Neural Embeddings Migration for Proactive Cyber Attack Forecasting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber security solutions are reactionary and lack proactive capabilities to predict and classify cyber attacks, relying on rule and signature-based methods that struggle to adapt to changing Advanced Persistent Threat (APT) attack vectors and new attack methods, limiting their ability to prevent or alert in real-time.

Innovation Solution

A method and system utilizing neural embeddings migration, which constructs feature vectors from analytical and Pattern of Life data, introduces noise, and combines them to forecast future cyber attacks by inputting aged feature vectors into a trained neural network, enabling proactive prediction and classification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If rule and signature-based methods are used for cyber security detection, then the system can detect known attack patterns, but it cannot adapt to changing APT attack vectors and new attack methods

Engineering Contradiction:
Improveadaptability to changing attack vectorsVSAvoiddetection reliability of known attacks
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent transforms static rule-based detection into dynamic machine learning models that continuously learn from new attack data. The system uses neural networks with evolving weight matrices that adapt to changing attack patterns while maintaining detection of known threats through trained parameters.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the fundamental parameters of detection by transitioning from fixed signature matching to probabilistic predictions based on neural network outputs. The system uses confidence scores and probability thresholds that can be dynamically adjusted based on attack sophistication and data quality.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If reactive security solutions are implemented, then the system can respond to detected threats, but it cannot predict or prevent future attacks proactively

Engineering Contradiction:
Improvereal-time response capabilityVSAvoidtime to detect and respond to attacks
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by using machine learning models to predict future attacks before they occur. The system analyzes historical attack patterns and system behavior to generate predictions about upcoming threats, allowing security teams to prepare defenses in advance rather than reacting after detection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback loops where prediction outcomes and actual attack data are continuously fed back into the training process. This closed-loop system improves prediction accuracy over time while maintaining real-time detection capabilities through ongoing model refinement and retraining.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If machine learning techniques are employed to predict future attacks, then the system can adapt to evolving attack methods, but it requires complex training data construction and feature vector processing

Engineering Contradiction:
Improveability to predict new attack methodsVSAvoidcomplexity of data processing pipeline
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the complex data processing pipeline into distinct functional modules: data collection, feature extraction, vector construction, noise injection, and model training. Each module handles a specific aspect of the process, making the overall system more manageable and maintainable despite its complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediate representations such as feature vectors and embedded representations that bridge raw security data and model predictions. These intermediaries simplify the transformation process and enable more efficient processing while maintaining the ability to capture complex attack patterns.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10230751B2Forecasting and classifying cyber attacks using neural embeddings migration
Publication Date: 2019.03.12 KYNDRYL INC
  • US10230751B2 patent drawing
  • US10230751B2 patent drawing
  • US10230751B2 patent drawing

AI summary

A first collection including a first feature vector and a Q&A feature vector is constructed. A second collection is constructed from the first collection by inserting noise in at least one of the vectors. A third collection is constructed by migrating, at least one of a vectors of the second collection with a corresponding vector of a fourth collection. The second and the fourth collections have a property distinct from one another. Using a forecasting configuration, a vector of the third collection is aged to generate a changed feature vector, the changed feature vector containing feature values expected at a future time. The changed feature vector is input into a trained neural network to predict a probability of the cyber-attack occurring at the future time.