Governing System for Cyber Threat Behavior Deviation Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cyber-security systems are inadequate in addressing evolving and unknown cyber-security threats, with high failure rates due to human error, coordinated attacks, and natural disasters, and are vulnerable to new types of threats.
Innovation Solution
A proactive, governing data processing system that monitors and analyzes data from governed systems to detect deviations from modeled behavior, using advanced modeling and analytics to identify potential cyber-threats and implement countermeasures, such as moving target actions and workload migration, to mitigate adverse outcomes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional reactive cyber-security systems are used, then system simplicity is maintained, but the system fails to address evolving and unknown threats effectively
Solution Approach 1:
The patent implements behavior modeling that establishes expected system and user behavior patterns in advance. The governing system uses these pre-established models to proactively detect deviations indicating potential threats before they materialize into actual attacks, enabling preventive rather than reactive security responses.
Solution Approach 2:
The patent introduces a separate governing data processing system as an intermediary layer between the governed system and threats. This governing system independently monitors behavior, detects anomalies, and implements countermeasures without being part of the core governed system, thereby isolating security functions and reducing overall system complexity while improving security effectiveness.
2Reliability
If a governing system with continuous monitoring and predictive analytics is implemented, then cyber-security resilience is improved, but system complexity and resource requirements increase
Solution Approach 1:
The patent divides the security architecture into distinct functional modules: behavior modeling components, data capture modules, anomaly detection engines, and countermeasure implementation mechanisms. Each module performs a specific function independently, making the overall complex system manageable through modular design and enabling targeted optimization of individual components.
Solution Approach 2:
The governing system continuously captures operational data from the governed system, compares it against established behavior models, and uses the feedback from anomaly detection to dynamically adjust monitoring parameters and trigger appropriate countermeasures. This closed-loop feedback mechanism enables adaptive security responses without requiring manual intervention.
3Loss of time
If proactive countermeasures such as workload migration are implemented, then response time to threats is reduced, but system operational complexity increases
Solution Approach 1:
The patent pre-configures countermeasure responses for various types of detected anomalies and potential threats. When the governing system detects specific deviation patterns indicating potential security incidents, it automatically executes pre-planned countermeasures such as workload migration, system isolation, or access revocation, eliminating the need for real-time decision-making and reducing response time.
Solution Approach 2:
The governing system autonomously performs the complete security response cycle: detecting anomalies through behavior analysis, determining appropriate countermeasures based on pre-established rules and models, and executing those countermeasures without human intervention. This self-service capability reduces response time while managing operational complexity through automation.
Data Source
AI summary
Disclosed is a method and system to operate a governed data processing system in concert with a governing data processing system. The method includes operating a secure governing data processing system to monitor operation of at least one governed data processing system to detect a deviation from modeled user and governed data processing system behavior. The method further includes, upon detecting a deviation from the modeled behavior, taking proactive action to mitigate an occurrence of a potential adverse result of an occurrence of a cyber-security threat.


