Cybersecurity Profile Generation via Network Event Anomaly Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity rating methods, such as CVSS, fail to adequately profile and rate the cybersecurity profiles of organizations due to insufficient information incorporation, making it difficult to monitor critical infrastructure entities, identify anomalous network events, and correlate them to determine attack paths and points of origin.
Innovation Solution
A system and method that uses active and passive reconnaissance to create a cyber-physical graph of an organization, allowing for the identification of attack patterns and points of origin by correlating network event anomalies and generating a cybersecurity profile that incorporates data on infrastructure, operations, and behavioral data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If existing cybersecurity rating methods (e.g., CVSS) are used, then the rating process is simple, but the cybersecurity profile is inadequate due to insufficient information incorporation
Solution Approach 1:
The patent combines multiple data sources including network event data, asset inventory data, vulnerability data, threat intelligence data, and contextual data into a unified cybersecurity profile. This merging of previously separate information sources enables comprehensive organization-wide cybersecurity assessment rather than isolated system ratings
Solution Approach 2:
The cybersecurity profile system serves multiple functions simultaneously: it monitors network events, identifies anomalies, correlates attack information, assesses organizational cybersecurity posture, and provides actionable insights. This multi-functional approach replaces the single-function nature of traditional rating systems
2Measurement precision
If comprehensive data gathering is performed to create accurate cybersecurity profiles, then the cybersecurity rating accuracy is improved, but the system complexity and resource requirements increase
Solution Approach 1:
The patent segments the cybersecurity assessment into distinct modular components: network event monitoring module, anomaly detection module, attack information correlation module, and profile generation module. Each module handles specific data processing tasks independently, making the complex system manageable and maintainable while achieving high accuracy through comprehensive data integration
3Reliability
If network event anomalies are monitored and correlated across the entire organization, then attack path identification is improved, but the computational requirements and processing time increase
Solution Approach 1:
The system performs preliminary actions by continuously gathering and organizing network event data, asset inventory, vulnerability information, and threat intelligence before attacks occur. This pre-processing and structuring of data enables rapid anomaly detection and attack path identification when events occur, reducing processing time during critical incidents
Data Source
AI summary
A system and method for correlating network event anomalies to identify attack information, that identifies anomalous events within the network, identifies correlations between anomalies and other network events and resources, generates a behavior graph describing an attack pathway derived from the correlations, and determines an attack point of origin using the behavior graph.


