Persistent Attack Detection with Expiring Cloud Evidence Tables
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud computing environments face challenges in quickly and accurately detecting complex and slow-developing malicious activities due to the structure and timeliness of data feeds, necessitating improved methods for threat detection.
Innovation Solution
An evidence table is used to store threat data with parameters such as threat severity, duration, and dependency, enabling threat detection by aggregating non-expired records for analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all available threat information is tracked persistently, then threat detection completeness is improved, but system complexity and resource consumption increase
Solution Approach 1:
The patent segments threat information tracking by creating an evidence table that divides threat data into discrete, manageable records. Each record represents a specific threat indicator with defined attributes (severity, duration, dependency), allowing the system to track only relevant threats rather than all possible threat information, thus reducing complexity while maintaining detection completeness.
Solution Approach 2:
The patent changes the parameters of threat tracking by introducing expiry times and dependency relationships. Threat records automatically expire after a defined duration, and dependency tracking allows the system to focus on chains of related threats rather than isolated events. This parameter-based approach enables efficient resource allocation while maintaining comprehensive threat detection.
2Measurement precision
If threat data is stored with extended retention periods, then threat detection accuracy is improved, but data storage requirements and processing overhead increase
Solution Approach 1:
The patent applies preliminary action by pre-defining expiry times for threat records based on their expected relevance duration. This allows the system to automatically manage data retention periods without requiring continuous manual intervention or complex cleanup processes, balancing detection accuracy with storage efficiency by keeping data only as long as it remains potentially useful.
Solution Approach 2:
The patent implements partial action by selectively retaining threat data based on severity scores and dependency relationships. High-severity threats and those with unmet dependencies are retained longer, while low-severity, isolated threats expire sooner. This selective retention strategy maintains detection accuracy for critical threats while reducing overall storage requirements.
3Reliability
If threat analysis considers multiple interdependent factors, then detection reliability is improved, but computational complexity increases
Solution Approach 1:
The patent introduces an intermediary mechanism in the form of an evidence table that mediates between raw threat data and final detection decisions. The table structure with predefined columns (severity, duration, dependency, expiry time) provides a standardized intermediate representation that simplifies complex analysis by organizing multifaceted threat information into a manageable format with clear relationships between factors.
Solution Approach 2:
The patent implements feedback through dependency tracking, where the detection of one threat can influence the evaluation of related threats. When a threat is detected, the system checks for dependent threats in the evidence table and adjusts analysis accordingly, creating a feedback loop that improves detection reliability while maintaining manageable complexity through structured interrelationships.
Data Source
AI summary
An evidence table for threat data in a cloud computing environment permits independent tracking of several parameters related to the potential threat posed by a new instance of threat data. The evidence table may, for example, combine a first measure of threat severity, a second measure of the duration over which an instance of threat data remains relevant, and a third measure of dependency on other types of threat data. This approach can improve threat detection by facilitating storage and analysis of threat information based on the significance, temporal relevance, and interdependency of threat information without requiring persistent tracking of all available threat information for a cloud computing environment.


