Cyber Threat Attenuation via Distributed Sensor Control Points
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity systems are inadequate in detecting and responding to advanced persistent threats (APTs), zero-day threats, and rogue user threats within enterprise networks, as they often rely on conventional methods that are difficult to detect and require sophisticated, stealthy processes.
Innovation Solution
A cyber threat attenuation system comprising sensor control points (SCPs) with processor and memory units, an analytics correlation system, and a rules engine that analyzes data packet traffic, identifies unusual patterns, and takes action such as sandboxing or shutting down compromised hosts, independent of traditional firewall systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If conventional cybersecurity methods are used, then system simplicity is maintained, but detection capability for advanced persistent threats deteriorates
Solution Approach 1:
The system segments the enterprise network into multiple LAN segments, each monitored by independent sensor control points. This segmentation allows distributed detection of advanced threats while maintaining manageable system complexity through modular architecture. Each sensor control point independently analyzes data packets in its specific LAN segment, enabling comprehensive threat detection without requiring a monolithic complex system.
Solution Approach 2:
The patent introduces sensor control points as intermediary components between network segments and the central analytics correlation system. These intermediaries locally analyze data packets and generate notifications only when threats are detected, reducing the complexity of continuous centralized analysis while maintaining high detection capability for sophisticated threats like APTs and zero-day vulnerabilities.
2Measurement precision
If multi-source threat data analysis is implemented, then threat detection accuracy is improved, but system complexity increases
Solution Approach 1:
The system merges data from multiple sources including sensor control points, network data traffic stores, and cyber threat data stores into a unified analysis framework. The analytics correlation system combines notifications from various sensors with expected traffic volume data and threat intelligence to achieve high detection accuracy for sophisticated threats while managing complexity through integrated processing.
Solution Approach 2:
The analytics correlation system performs multiple functions: analyzing data packet traffic patterns, comparing against expected values, cross-referencing with threat intelligence, and coordinating responses across multiple LAN segments. This multi-functionality consolidates what would otherwise require separate complex systems into a single unified platform, improving detection accuracy without proportionally increasing complexity.
3Speed
If real-time network traffic monitoring is implemented, then response time to threats is improved, but processing requirements and system complexity increase
Solution Approach 1:
The system performs preliminary actions by pre-establishing expected traffic volume values and variability measures for each LAN segment and host. These baselines are computed in advance, allowing real-time monitoring to simply compare current traffic against pre-defined thresholds rather than performing complex analysis during threat response, thus improving response speed without increasing processing complexity.
Solution Approach 2:
The sensor control points implement partial analysis by focusing monitoring on specific criteria identified by each sensor type rather than analyzing all packet characteristics comprehensively. This selective monitoring achieves sufficient detection capability for sophisticated threats while reducing processing requirements compared to full-depth real-time analysis of all network traffic.
Data Source
AI summary
A cyber threat attenuation system. The system comprises a cyber threat data store, a plurality of sensor control points (SCPs), wherein at least one SCP is located in each local area network (LAN) segment of an enterprise network, and an analytics correlation system (ACS). Each SCP comprises a plurality of sensor applications that analyze data packets transported by the LAN segment in which the SCP is located and transmits a notification identifying the transmitting sensor, an identity of the source of the data packet, an identity of the destination of the data packet, and a notification reason to the data store. The ACS comprises an application that determines unusual data packet traffic in the enterprise network and transmits a notification comprising information about the unusual data packet traffic and an identity of a host computer associated with the unusual data packet traffic to the data store.


