Multiphase Threat Analysis Engine for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security tools struggle to effectively analyze and differentiate between legitimate and suspicious network traffic, particularly when the nature and impact of unknown threats are unclear, leading to potential network infiltration and harm.

Innovation Solution

Implementing a high-interaction network that emulates parts of the network to analyze suspect traffic, generating indicators to determine threat susceptibility and source, and using multiphase threat analysis and correlation to reconstruct attack sequences, along with deceptive security mechanisms to divert and detect threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network security tools analyze suspect network traffic using traditional methods, then they can identify known threats, but they struggle to effectively analyze and differentiate between legitimate and suspicious traffic, particularly unknown threats

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidunknown threat analysis difficulty
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a high-interaction network emulator as an intermediary system between the network security tool and the actual network. This emulator creates a controlled environment where suspect traffic can be analyzed without directly exposing the real network to potential threats. The emulator acts as a mediator that safely contains unknown traffic patterns, allowing detailed analysis of attack techniques while isolating the actual network from harm.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a virtual copy of the network infrastructure within the high-interaction network emulator. This copy includes emulated network elements such as routers, switches, servers, and end devices that replicate the actual network's structure and behavior. By analyzing traffic against this realistic virtual replica rather than abstract models, the security tool can accurately identify unknown threats while maintaining network safety.

Inventive Principle:
Principle #26Copying

2Loss of information

If the network analyzes suspect traffic in detail to understand unknown threats, then threat intelligence improves, but network security tools lack the capability to determine impact and susceptibility without high-interaction emulation

Engineering Contradiction:
Improvethreat intelligence qualityVSAvoidanalysis system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent segments the network analysis function into separate components: the high-interaction network emulator handles complex traffic simulation and impact analysis, while the network security tool focuses on pattern recognition and threat identification. This segmentation allows each component to specialize in specific tasks, improving overall threat intelligence quality while managing system complexity through functional division.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The high-interaction network emulator serves as an intermediary that bridges the gap between simple traffic monitoring and comprehensive threat analysis. It provides the actual network with the capability to understand unknown threats by safely containing and observing traffic behavior in a controlled environment, thereby improving threat intelligence without requiring the entire network infrastructure to become overly complex.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If traditional network security tools block suspect traffic, then known threats are stopped, but legitimate traffic may be disrupted and network response capability is reduced

Engineering Contradiction:
Improvenetwork security reliabilityVSAvoidnetwork operation continuity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent converts the potential harm of blocking traffic into a benefit by using the high-interaction network emulator to analyze and learn from traffic patterns. Instead of simply blocking suspect traffic, the system emulates network conditions to observe how traffic behaves, identifies genuine threats, and develops more intelligent blocking strategies. This approach improves security reliability while preserving network operation continuity by making blocking decisions based on comprehensive analysis rather than simple heuristics.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS10270789B2Multiphase threat analysis and correlation engine
Publication Date: 2019.04.23 ACALVIO TECH
  • US10270789B2 patent drawing
  • US10270789B2 patent drawing
  • US10270789B2 patent drawing

AI summary

Provided are systems, methods, and computer-program products for a targeted threat intelligence engine, implemented in a network device. The network device may receive incident data, which may include information derived starting at detection of an attack on the network until detection of an event. The network device may include analytic engines that run in a predetermined order. An analytic engine can analyze incident data of a certain data type, and can produce a result indicating whether a piece of data is associated with the attack. The network device may produce a report of the attack, which may include correlating the results from the analytic engines. The report may provide information about a sequence of events that occurred in the course of the attack. The network device may use the record of the attack to generate indicators, which may describe the attack, and may facilitate configuring security for a network.