Cybersecurity Profile Generation via Network Event Anomaly Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity rating methods, such as CVSS, fail to adequately profile and rate the cybersecurity profiles of organizations due to insufficient information incorporation, making it difficult to monitor critical infrastructure entities, identify anomalous network events, and correlate them to determine attack paths and points of origin.

Innovation Solution

A system and method that uses active and passive reconnaissance to create a cyber-physical graph of an organization, allowing for the identification of attack patterns and points of origin by correlating network event anomalies and generating a cybersecurity profile that incorporates data on infrastructure, operations, and behavioral data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If existing cybersecurity rating methods (e.g., CVSS) are used, then the rating process is simple, but the cybersecurity profile is inadequate due to insufficient information incorporation

Engineering Contradiction:
Improveinformation incorporationVSAvoidrating system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent combines multiple data sources including network event data, asset inventory data, vulnerability data, threat intelligence data, and contextual data into a unified cybersecurity profile. This merging of previously separate information sources enables comprehensive organization-wide cybersecurity assessment rather than isolated system ratings

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The cybersecurity profile system serves multiple functions simultaneously: it monitors network events, identifies anomalies, correlates attack information, assesses organizational cybersecurity posture, and provides actionable insights. This multi-functional approach replaces the single-function nature of traditional rating systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If comprehensive data gathering is performed to create accurate cybersecurity profiles, then the cybersecurity rating accuracy is improved, but the system complexity and resource requirements increase

Engineering Contradiction:
Improvecybersecurity rating accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the cybersecurity assessment into distinct modular components: network event monitoring module, anomaly detection module, attack information correlation module, and profile generation module. Each module handles specific data processing tasks independently, making the complex system manageable and maintainable while achieving high accuracy through comprehensive data integration

Inventive Principle:
Principle #1Segmentation

3Reliability

If network event anomalies are monitored and correlated across the entire organization, then attack path identification is improved, but the computational requirements and processing time increase

Engineering Contradiction:
Improveattack detection reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously gathering and organizing network event data, asset inventory, vulnerability information, and threat intelligence before attacks occur. This pre-processing and structuring of data enables rapid anomaly detection and attack path identification when events occur, reducing processing time during critical incidents

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250168201A1Correlating network event anomalies using active and passive external reconnaissance to identify attack information
Publication Date: 2025.05.22 QPX LLC
  • US20250168201A1 patent drawing
  • US20250168201A1 patent drawing
  • US20250168201A1 patent drawing

AI summary

A system and method for correlating network event anomalies to identify attack information, that identifies anomalous events within the network, identifies correlations between anomalies and other network events and resources, generates a behavior graph describing an attack pathway derived from the correlations, and determines an attack point of origin using the behavior graph.