Cyberattack Forecasting via Unconventional Signal Fusion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods fail to effectively forecast cyberattacks before their first observables are seen, as they rely on direct and repetitive data sources, lacking a systematic way to combine unconventional signals that may collectively predict future attacks.

Innovation Solution

A system that collects and processes a variety of predictive signals, imputes missing values, selects relevant non-redundant lagged signals, performs concept drift analysis, and trains a forecasting model using ground truth data to predict cyberattacks, incorporating both internal and external signals from various sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional predictive analytics or machine learning techniques are used, then forecasting accuracy may be improved, but they require training data of known attack strategies which are scarce and not practical given the evolving nature of cyberattacks

Engineering Contradiction:
Improveforecasting accuracyVSAvoidtraining data availability
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent introduces an intermediary layer of signal processing and feature engineering that transforms unconventional signals into meaningful predictive features. This intermediary process enables the system to work with limited training data by creating synthetic training scenarios and using signal transformation techniques that don't rely on large volumes of labeled attack data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary signal collection, processing, and feature extraction before actual cyberattacks occur. By pre-processing unconventional signals and creating predictive features in advance, the system builds a foundation for forecasting that doesn't require waiting for attack data to accumulate.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If direct observables of cyber threats are used for prediction, then the prediction may be more directly related to actual attacks, but it is not possible to forecast a cyber incident before its first observables are seen

Engineering Contradiction:
Improveprediction reliabilityVSAvoidforecast lead time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent inverts the traditional approach by not starting from attack observables and trying to detect them, but rather starting from unconventional signals that precede attacks and working backwards to predict attack occurrence. This inversion enables forecasting before first observables are seen.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system collects and processes unconventional signals in advance before attacks occur, performing preliminary analysis on signals such as vulnerability scans, threat intelligence feeds, and security configuration data to establish baseline conditions that precede actual attacks.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If a significant number of unconventional signals are collected individually, then they may collectively help forecast future cyberattacks, but there is no systematic way to combine or fuse these signals which individually may be weak

Engineering Contradiction:
Improveforecast precisionVSAvoidsignal fusion complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges multiple unconventional signals from diverse sources into a unified forecasting framework. By combining vulnerability scan data, threat intelligence, security configuration signals, and other unconventional data sources, the system creates a composite predictive model that leverages the collective value of weak individual signals.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system employs a universal signal processing framework that can handle multiple types of unconventional signals through common processing pipelines. This multi-functional approach enables the same system architecture to process diverse signal types without requiring separate specialized systems for each signal source.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If more signals and data sources are explored to forecast cyberattacks, then the forecasting capability may be improved, but the data may not directly and repeatedly be related to the attack itself and requires systematic combination

Engineering Contradiction:
Improvesignal source versatilityVSAvoidsystematic processing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the complex signal fusion process into distinct modular components: signal collection, signal processing, feature extraction, and forecasting. This segmentation allows each component to handle specific aspects of unconventional signals independently, reducing overall system complexity while maintaining versatility.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11632386B2Cyberattack forecasting using predictive information
Publication Date: 2023.04.18 ROCHESTER INSTITUTE OF TECHNOLOGY
  • US11632386B2 patent drawing
  • US11632386B2 patent drawing
  • US11632386B2 patent drawing

AI summary

A computerized method and system for predicting the probability of a cyberattack to a target entity, includes: collecting a plurality of predictive signals to a target entity for a specific cyberattack type; optionally, imputing a value for missing values of the collected signals; selecting a set of relevant non-redundant signals from the collected signals to create lagged signals; identifying from the lagged signals relevant data chunks to form a custom training set of signals; providing selected ground truth data related to the specific attack type for the target entity; training a forecasting model using the custom training set of signals together with the selected ground truth data related to the specific attack type for the target entity to generate a trained forecasting model; providing a second set of signals of the same type of signals as the custom training set of signals; and generating the probability of the specific attack type of interest against the target entity by inputting the second set of signals into the trained forecasting model.