Host Similarity Engine for Network Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing deception mechanisms in networks are limited in detecting all compromised devices during an attack and fail to assess the severity of the threat posed by detected compromised devices, leaving networks insecure and vulnerable.
Innovation Solution
The method involves evaluating weighted attributes of a known compromised host to identify similar hosts and assess threat severity, using a similarity engine to determine candidate items and cluster quality parameters, and updating attribute weights based on user feedback.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If deception mechanisms are implemented to identify compromised servers, then detection capability is improved, but processing resource burden increases and some compromised devices remain undetected
Solution Approach 1:
The system creates a virtual representation (copy) of the compromised host's attributes and characteristics in the form of a query item. This copy is then used to search for and identify similar hosts in the network without requiring direct interaction with or heavy processing of each individual host, thereby reducing processing resource burden while maintaining detection capability.
Solution Approach 2:
The system transforms the detection approach by changing from examining raw host data to evaluating weighted attribute distances. By converting host characteristics into comparable attribute parameters with assigned weights and calculating distance metrics, the system simplifies the detection process and reduces computational complexity while improving reliability.
2Loss of information
If existing deception mechanisms detect compromised servers, then security awareness is improved, but the severity of threats remains unknown and networks remain vulnerable
Solution Approach 1:
The system replaces simple detection mechanisms with a sophisticated evaluation system that calculates weighted attribute distances. This substitution enables the system to not only detect compromised hosts but also assess their similarity to known compromised hosts, thereby inferring threat severity and providing more actionable security intelligence.
Solution Approach 2:
The system implements a feedback mechanism where detected compromised hosts are added to the database of known compromised hosts. This feedback loop continuously improves the system's ability to identify similar hosts and assess threat severity, reducing network vulnerability over time as the database grows and refinement occurs.
3Measurement precision
If attribute weights are assigned to evaluate compromised hosts, then identification accuracy is improved, but system complexity increases
Solution Approach 1:
The system segments the host evaluation process into distinct attribute components, each with its own weight. By dividing the complex task of host assessment into manageable attribute segments (e.g., OS type, service ports, configuration characteristics), the system achieves higher identification accuracy while keeping each segment's complexity manageable.
Solution Approach 2:
The weighted attribute evaluation system serves multiple functions: it identifies compromised hosts, assesses their similarity to known threats, determines threat severity, and provides feedback for continuous improvement. This multi-functionality justifies the increased system complexity by delivering comprehensive security analysis in a unified framework.
Data Source
AI summary
Systems and methods for identifying potentially compromised devices using attributes of a known compromised device may be provided. In one embodiment, an attribute set can be constructed for the compromised hosts using data from these logs. Weights can be assigned to each attribute in the attribute set initially, and further weights can be learned using audits by a user. This attribute set can be used in the disclosed systems and methods for identifying hosts that are similar to compromised hosts. The similar items can be used as hosts for deception mechanisms, can be taken off the network as being likely compromised or likely to become compromised, or quarantined.


