Dynamic Stochastic Network for Emerging Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for proactive emerging threat detection are non-real-time and require pre-defined event and causal relationships, making them ineffective against adaptive adversaries who use new attack methods.
Innovation Solution
A dynamic stochastic network is created in real-time using event data, with super nodes representing events and agents, and local nodes representing agents, allowing for adaptive connection strength adjustments and real-time anomaly detection based on instability metrics.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If pre-defined models with fixed causal relationships are used for threat detection, then the system can provide stable predictions for known events, but it cannot detect emerging threats using new attack methods
Solution Approach 1:
The patent transforms the static, pre-defined predictive model into a dynamic system that continuously learns from incoming event data. The model adapts its parameters and structures in real-time based on observed patterns, allowing it to detect emerging threats while maintaining reliability through continuous validation against established baselines.
Solution Approach 2:
The system performs self-training and self-adjustment by automatically learning from the data it processes. Instead of requiring external retraining by domain experts, the system autonomously updates its understanding of normal and abnormal patterns, enabling it to adapt to new attack methods without manual intervention.
2Measurement precision
If domain experts manually model causal relationships between events, then the system can capture accurate domain knowledge, but it requires significant expert time and cannot keep pace with evolving threats
Solution Approach 1:
The patent replaces the manual, mechanical process of expert modeling with an automated computational system. Machine learning algorithms automatically infer causal relationships from data, substituting human expert effort with computational processes that can analyze patterns at scales and speeds impossible for manual modeling.
Solution Approach 2:
The system introduces an intermediate layer of automated pattern recognition and statistical analysis between raw event data and threat detection conclusions. This intermediary processing layer automatically extracts causal relationships and patterns, reducing the need for direct expert intervention while maintaining detection accuracy.
3Reliability
If copious amounts of representative training data are gathered ahead of time, then the model can be trained effectively, but the data must be pre-collected and cannot capture real-time emerging threats
Solution Approach 1:
The system performs preliminary actions by continuously pre-processing and pre-analyzing incoming data streams in real-time. It maintains ready-to-use feature extractions and pattern recognitions that can be immediately applied to detect emerging threats without requiring separate, time-consuming training phases.
Solution Approach 2:
The system ensures continuous learning and adaptation by processing data streams without interruption. Instead of batch processing with periodic retraining, the system maintains continuous operation where data ingestion, analysis, and model updating occur simultaneously and continuously, enabling real-time detection while maintaining model quality.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
A system creates a dynamic stochastic network using data relating to events. The dynamic stochastic network includes super nodes, local nodes, and agents. Connections among the super nodes and local nodes include events that are related to the super nodes and the local nodes. Strengths of the connections between the super nodes and local nodes are a function of a number of events that are common to the super nodes and local nodes. The connections are made and broken as the agents interact over time. The strengths of the connections increase and decrease as a function of a change in the number of events that the super nodes and local nodes have in common. An instability metric is calculated for the dynamic stochastic network, and an emerging group threat behavior is detected based on a deviation from the instability metric.