Host Similarity Engine for Network Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing deception mechanisms in networks are limited in detecting all compromised devices during an attack and fail to assess the severity of the threat posed by detected compromised devices, leaving networks insecure and vulnerable.

Innovation Solution

The method involves evaluating weighted attributes of a known compromised host to identify similar hosts and assess threat severity, using a similarity engine to determine candidate items and cluster quality parameters, and updating attribute weights based on user feedback.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If deception mechanisms are implemented to identify compromised servers, then detection capability is improved, but processing resource burden increases and some compromised devices remain undetected

Engineering Contradiction:
Improvedetection capabilityVSAvoidprocessing resource burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system creates a virtual representation (copy) of the compromised host's attributes and characteristics in the form of a query item. This copy is then used to search for and identify similar hosts in the network without requiring direct interaction with or heavy processing of each individual host, thereby reducing processing resource burden while maintaining detection capability.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system transforms the detection approach by changing from examining raw host data to evaluating weighted attribute distances. By converting host characteristics into comparable attribute parameters with assigned weights and calculating distance metrics, the system simplifies the detection process and reduces computational complexity while improving reliability.

Inventive Principle:
Principle #35Parameter changes

2Loss of information

If existing deception mechanisms detect compromised servers, then security awareness is improved, but the severity of threats remains unknown and networks remain vulnerable

Engineering Contradiction:
Improvethreat severity informationVSAvoidnetwork vulnerability
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The system replaces simple detection mechanisms with a sophisticated evaluation system that calculates weighted attribute distances. This substitution enables the system to not only detect compromised hosts but also assess their similarity to known compromised hosts, thereby inferring threat severity and providing more actionable security intelligence.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system implements a feedback mechanism where detected compromised hosts are added to the database of known compromised hosts. This feedback loop continuously improves the system's ability to identify similar hosts and assess threat severity, reducing network vulnerability over time as the database grows and refinement occurs.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If attribute weights are assigned to evaluate compromised hosts, then identification accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveidentification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the host evaluation process into distinct attribute components, each with its own weight. By dividing the complex task of host assessment into manageable attribute segments (e.g., OS type, service ports, configuration characteristics), the system achieves higher identification accuracy while keeping each segment's complexity manageable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The weighted attribute evaluation system serves multiple functions: it identifies compromised hosts, assesses their similarity to known threats, determines threat severity, and provides feedback for continuous improvement. This multi-functionality justifies the increased system complexity by delivering comprehensive security analysis in a unified framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9836512B1Systems and methods for identifying similar hosts
Publication Date: 2017.12.05 ACALVIO TECH
  • US9836512B1 patent drawing
  • US9836512B1 patent drawing
  • US9836512B1 patent drawing

AI summary

Systems and methods for identifying potentially compromised devices using attributes of a known compromised device may be provided. In one embodiment, an attribute set can be constructed for the compromised hosts using data from these logs. Weights can be assigned to each attribute in the attribute set initially, and further weights can be learned using audits by a user. This attribute set can be used in the disclosed systems and methods for identifying hosts that are similar to compromised hosts. The similar items can be used as hosts for deception mechanisms, can be taken off the network as being likely compromised or likely to become compromised, or quarantined.