Governing System for Cyber Threat Behavior Deviation Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber-security systems are inadequate in addressing evolving and unknown cyber-security threats, with high failure rates due to human error, coordinated attacks, and natural disasters, and are vulnerable to new types of threats.

Innovation Solution

A proactive, governing data processing system that monitors and analyzes data from governed systems to detect deviations from modeled behavior, using advanced modeling and analytics to identify potential cyber-threats and implement countermeasures, such as moving target actions and workload migration, to mitigate adverse outcomes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional reactive cyber-security systems are used, then system simplicity is maintained, but the system fails to address evolving and unknown threats effectively

Engineering Contradiction:
Improvecyber-security effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements behavior modeling that establishes expected system and user behavior patterns in advance. The governing system uses these pre-established models to proactively detect deviations indicating potential threats before they materialize into actual attacks, enabling preventive rather than reactive security responses.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a separate governing data processing system as an intermediary layer between the governed system and threats. This governing system independently monitors behavior, detects anomalies, and implements countermeasures without being part of the core governed system, thereby isolating security functions and reducing overall system complexity while improving security effectiveness.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a governing system with continuous monitoring and predictive analytics is implemented, then cyber-security resilience is improved, but system complexity and resource requirements increase

Engineering Contradiction:
Improvecyber-security resilienceVSAvoidgoverning system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the security architecture into distinct functional modules: behavior modeling components, data capture modules, anomaly detection engines, and countermeasure implementation mechanisms. Each module performs a specific function independently, making the overall complex system manageable through modular design and enabling targeted optimization of individual components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The governing system continuously captures operational data from the governed system, compares it against established behavior models, and uses the feedback from anomaly detection to dynamically adjust monitoring parameters and trigger appropriate countermeasures. This closed-loop feedback mechanism enables adaptive security responses without requiring manual intervention.

Inventive Principle:
Principle #23Feedback

3Loss of time

If proactive countermeasures such as workload migration are implemented, then response time to threats is reduced, but system operational complexity increases

Engineering Contradiction:
Improvethreat response timeVSAvoidcountermeasure implementation complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent pre-configures countermeasure responses for various types of detected anomalies and potential threats. When the governing system detects specific deviation patterns indicating potential security incidents, it automatically executes pre-planned countermeasures such as workload migration, system isolation, or access revocation, eliminating the need for real-time decision-making and reducing response time.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The governing system autonomously performs the complete security response cycle: detecting anomalies through behavior analysis, determining appropriate countermeasures based on pre-established rules and models, and executing those countermeasures without human intervention. This self-service capability reduces response time while managing operational complexity through automation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9129108B2Systems, methods and computer programs providing impact mitigation of cyber-security failures
Publication Date: 2015.09.08 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9129108B2 patent drawing
  • US9129108B2 patent drawing
  • US9129108B2 patent drawing

AI summary

Disclosed is a method and system to operate a governed data processing system in concert with a governing data processing system. The method includes operating a secure governing data processing system to monitor operation of at least one governed data processing system to detect a deviation from modeled user and governed data processing system behavior. The method further includes, upon detecting a deviation from the modeled behavior, taking proactive action to mitigate an occurrence of a potential adverse result of an occurrence of a cyber-security threat.