Network Traffic Analysis for Cyber Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems struggle to distinguish between malicious and benign network activities, are costly for data gathering and forensic investigation, and rely on traditional threat intelligence that can be easily subverted by sophisticated attackers, making it difficult to detect and remediate cyber threats in a timely and cost-effective manner.

Innovation Solution

The system analyzes network traffic data from multiple networks in real-time using analytic models, correlation engines, and enrichment engines to identify and correlate similar events, generating feature vectors and applying similarity metrics to detect anomalies and trends, enabling rapid investigation and remediation across networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional threat intelligence sharing focusing on signatures is used, then knowledge sharing about malware is simplified, but the system is easily subverted by sophisticated attackers who can change domains and IP addresses

Engineering Contradiction:
Improvesimplicity of threat intelligence sharingVSAvoideffectiveness of threat detection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system transitions from static signature-based detection to dynamic behavior-based detection. Instead of relying on fixed malware signatures that can be easily changed, the system monitors behavioral parameters such as network traffic patterns, process creation sequences, and system call sequences. These behavioral parameters are more difficult for attackers to manipulate while maintaining detection effectiveness.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces the mechanical approach of signature matching with a behavioral modeling approach. Rather than using rigid signature databases that can be subverted, the system employs analytical models that learn and adapt to normal behavior patterns, enabling detection of anomalies and sophisticated attacks that deviate from established norms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If manual searching and analysis of cyber threats is performed, then detailed investigation can be conducted, but the process becomes slow and expensive from a resource standpoint

Engineering Contradiction:
Improvedepth of threat analysisVSAvoidspeed and cost of threat detection
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system performs self-service analysis by automatically collecting, analyzing, and correlating security event data without requiring extensive manual intervention. The analytical models autonomously identify threats, determine their severity, and prioritize them for investigation, significantly reducing the resources needed while maintaining analysis depth.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary analysis and triage of security events automatically before they reach human analysts. By pre-filtering, prioritizing, and contextualizing threats based on behavioral models and correlation analysis, the system prepares detailed investigation packages that reduce the time and effort required for manual analysis.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If data gathering and forensic investigation are conducted to determine root causes, then comprehensive understanding of threats is achieved, but the process becomes prohibitively costly at scale

Engineering Contradiction:
Improvecompleteness of threat informationVSAvoidcost efficiency of investigation
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The system extracts and focuses analysis only on the most critical behavioral patterns and threat indicators rather than conducting comprehensive forensic investigations on all data. By identifying and isolating significant behavioral anomalies through analytical models, the system obtains sufficient threat intelligence without the prohibitive cost of exhaustive data gathering and forensic analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies partial analysis to the most critical aspects of security events rather than attempting complete forensic investigation of all data. By focusing analytical resources on high-value behavioral indicators and using correlation analysis to identify patterns, the system achieves cost-effective threat detection without sacrificing essential investigative depth.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If behavioral models are used to detect cyber threats, then detection capability is improved, but the ability to distinguish between threats and benign activity remains insufficient

Engineering Contradiction:
Improvedetection capabilityVSAvoidaccuracy of threat distinction
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The system employs dynamic behavioral models that continuously learn from and adapt to normal behavior patterns in the environment. Rather than using static detection rules, the models dynamically adjust their understanding of acceptable behavior based on observed data, enabling more accurate distinction between legitimate activity and threats while maintaining high detection capability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms where detected behaviors and their outcomes are fed back into the analytical models to refine their accuracy. This continuous learning process allows the models to improve their ability to distinguish between benign activity and threats by adjusting their behavioral baselines based on actual system responses and user feedback.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240291843A1Systems and methods for analyzing cybersecurity events
Publication Date: 2024.08.29 IRONNET CYBERSECURITY INC
  • US20240291843A1 patent drawing
  • US20240291843A1 patent drawing
  • US20240291843A1 patent drawing

AI summary

Methods and systems for the detection, identification, analysis of cybersecurity events in order to support prevention of the persistence of threats, malware or other harmful events are provided. The methods and systems of the present invention enable a user to find similar anomalous network traffic within a single network or across multiple networks. The methods and systems identify and correlate activity in order to analyze potential threats within a network by providing broader contextual information about how those threats relate to other activity within the network or across a sector or country.