Network Threat Detection via Multi-Indicator Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions fail to detect sophisticated malware, lateral movement, data exfiltration, and inside attacks within complex networks, leading to data loss, downtime, and high recovery costs, as they rely on outdated signature and heuristic matching methods that are ineffective against advanced threat activities.

Innovation Solution

A system that monitors both north-south and east-west traffic using multiple collectors to detect first and second-order indicators of compromise, generating a risk score and incident alerts to prevent and respond to threats across the entire kill chain, including lateral movement and data exfiltration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If legacy security solutions use structured processes (signature and heuristics matching) to detect threats, then the detection process is simple and fast, but they fail to detect sophisticated malware, lateral movement, data exfiltration, and inside attacks

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The detection system is segmented into multiple independent collectors that monitor different aspects of network traffic (north-south and east-west traffic). Each collector focuses on specific indicators of compromise, allowing the system to detect sophisticated threats without requiring a single complex detection engine. This segmentation enables parallel processing of multiple threat vectors simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transitions from traditional single-dimension signature matching to multi-dimensional analysis by correlating first-order indicators (malware signatures, known attack patterns) with second-order indicators (anomalous behavior patterns, lateral movement signatures, data exfiltration indicators). This dimensional expansion enables detection of previously undetectable threat activities.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If current security solutions focus on detecting threat acts of infecting or penetrating a target system, then they can detect initial malware infections, but they fail to detect lateral movement and data exfiltration

Engineering Contradiction:
Improvecomprehensive threat detectionVSAvoiddetection difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system implements continuous monitoring of network traffic throughout the entire kill chain, from initial infection through lateral movement to data exfiltration. Multiple collectors continuously analyze north-south traffic (external communications) and east-west traffic (internal network communications), ensuring no stage of the attack lifecycle goes undetected. This continuous action maintains constant security coverage across all threat phases.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system introduces second-order indicators as intermediary detection mechanisms that bridge the gap between initial malware detection and advanced threat detection. These second-order indicators act as mediators that translate complex, subtle threat activities (lateral movement, data exfiltration) into detectable patterns, making previously undetectable activities measurable and identifiable.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security solutions use traditional detection methods, then the system complexity is low, but they fail to detect sophisticated malware that hides within complex business applications and network protocols

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the detection function into multiple specialized collectors, each designed to detect specific types of threats and indicators. This segmentation allows each collector to remain relatively simple while the aggregate system achieves comprehensive detection capability. Each collector can be independently maintained and updated without affecting the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The multiple collectors are designed with universal functionality to detect various types of threats (malware, lateral movement, data exfiltration, inside attacks) across different network traffic types (north-south and east-west). This multi-functionality allows a single collector architecture to handle diverse threat scenarios without requiring specialized complex systems for each threat type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10326778B2System and method for detecting lateral movement and data exfiltration
Publication Date: 2019.06.18 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10326778B2 patent drawing
  • US10326778B2 patent drawing
  • US10326778B2 patent drawing

AI summary

A system configured to detect a threat activity on a network. The system including a digital device configured to detect a first order indicator of compromise on a network, detect a second order indicator of compromise on the network, generate a risk score based on correlating said first order indicator of compromise on the network with the second order indicator of compromise on said network, and generate at least one incident alert based on comparing the risk score to a threshold.