accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts the level of analysis performed based on the situation. For routine threats, pre-established rules and quick assessments are used to save time. For novel or complex threats, the system intensifies contextual analysis to ensure accuracy. This dynamic approach balances speed and reliability based on the specific threat scenario

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If generic cyber threat intelligence is applied without customization, then deployment is simple and fast, but the intelligence lacks meaning and effectiveness for the specific organization

Engineering Contradiction:
Improvesimplicity of intelligence deploymentVSAvoidrelevance to specific information system
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements universality by creating a multi-functional platform that can handle both generic threat intelligence ingestion and system-specific customization automatically. The system provides a standardized interface for deploying intelligence while internally performing context-specific adaptations, allowing simple deployment operations while achieving high adaptability through automated contextualization of threat data

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4181002A1Method for detecting a cyber threat weighing on an information system; associated computer program product and computer system
Publication Date: 2023.05.17 THALES SA
  • EP4181002A1 patent drawingFigure 1
  • EP4181002A1 patent drawingFigure 2
  • EP4181002A1 patent drawing

AI summary

This process, which is carried out by a computer system (50, 40) comprising a monitoring component (42, 44, 46) of the information system (10) to be protected, a database (54) of intelligence information, and a recommendation module (51) running a proposal engine, consists of: collecting a set of observation data on the operation of the information system; running the recommendation module to query the database (54) based on a subset of the data collected in order to extract relevant indicators; and defining a proposal relating to a potential cyberattack from the extracted indicators; transmitting the proposal to the monitoring component; and, implementing the proposal by the monitoring component to monitor the information system (10).