Autonomous System Threat Scoring for Proactive Malicious Activity Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing malicious activity detection techniques in autonomous systems are unable to anticipate and prevent the occurrence of malicious activities, as they rely on threat intelligence signals generated after the fact, and blocking individual IP addresses is insufficient against actors who change IP addresses frequently.

Innovation Solution

An apparatus calculates a normalized threat intelligence score (TIS) for autonomous systems based on threat intelligence signals and IP address counts, determining a reputation level that predicts the likelihood of malicious activities, allowing proactive detection and prevention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If threat intelligence signals are used to detect malicious activities, then detection capability is improved, but the ability to anticipate and prevent malicious activities before they occur remains insufficient

Engineering Contradiction:
Improvemalicious activity detection capabilityVSAvoidtime to detect and respond to malicious activities
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent calculates a normalized threat intelligence score (TIS) for autonomous systems before malicious activities occur. By aggregating threat intelligence signals and normalizing them against the number of IP addresses in each AS, the system proactively identifies high-risk autonomous systems and can take preventive actions before actual malicious activities manifest, thus resolving the contradiction between detection capability and response time.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If individual IP addresses are blocked to prevent malicious activities, then immediate malicious behavior is stopped, but the approach fails against actors who change IP addresses frequently

Engineering Contradiction:
Improveimpact of blocked malicious activitiesVSAvoidability to counter IP-changing malicious actors
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent segments the approach from blocking individual IP addresses to blocking at the autonomous system level. By calculating and normalizing threat intelligence scores across all IP addresses within an autonomous system, the system identifies malicious actors based on their AS-level characteristics rather than relying on static IP address blocking, thereby adapting to IP-changing behavior while maintaining effective mitigation.

Inventive Principle:
Principle #1Segmentation

3Reliability

If threat intelligence signals are aggregated for autonomous systems, then proactive detection is enabled, but resource utilization needs to be optimized by focusing on high-risk systems

Engineering Contradiction:
Improveproactive malicious activity detectionVSAvoidresource utilization efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by normalizing the aggregated threat intelligence signals against the specific characteristics of each autonomous system (number of IP addresses). This creates a localized risk assessment for each AS, enabling the system to identify which autonomous systems pose the highest risk and direct resources accordingly, thereby optimizing resource utilization while maintaining proactive detection capability.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12373568B2Malicious activity probability determinations for autonomous systems
Publication Date: 2025.07.29 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12373568B2 patent drawing
  • US12373568B2 patent drawing
  • US12373568B2 patent drawing

AI summary

According to examples, an apparatus may include a processor that may calculate a normalized threat intelligence score (TIS) for an autonomous system (AS) based on a sum of threat intelligence (TI) signals associated with Internet protocol (IP) addresses controlled by the AS and a count of the IP addresses controlled by the AS. The processor may also determine, based on the normalized TIS for the AS, a probability that activities associated with the IP addresses controlled by the AS are likely to be malicious. The processor may further output the determined probability that the activities associated with the IP addresses controlled by the AS are likely to be malicious.