Autonomous System Threat Scoring for Proactive Malicious Activity Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing malicious activity detection techniques in autonomous systems are unable to anticipate and prevent the occurrence of malicious activities, as they rely on threat intelligence signals generated after the fact, and blocking individual IP addresses is insufficient against actors who change IP addresses frequently.
Innovation Solution
An apparatus calculates a normalized threat intelligence score (TIS) for autonomous systems based on threat intelligence signals and IP address counts, determining a reputation level that predicts the likelihood of malicious activities, allowing proactive detection and prevention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If threat intelligence signals are used to detect malicious activities, then detection capability is improved, but the ability to anticipate and prevent malicious activities before they occur remains insufficient
Solution Approach 1:
The patent calculates a normalized threat intelligence score (TIS) for autonomous systems before malicious activities occur. By aggregating threat intelligence signals and normalizing them against the number of IP addresses in each AS, the system proactively identifies high-risk autonomous systems and can take preventive actions before actual malicious activities manifest, thus resolving the contradiction between detection capability and response time.
2Object-affected harmful factors
If individual IP addresses are blocked to prevent malicious activities, then immediate malicious behavior is stopped, but the approach fails against actors who change IP addresses frequently
Solution Approach 1:
The patent segments the approach from blocking individual IP addresses to blocking at the autonomous system level. By calculating and normalizing threat intelligence scores across all IP addresses within an autonomous system, the system identifies malicious actors based on their AS-level characteristics rather than relying on static IP address blocking, thereby adapting to IP-changing behavior while maintaining effective mitigation.
3Reliability
If threat intelligence signals are aggregated for autonomous systems, then proactive detection is enabled, but resource utilization needs to be optimized by focusing on high-risk systems
Solution Approach 1:
The patent applies local quality by normalizing the aggregated threat intelligence signals against the specific characteristics of each autonomous system (number of IP addresses). This creates a localized risk assessment for each AS, enabling the system to identify which autonomous systems pose the highest risk and direct resources accordingly, thereby optimizing resource utilization while maintaining proactive detection capability.
Data Source
AI summary
According to examples, an apparatus may include a processor that may calculate a normalized threat intelligence score (TIS) for an autonomous system (AS) based on a sum of threat intelligence (TI) signals associated with Internet protocol (IP) addresses controlled by the AS and a count of the IP addresses controlled by the AS. The processor may also determine, based on the normalized TIS for the AS, a probability that activities associated with the IP addresses controlled by the AS are likely to be malicious. The processor may further output the determined probability that the activities associated with the IP addresses controlled by the AS are likely to be malicious.


