Cyber Threat Attenuation via Distributed Sensor Control Points

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems are inadequate in detecting and responding to advanced persistent threats (APTs), zero-day threats, and rogue user threats within enterprise networks, as they often rely on conventional methods that are difficult to detect and require sophisticated, stealthy processes.

Innovation Solution

A cyber threat attenuation system comprising sensor control points (SCPs) with processor and memory units, an analytics correlation system, and a rules engine that analyzes data packet traffic, identifies unusual patterns, and takes action such as sandboxing or shutting down compromised hosts, independent of traditional firewall systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If conventional cybersecurity methods are used, then system simplicity is maintained, but detection capability for advanced persistent threats deteriorates

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The system segments the enterprise network into multiple LAN segments, each monitored by independent sensor control points. This segmentation allows distributed detection of advanced threats while maintaining manageable system complexity through modular architecture. Each sensor control point independently analyzes data packets in its specific LAN segment, enabling comprehensive threat detection without requiring a monolithic complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces sensor control points as intermediary components between network segments and the central analytics correlation system. These intermediaries locally analyze data packets and generate notifications only when threats are detected, reducing the complexity of continuous centralized analysis while maintaining high detection capability for sophisticated threats like APTs and zero-day vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If multi-source threat data analysis is implemented, then threat detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system merges data from multiple sources including sensor control points, network data traffic stores, and cyber threat data stores into a unified analysis framework. The analytics correlation system combines notifications from various sensors with expected traffic volume data and threat intelligence to achieve high detection accuracy for sophisticated threats while managing complexity through integrated processing.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The analytics correlation system performs multiple functions: analyzing data packet traffic patterns, comparing against expected values, cross-referencing with threat intelligence, and coordinating responses across multiple LAN segments. This multi-functionality consolidates what would otherwise require separate complex systems into a single unified platform, improving detection accuracy without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Speed

If real-time network traffic monitoring is implemented, then response time to threats is improved, but processing requirements and system complexity increase

Engineering Contradiction:
Improveresponse timeVSAvoidprocessing complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-establishing expected traffic volume values and variability measures for each LAN segment and host. These baselines are computed in advance, allowing real-time monitoring to simply compare current traffic against pre-defined thresholds rather than performing complex analysis during threat response, thus improving response speed without increasing processing complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The sensor control points implement partial analysis by focusing monitoring on specific criteria identified by each sensor type rather than analyzing all packet characteristics comprehensively. This selective monitoring achieves sufficient detection capability for sophisticated threats while reducing processing requirements compared to full-depth real-time analysis of all network traffic.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10454894B2Cyber threat attenuation using multi-source threat data analysis
Publication Date: 2019.10.22 CYBER ADAPT INC
  • US10454894B2 patent drawing
  • US10454894B2 patent drawing
  • US10454894B2 patent drawing

AI summary

A cyber threat attenuation system. The system comprises a cyber threat data store, a plurality of sensor control points (SCPs), wherein at least one SCP is located in each local area network (LAN) segment of an enterprise network, and an analytics correlation system (ACS). Each SCP comprises a plurality of sensor applications that analyze data packets transported by the LAN segment in which the SCP is located and transmits a notification identifying the transmitting sensor, an identity of the source of the data packet, an identity of the destination of the data packet, and a notification reason to the data store. The ACS comprises an application that determines unusual data packet traffic in the enterprise network and transmits a notification comprising information about the unusual data packet traffic and an identity of a host computer associated with the unusual data packet traffic to the data store.