Parallel Inference-Correlation Groups for Cyber Threat Speed
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional surveillance analytics and projection systems for security threats suffer from propagation delay processing speed, leading to slow rollout of threat mitigation strategies, as they typically use sequential mode processing of correlation criteria, which is undesirable in rapidly escalating cyber threats.
Innovation Solution
An n-tiering security threat inference and correlation apparatus that utilizes a plurality of groups of inference-correlation systems to process security events in parallel, with inference systems applying stochastic rules and correlation systems using deterministic rules derived from historical data, enabling faster identification of cyber attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If sequential mode processing of correlation criteria is used, then system complexity is reduced, but processing speed deteriorates
Solution Approach 1:
The patent divides the security event processing system into multiple independent inference-correlation system groups, each capable of processing security events autonomously. This segmentation allows parallel processing of security events across multiple groups, significantly improving processing speed while maintaining manageable complexity through modular design. Each group contains inference systems and correlation systems that work independently but can be scaled by adding more groups.
Solution Approach 2:
The patent transitions from single-dimensional sequential processing to multi-dimensional parallel processing by introducing multiple inference-correlation system groups that operate simultaneously. This dimensional expansion from one processing stream to many enables the system to handle exponentially increasing security threats without proportionally increasing system complexity, as each dimension (group) is a replicated, manageable unit.
2Productivity
If parallel processing is implemented, then processing speed is improved, but system complexity increases
Solution Approach 1:
The system is segmented into identical or similar inference-correlation system groups that can be replicated and scaled. Each group processes a subset of security events independently, allowing the system to achieve high productivity through parallel processing while keeping individual group complexity low and manageable through standardization.
Solution Approach 2:
Each inference-correlation system group is designed as a universal, multi-functional unit that can handle various types of security events and threats. This universality allows the same group architecture to be replicated across multiple parallel instances, improving overall productivity without increasing the complexity of individual units, as they all follow the same proven design pattern.
3Reliability
If more inference-correlation system groups are added, then threat detection capability is improved, but resource consumption increases
Solution Approach 1:
The patent implements a scalable architecture where inference-correlation system groups can be dynamically activated based on threat levels and resource availability. Instead of always running maximum parallel groups, the system activates the necessary number of groups to handle current threat volumes, achieving sufficient reliability without unnecessarily consuming computational resources during lower-threat periods.
Solution Approach 2:
The system dynamically adjusts operational parameters such as the number of active inference-correlation system groups, processing priorities, and resource allocation based on real-time threat assessment and system load conditions. This allows the system to optimize the balance between threat detection capability and resource consumption by changing operational parameters rather than fixed hardware configuration.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An n-tiering security threat inference and correlation apparatus (100) for monitoring and anticipating cyber attacks is disclosed. The apparatus comprises a plurality of groups of inference-correlation systems (106(a, b)-1 14(a, b)), each group arranged with at least one inference system and at least one associated correlation system configured to monitor at least one network; and an input/output (I/O) system (102) configured to receive security events, and broadcast the received security events to the plurality of groups of inference-correlation systems; wherein the respective groups of inference-correlation systems are configured to process only the broadcasted security events relevant to the respective networks to identify the cyber attacks. A method of operating the apparatus is also disclosed.