NETWAR Cyber Threat Detection and Prediction System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer network defense technologies are inadequate in detecting and predicting sophisticated, automated cyber attacks, such as 'Search-Engine Hacks,' due to overwhelming real-time information, inability to accurately identify attacks, and lack of situational awareness, leading to potential catastrophic operational failures.

Innovation Solution

A method and system, known as NETWAR, which utilizes a Tactical and Strategic Attack Detection and Prediction (TSADaP) utility to computationally recognize threats by sensing network data with multiple sensors, performing graph-based search and anomaly detection, and predicting future attacks without requiring full attack signatures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional signature-based detection methods are used, then known attacks can be detected, but the system cannot detect evolved or sophisticated attacks and experiences lag time

Engineering Contradiction:
Improveattack detection accuracyVSAvoidresponse time to attacks
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously monitoring and analyzing network traffic patterns, user behaviors, and system states before attacks occur. The anomaly detection engine establishes baseline behaviors and prepares detection rules in advance, enabling the system to identify attacks as they begin rather than waiting for signature updates.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system transitions from static signature-based detection to dynamic anomaly detection. The detection engine continuously adapts to changing network conditions, learns normal behavior patterns, and dynamically adjusts detection thresholds. This dynamic approach allows the system to detect evolved attacks that deviate from established baselines without requiring pre-defined signatures.

Inventive Principle:
Principle #15Dynamics

2Measurement precision

If comprehensive network surveillance is implemented to detect all attacks, then detection coverage improves, but the overwhelming volume of real-time information makes accurate identification difficult

Engineering Contradiction:
Improveattack identification accuracyVSAvoidinformation processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the complex surveillance task into multiple specialized components: traffic analysis modules, behavior monitoring modules, anomaly detection engines, and response coordination systems. Each segment focuses on specific aspects of network activity, processing relevant data independently before integration. This segmentation reduces the complexity burden on any single component while maintaining comprehensive detection coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces intermediary analysis layers between raw network data and final attack identification. These intermediaries include behavior baselines, anomaly scores, and contextual filters that process and simplify raw surveillance data. The intermediaries translate overwhelming volumes of raw information into manageable indicators of potential attacks, making accurate identification feasible without reducing detection precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If automated tools are used to execute attacks, then attack speed and coordination improve, but defenders lack automated prediction capabilities

Engineering Contradiction:
Improveattack prediction efficiencyVSAvoiddefensive automation level
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The system implements feedback loops where detection results, analyzed patterns, and response outcomes continuously inform and refine detection algorithms. The anomaly detection engine learns from each detected incident, adjusting baselines and improving prediction accuracy over time. This automated feedback mechanism enables the system to adapt to new attack patterns without human intervention, matching the automation level of offensive tools.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary automated analysis of network behaviors, user patterns, and system states to predict potential attacks before they occur. By continuously monitoring and pre-processing data through automated anomaly detection, the system prepares predictions and alerts in advance, enabling defenders to take proactive measures against coordinated automated attacks.

Inventive Principle:
Principle #10Preliminary action

4Loss of information

If defenders manually analyze all security data, then detailed understanding of attacks is achieved, but the workload becomes unmanageable and response time increases

Engineering Contradiction:
Improvesituational awarenessVSAvoidanalyst workload efficiency
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The system performs self-service by automatically monitoring, analyzing, and detecting anomalies without requiring constant human intervention. The anomaly detection engine autonomously establishes baselines, identifies deviations, and generates alerts, freeing analysts from manual data analysis. This self-service capability maintains comprehensive situational awareness while dramatically reducing analyst workload and improving response efficiency.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system introduces automated intermediary analysis layers between raw security data and human analysts. These intermediaries process, filter, and prioritize information, presenting only the most relevant anomalies and threats to analysts. This intermediary processing preserves complete situational awareness in the system while reducing the information burden on human analysts, improving both awareness and productivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7530105B2Tactical and strategic attack detection and prediction
Publication Date: 2009.05.05 NORTHROP GRUMMAN SYSTEMS CORP
  • US7530105B2 patent drawing
  • US7530105B2 patent drawing
  • US7530105B2 patent drawing

AI summary

NETWAR provides a utility that enables detection of both tactical and strategic threats against an individual entity and interrelated/affiliated networks of entities. A distributed network of sensors and evaluators are utilized to detect tactical attacks against one or more entities. Events on the general network are represented as an input graph, which is searched for matches of example pattern graphs that represent tactical attacks. The search is performed using a scalable graph matching engine and an ontology that is periodically updated by a subject matter expert or analyst. NETWAR provides the functionality to determine/understand the strategic significance of the detected tactical attacks by correlating detected tactical attacks on the individual entities to identify the true motive of these attacks as a strategic attack. NETWAR also provides predictive capability to predict future entities and sub-entities that may be targeted based on evaluation of the attack data.