Intrusion Response System Action Verification Module

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Intrusion response systems (IRSs) face challenges in selecting appropriate actions to mitigate cyber intrusions, as both knowledge-driven and data-driven approaches can lead to inappropriate or infeasible actions, especially in automated systems where human verification is impractical.

Innovation Solution

An intrusion response system with an action verification module that receives proposed mitigating actions, identifies verification tests, performs these tests, calculates a verification score, and determines if it exceeds a predetermined threshold to ensure the appropriateness and feasibility of the actions before execution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated action selection is used in intrusion response systems, then response speed and productivity are improved, but the risk of selecting inappropriate or infeasible actions increases

Engineering Contradiction:
Improveresponse speedVSAvoidaction appropriateness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the results of verification tests are fed back into the action selection process. The system performs verification tests on selected actions and uses the outcomes to adjust future action selections, thereby improving reliability while maintaining automated response speed.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary verification module between the action selection component and the action execution component. This intermediary performs verification tests and acts as a mediator to filter out inappropriate actions before they are executed, resolving the contradiction between fast automated response and reliable action selection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If verification tests are performed on all proposed actions, then action appropriateness is improved, but system complexity and processing time increase

Engineering Contradiction:
Improveaction verification accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies partial verification by selecting and performing only the most relevant verification tests based on the specific intrusion context and action type, rather than executing all possible verification tests. This reduces system complexity while maintaining sufficient verification accuracy.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent implements local quality by tailoring the verification process to the specific characteristics of each action and intrusion scenario. Different verification tests are applied selectively based on the local context, rather than applying a uniform verification procedure to all actions, thereby reducing unnecessary complexity.

Inventive Principle:
Principle #3Local quality

3Reliability

If human verification of actions is performed, then action appropriateness is improved, but response time and productivity decrease

Engineering Contradiction:
Improveaction appropriatenessVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces the mechanical system of human verification with an automated electronic verification system that performs verification tests using computational algorithms. This substitution maintains high reliability in action selection while eliminating the time loss associated with human review processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent implements self-service by enabling the intrusion response system to automatically verify and validate its own proposed actions without external human intervention. The system performs verification tests and makes autonomous decisions about action appropriateness, maintaining reliability while ensuring rapid response times.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4366233A1Verification method for intrusion response system
Publication Date: 2024.05.08 BRITISH TELECOM PLC
  • EP4366233A1 patent drawingFigure 1
  • EP4366233A1 patent drawingFigure 2
  • EP4366233A1 patent drawingFigure 3

AI summary

An intrusion response system is disclosed comprising an action verification module. The action verification module is configured to receive an identifier associated with at least one proposed mitigating action to perform in response to a detected cyber intrusion and details of the detected cyber intrusion, identify one or more verification tests to be performed, perform each of the one or more verification tests to obtain a respective one or more verification outcomes, calculate a verification score associated with the at least one proposed mitigating action based on the respective one or more verification outcomes, and determine whether the verification score exceeds a predetermined threshold value. Also disclosed is a corresponding method of verifying a proposed mitigating action to perform in response to a detected cyber intrusion.