Multiphase Threat Analysis Engine for Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security tools struggle to effectively analyze and differentiate between legitimate and suspicious network traffic, particularly when the nature and impact of unknown threats are unclear, leading to potential network infiltration and harm.
Innovation Solution
Implementing a high-interaction network that emulates parts of the network to analyze suspect traffic, generating indicators to determine threat susceptibility and source, and using multiphase threat analysis and correlation to reconstruct attack sequences, along with deceptive security mechanisms to divert and detect threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If network security tools analyze suspect network traffic using traditional methods, then they can identify known threats, but they struggle to effectively analyze and differentiate between legitimate and suspicious traffic, particularly unknown threats
Solution Approach 1:
The patent introduces a high-interaction network emulator as an intermediary system between the network security tool and the actual network. This emulator creates a controlled environment where suspect traffic can be analyzed without directly exposing the real network to potential threats. The emulator acts as a mediator that safely contains unknown traffic patterns, allowing detailed analysis of attack techniques while isolating the actual network from harm.
Solution Approach 2:
The patent creates a virtual copy of the network infrastructure within the high-interaction network emulator. This copy includes emulated network elements such as routers, switches, servers, and end devices that replicate the actual network's structure and behavior. By analyzing traffic against this realistic virtual replica rather than abstract models, the security tool can accurately identify unknown threats while maintaining network safety.
2Loss of information
If the network analyzes suspect traffic in detail to understand unknown threats, then threat intelligence improves, but network security tools lack the capability to determine impact and susceptibility without high-interaction emulation
Solution Approach 1:
The patent segments the network analysis function into separate components: the high-interaction network emulator handles complex traffic simulation and impact analysis, while the network security tool focuses on pattern recognition and threat identification. This segmentation allows each component to specialize in specific tasks, improving overall threat intelligence quality while managing system complexity through functional division.
Solution Approach 2:
The high-interaction network emulator serves as an intermediary that bridges the gap between simple traffic monitoring and comprehensive threat analysis. It provides the actual network with the capability to understand unknown threats by safely containing and observing traffic behavior in a controlled environment, thereby improving threat intelligence without requiring the entire network infrastructure to become overly complex.
3Reliability
If traditional network security tools block suspect traffic, then known threats are stopped, but legitimate traffic may be disrupted and network response capability is reduced
Solution Approach 1:
The patent converts the potential harm of blocking traffic into a benefit by using the high-interaction network emulator to analyze and learn from traffic patterns. Instead of simply blocking suspect traffic, the system emulates network conditions to observe how traffic behaves, identifies genuine threats, and develops more intelligent blocking strategies. This approach improves security reliability while preserving network operation continuity by making blocking decisions based on comprehensive analysis rather than simple heuristics.
Data Source
AI summary
Provided are systems, methods, and computer-program products for a targeted threat intelligence engine, implemented in a network device. The network device may receive incident data, which may include information derived starting at detection of an attack on the network until detection of an event. The network device may include analytic engines that run in a predetermined order. An analytic engine can analyze incident data of a certain data type, and can produce a result indicating whether a piece of data is associated with the attack. The network device may produce a report of the attack, which may include correlating the results from the analytic engines. The report may provide information about a sequence of events that occurred in the course of the attack. The network device may use the record of the attack to generate indicators, which may describe the attack, and may facilitate configuring security for a network.


