Intrusion Response System Action Verification Module
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Intrusion response systems (IRSs) face challenges in selecting appropriate actions to mitigate cyber intrusions, as both knowledge-driven and data-driven approaches can lead to inappropriate or infeasible actions, especially in automated systems where human verification is impractical.
Innovation Solution
An intrusion response system with an action verification module that receives proposed mitigating actions, identifies verification tests, performs these tests, calculates a verification score, and determines if it exceeds a predetermined threshold to ensure the appropriateness and feasibility of the actions before execution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If automated action selection is used in intrusion response systems, then response speed and productivity are improved, but the risk of selecting inappropriate or infeasible actions increases
Solution Approach 1:
The patent implements a feedback mechanism where the results of verification tests are fed back into the action selection process. The system performs verification tests on selected actions and uses the outcomes to adjust future action selections, thereby improving reliability while maintaining automated response speed.
Solution Approach 2:
The patent introduces an intermediary verification module between the action selection component and the action execution component. This intermediary performs verification tests and acts as a mediator to filter out inappropriate actions before they are executed, resolving the contradiction between fast automated response and reliable action selection.
2Reliability
If verification tests are performed on all proposed actions, then action appropriateness is improved, but system complexity and processing time increase
Solution Approach 1:
The patent applies partial verification by selecting and performing only the most relevant verification tests based on the specific intrusion context and action type, rather than executing all possible verification tests. This reduces system complexity while maintaining sufficient verification accuracy.
Solution Approach 2:
The patent implements local quality by tailoring the verification process to the specific characteristics of each action and intrusion scenario. Different verification tests are applied selectively based on the local context, rather than applying a uniform verification procedure to all actions, thereby reducing unnecessary complexity.
3Reliability
If human verification of actions is performed, then action appropriateness is improved, but response time and productivity decrease
Solution Approach 1:
The patent replaces the mechanical system of human verification with an automated electronic verification system that performs verification tests using computational algorithms. This substitution maintains high reliability in action selection while eliminating the time loss associated with human review processes.
Solution Approach 2:
The patent implements self-service by enabling the intrusion response system to automatically verify and validate its own proposed actions without external human intervention. The system performs verification tests and makes autonomous decisions about action appropriateness, maintaining reliability while ensuring rapid response times.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An intrusion response system is disclosed comprising an action verification module. The action verification module is configured to receive an identifier associated with at least one proposed mitigating action to perform in response to a detected cyber intrusion and details of the detected cyber intrusion, identify one or more verification tests to be performed, perform each of the one or more verification tests to obtain a respective one or more verification outcomes, calculate a verification score associated with the at least one proposed mitigating action based on the respective one or more verification outcomes, and determine whether the verification score exceeds a predetermined threshold value. Also disclosed is a corresponding method of verifying a proposed mitigating action to perform in response to a detected cyber intrusion.