Hybrid Intrusion Response System Using ML and Knowledge Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing intrusion response systems face challenges in determining appropriate responses to computer system behavior, often leading to inappropriate actions that impact system performance, especially when faced with new or unknown behaviors.

Innovation Solution

A hybrid intrusion response system combining knowledge-based and prediction-based approaches, using prior responses and trained machine learning models to determine responses, which allows for effective mitigation of known attacks while adapting to new behaviors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If an active intrusion response system automatically generates actions to mitigate attacks, then the system can effectively respond to high-speed attacks in large-scale computing environments, but the consequences of the action can be significant and undesirably impact system performance if the action selected is inappropriate for the activity performed

Engineering Contradiction:
Improveresponse speedVSAvoidresponse accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent combines rule-based response generation (providing fast automated responses) with machine learning-based response prediction (providing accurate context-aware responses) into a unified intrusion response system. The system merges both approaches to determine final responses, ensuring both speed and accuracy are achieved simultaneously.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a response prediction component using machine learning models as an intermediary between the intrusion detection system and the response execution system. This intermediary predicts the appropriate response by analyzing historical data and behavior patterns, preventing inappropriate actions while maintaining automated response capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a knowledge-based system uses rules derived from prior responses to determine actions, then the system can leverage historical knowledge for consistent responses, but the system lacks flexibility when faced with new or unknown behaviors

Engineering Contradiction:
Improveresponse consistencyVSAvoidresponse flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent makes the response determination system dynamic by incorporating machine learning models that can adapt to new behaviors. The system transitions from static rule-based responses to dynamic prediction-based responses that learn from new data, allowing the system to maintain consistency for known threats while adapting to novel attack patterns.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a composite response determination mechanism that combines rule-based knowledge (providing consistency) with machine learning predictions (providing adaptability). This composite approach integrates both deterministic rules and probabilistic predictions to achieve both reliability and flexibility in response generation.

Inventive Principle:
Principle #40Composite materials

3Adaptability or versatility

If a machine learning model predicts responses based on trained behavior data, then the system can adapt to new behaviors, but the model may produce inaccurate predictions for behaviors not well-represented in training data

Engineering Contradiction:
Improveresponse adaptabilityVSAvoidprediction accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent prepares the system in advance by training machine learning models on comprehensive historical behavior data to cushion against future unknown threats. The models are pre-trained on diverse attack patterns and normal behaviors, creating a robust foundation that improves prediction accuracy for novel threats while maintaining adaptability.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

The patent implements feedback mechanisms where the outcomes of predicted responses are fed back into the machine learning model for continuous improvement. The system learns from the effectiveness of past predictions, refining its accuracy over time while maintaining its ability to adapt to new behavior patterns through ongoing training.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240073241A1Intrusion response determination
Publication Date: 2024.02.29 BRITISH TELECOM PLC
  • US20240073241A1 patent drawing
  • US20240073241A1 patent drawing
  • US20240073241A1 patent drawing

AI summary

An intrusion response system (IRS) can include a knowledge-based intrusion response (IR) component configured to use knowledge of prior responses to prior behavior of at least one computer system to determine a first response to behavior of a target computer system; a prediction-based IR component configured to use at least one trained machine learning (ML) model of behavior of the target computer system to predict a second response to the behavior of the target computer system; and a response component configured to determine an output response to the behavior of the target computer system based on at least one of the first response and the second response.