Persistent Attack Detection with Expiring Cloud Evidence Tables

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing environments face challenges in quickly and accurately detecting complex and slow-developing malicious activities due to the structure and timeliness of data feeds, necessitating improved methods for threat detection.

Innovation Solution

An evidence table is used to store threat data with parameters such as threat severity, duration, and dependency, enabling threat detection by aggregating non-expired records for analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all available threat information is tracked persistently, then threat detection completeness is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvethreat detection completenessVSAvoidtracking system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments threat information tracking by creating an evidence table that divides threat data into discrete, manageable records. Each record represents a specific threat indicator with defined attributes (severity, duration, dependency), allowing the system to track only relevant threats rather than all possible threat information, thus reducing complexity while maintaining detection completeness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameters of threat tracking by introducing expiry times and dependency relationships. Threat records automatically expire after a defined duration, and dependency tracking allows the system to focus on chains of related threats rather than isolated events. This parameter-based approach enables efficient resource allocation while maintaining comprehensive threat detection.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If threat data is stored with extended retention periods, then threat detection accuracy is improved, but data storage requirements and processing overhead increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoiddata storage volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent applies preliminary action by pre-defining expiry times for threat records based on their expected relevance duration. This allows the system to automatically manage data retention periods without requiring continuous manual intervention or complex cleanup processes, balancing detection accuracy with storage efficiency by keeping data only as long as it remains potentially useful.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements partial action by selectively retaining threat data based on severity scores and dependency relationships. High-severity threats and those with unmet dependencies are retained longer, while low-severity, isolated threats expire sooner. This selective retention strategy maintains detection accuracy for critical threats while reducing overall storage requirements.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If threat analysis considers multiple interdependent factors, then detection reliability is improved, but computational complexity increases

Engineering Contradiction:
Improvedetection reliabilityVSAvoidanalysis system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mechanism in the form of an evidence table that mediates between raw threat data and final detection decisions. The table structure with predefined columns (severity, duration, dependency, expiry time) provides a standardized intermediate representation that simplifies complex analysis by organizing multifaceted threat information into a manageable format with clear relationships between factors.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements feedback through dependency tracking, where the detection of one threat can influence the evaluation of related threats. When a threat is detected, the system checks for dependent threats in the evidence table and adjusts analysis accordingly, creating a feedback loop that improves detection reliability while maintaining manageable complexity through structured interrelationships.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250280021A1Detecting persistent attacks in cloud computing environments
Publication Date: 2025.09.04 SOPHOS LTD
  • US20250280021A1 patent drawing
  • US20250280021A1 patent drawing
  • US20250280021A1 patent drawing

AI summary

An evidence table for threat data in a cloud computing environment permits independent tracking of several parameters related to the potential threat posed by a new instance of threat data. The evidence table may, for example, combine a first measure of threat severity, a second measure of the duration over which an instance of threat data remains relevant, and a third measure of dependency on other types of threat data. This approach can improve threat detection by facilitating storage and analysis of threat information based on the significance, temporal relevance, and interdependency of threat information without requiring persistent tracking of all available threat information for a cloud computing environment.