External Cyberattack Detection via Infrastructure Graph Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity solutions for network infrastructure monitoring are primarily focused on internal integration and do not effectively detect cyberattacks from an external perspective, lacking comprehensive monitoring of the cyberattack surface without intrusion.

Innovation Solution

A method and system that analyze network infrastructure elements represented as a graph from an external perspective, identifying indicators of compromise by scanning protected infrastructure elements and linked elements, generating warnings for potential cyberattacks without internal integration, using a computing device positioned externally to the network infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If vulnerability scanners and internal monitoring tools are used, then detection capability is improved, but system complexity and integration requirements increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary external monitoring system that observes the network infrastructure without requiring internal integration. This mediator collects data from external sources and analyzes it to detect cyberattacks, thereby improving detection capability while avoiding the complexity of internal system integration.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the monitoring function from the internal network infrastructure and places it externally. By taking out the detection capability from the complex internal system, the patent achieves effective cyberattack detection without requiring integration with internal systems, thus reducing system complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If internal integration and comprehensive monitoring are implemented, then security coverage is improved, but intrusion and internal system dependency increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidintrusion level
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The external monitoring system acts as an intermediary that provides comprehensive security coverage without intruding into the internal network. It observes external indicators of compromise and analyzes them to detect threats, maintaining security coverage while avoiding internal system intrusion and dependency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the monitoring function from the internal network infrastructure, creating an independent external monitoring system. This segmentation allows comprehensive security coverage through external observation while eliminating the need for internal integration and reducing intrusion into the protected system.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If external monitoring without integration is used, then system independence is improved, but detection precision may worsen

Engineering Contradiction:
Improvesystem independenceVSAvoiddetection precision
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The external monitoring system is designed with multi-functionality to perform various detection tasks using external data sources. It can analyze different types of external indicators (domain registrations, SSL certificates, IP addresses, web services) to maintain high detection precision while remaining independent from internal systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements preliminary action by proactively monitoring external indicators of compromise before attacks penetrate internal systems. The external monitoring system continuously checks for suspicious patterns in domain registrations, SSL certificates, and web service configurations, enabling early threat detection with high precision while maintaining system independence.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11985147B2System and method for detecting a cyberattack
Publication Date: 2024.05.14 GRP IB GLOBAL PTE LTD
  • US11985147B2 patent drawing
  • US11985147B2 patent drawing
  • US11985147B2 patent drawing

AI summary

A method and a system for identifying indicators of compromise in a network infrastructure are provided. The method being executable by a computing device communicatively couplable to the network infrastructure, the computing devices being positioned outside a perimeter of the network infrastructure. The method comprises: obtaining an infrastructure graph for the network infrastructure, identifying, for a given protected infrastructure element, a portion of the infrastructure graph including vertices representative of linked infrastructure elements; analyzing a given one of the linked infrastructure elements to determine a respective value thereof; determining whether the respective value of the given one of the linked infrastructure elements is indicative of the network infrastructure being compromised; in response to the respective value of any one of the linked infrastructure elements associated to the given protected infrastructure element being indicative of the network infrastructure being compromised: generating and transmitting at least one warning about a potential cyberattack.