Hyper Cylinder Model for Cyber Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cyber-threat detection methods rely on identifying threats based on rules associated with previously identified threats, which is not sufficiently secure, and are unable to respond to fresh threats or detect subtle shifts and patterns in human and machine behavior.
Innovation Solution
A method and system that uses a Bayesian probabilistic model, referred to as the Hyper Cylinder model, to automatically detect cyber threats by analyzing metrics derived from input data related to activity on a computer system, without prior knowledge of the threat type, and updates the model of normal behavior dynamically.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional signature-driven threat detection methods are used, then known threats can be identified, but the system cannot detect novel threats or subtle behavioral changes
Solution Approach 1:
Instead of detecting threats by matching known threat signatures, the patent inverts the approach by first establishing a model of normal behavior and then detecting deviations from this baseline. This allows the system to identify both known and novel threats based on anomalous behavior patterns rather than requiring pre-defined threat knowledge.
Solution Approach 2:
The system performs preliminary action by continuously learning and updating the normal behavior model before threats occur. This proactive establishment of behavioral baselines enables the detection of subtle changes and novel threats without requiring real-time analysis of threat signatures.
2Reliability
If rule-based threat detection systems are deployed, then previously identified threats can be detected, but the systems generate high false positive rates and cannot adapt to changing threat landscapes
Solution Approach 1:
The system implements feedback by continuously monitoring actual system behavior and using this information to refine and update the normal behavior model. This ongoing feedback loop allows the system to distinguish between legitimate variations and actual threats, reducing false positives while maintaining detection accuracy.
Solution Approach 2:
The patent applies dynamics by making the threat detection system adaptive and evolving rather than static. The normal behavior model is continuously updated to reflect changing system conditions and legitimate behavior patterns, allowing the system to maintain precision as threats and normal operations evolve over time.
3Object-affected harmful factors
If traditional security models with strict perimeter control are used, then network boundaries can be protected, but the system cannot detect insider threats or threats from authorized access
Solution Approach 1:
The patent extends the inverted approach to insider threat detection by establishing individual normal behavior models for authorized users and devices. This allows the system to detect anomalies in behavior from authorized sources, identifying insider threats based on deviations from expected patterns rather than relying on perimeter-based access control.
Data Source
AI summary
Disclosed herein is a method for detection of a cyber-threat to a computer system. The method is arranged to be performed by a processing apparatus. The method comprises receiving input data associated with a first entity associated with the computer system, deriving metrics from the input data, the metrics representative of characteristics of the received input data, analysing the metrics using one or more models, and determining, in accordance with the analysed metrics and a model of normal behavior of the first entity, a cyber-threat risk parameter indicative of a likelihood of a cyber-threat. A computer readable medium, a computer program and a threat detection system are also disclosed.

