Neural Embeddings Forecast Cyber Attacks from Pattern of Life Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity solutions are reactionary, failing to predict and classify cyber attacks proactively, relying on rule and signature-based methods that struggle to adapt to changing Advanced Persistent Threats and new attack methods, limiting real-time preventative actions.

Innovation Solution

A method and system using neural embeddings based on pattern of life data, combining analytical and natural language processing features to forecast and classify potential cyber attacks by constructing and evolving feature vectors within a neural network, enabling proactive defense.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If rule and signature-based methods are used for cyber attack detection, then the system can detect known attacks, but it cannot adapt to new attack methods and Advanced Persistent Threats

Engineering Contradiction:
Improveadaptability to new attack methodsVSAvoiddetection accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary action by forecasting future cyber attacks before they occur. It uses machine learning models to analyze historical attack patterns and predict upcoming attacks, enabling proactive defense measures to be implemented in advance rather than reacting after attacks occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional mechanical rule-based and signature-based detection systems with intelligent machine learning systems. These systems use neural networks and pattern recognition algorithms to automatically adapt to new attack methods, eliminating the need for manual rule updates and providing continuous adaptation to evolving threats.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If reactive cybersecurity solutions are implemented, then the system can respond to known threats, but it fails to predict and prevent future attacks

Engineering Contradiction:
Improvethreat response capabilityVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by forecasting future cyber attacks before they occur. It uses machine learning models to analyze historical attack patterns and predict upcoming attacks, enabling proactive defense measures to be implemented in advance rather than reacting after attacks occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where attack detection results, response outcomes, and new threat intelligence are fed back into the machine learning models. This feedback mechanism allows the system to continuously improve its prediction accuracy and adapt to emerging attack patterns, creating a self-enhancing security system.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If traditional detection methods are used, then the system can identify current attacks, but it cannot classify and predict future attack types

Engineering Contradiction:
Improveattack identification accuracyVSAvoidattack classification capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent replaces traditional mechanical rule-based and signature-based detection systems with intelligent machine learning systems. These systems use neural networks and pattern recognition algorithms to automatically adapt to new attack methods, eliminating the need for manual rule updates and providing continuous adaptation to evolving threats.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system implements continuous feedback loops where attack detection results, response outcomes, and new threat intelligence are fed back into the machine learning models. This feedback mechanism allows the system to continuously improve its prediction accuracy and adapt to emerging attack patterns, creating a self-enhancing security system.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9998491B2Forecasting and classifying cyber-attacks using neural embeddings based on pattern of life data
Publication Date: 2018.06.12 KYNDRYL INC
  • US9998491B2 patent drawing
  • US9998491B2 patent drawing
  • US9998491B2 patent drawing

AI summary

A first collection including a pattern of life (POL) feature vector and a Q&A feature vector is constructed. A second collection is constructed from the first collection by inserting noise in at least one of the vectors. A third collection is constructed by combining a vector of the second collection with a corresponding vector of a different collection. Using a forecasting configuration, a POL feature vector of the third collection is aged to generate a changed POL feature vector containing POL feature values expected at a future time. The changed POL feature vector is input into a trained neural network to predict a probability of the cyber-attack occurring at the future time.