Predicting Network Activity via Hierarchical Progression States

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity solutions are often reactive and fail to detect malicious activities in computing networks until they have already occurred, leading to delays in prevention and mitigation, especially when attacks originate from internal actors with legitimate access.

Innovation Solution

A system that predicts sensitive network activities by identifying hierarchical-chained progression states using machine learning, allowing for early detection and implementation of control actions before harmful results are reached, based on dynamically configurable phases and environmental attributes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If reactive detection methods are used to identify malicious activities after they occur, then detection accuracy can be maintained, but response time is delayed and prevention capability is lost

Engineering Contradiction:
Improvedetection accuracyVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by detecting indicators of compromise (IOCs) and suspicious activities before malicious operations complete. It identifies hierarchical-chained progression states that represent early stages of attacks, enabling preventive intervention before damage occurs. This shifts the detection paradigm from reactive (after damage) to proactive (before damage).

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the malicious activity detection process into hierarchical-chained progression states, breaking down complex attacks into discrete, detectable phases. Each state represents a specific stage in the attack chain, allowing the system to detect and respond at multiple granular levels rather than waiting for the final harmful outcome.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If monitoring is performed only on completed malicious actions, then false positives are reduced, but the ability to prevent attacks is lost

Engineering Contradiction:
Improvefalse positive rateVSAvoidattack prevention capability
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The system takes preliminary action by detecting IOCs and suspicious patterns that precede confirmed malicious actions. It analyzes progression states that indicate an attack is in progress but not yet completed, enabling prevention while maintaining reasonable accuracy through multi-stage verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where detected IOCs and progression states trigger control actions that feed back into the monitoring process. This continuous feedback loop allows the system to adjust detection sensitivity and respond dynamically to evolving threats while learning from detected patterns.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If control actions are taken based on early detection of suspicious activities, then prevention capability is improved, but false positives may increase

Engineering Contradiction:
Improveattack prevention capabilityVSAvoidfalse positive rate
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The system performs preliminary detection of IOCs and suspicious patterns before taking control actions. By identifying hierarchical-chained progression states, it can trigger appropriate responses based on the stage of detection, allowing for graduated control measures that reduce false positives while maintaining prevention capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies local quality by implementing different control actions based on the specific progression state detected. Rather than a uniform response to all suspicious activities, it tailors control measures to the particular stage and nature of the detected threat, improving precision and reducing unnecessary disruptions.

Inventive Principle:
Principle #3Local quality

4Reliability

If comprehensive monitoring of all network activities is implemented, then detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments network monitoring into hierarchical-chained progression states, organizing complex detection tasks into manageable phases. This segmentation allows the system to focus computational resources on specific attack stages and IOCs rather than analyzing all network traffic uniformly, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements universal detection capabilities that can identify multiple types of malicious activities through a common framework of hierarchical-chained progression states. This multi-functional approach allows a single system to detect various attack vectors (data exfiltration, lateral movement, privilege escalation) using unified detection logic rather than separate specialized systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10447727B1Predicting and addressing harmful or sensitive network activity
Publication Date: 2019.10.15 CYBER ARK SOFTWARE LTD
  • US10447727B1 patent drawing
  • US10447727B1 patent drawing
  • US10447727B1 patent drawing

AI summary

Disclosed embodiments relate to systems and methods for predictable detection in a computing network. Techniques include identifying an activity associated with an identity in the computer network; accessing hierarchical-chained progression states representing timelines defining one or more process flows for operations in the computer network between beginning states and corresponding predictable result states to be controlled; identifying a hierarchical-chained progression state corresponding to the identified activity; automatically predicting a likelihood that the at least one activity will reach the predictable result state corresponding to the identified hierarchical-chained progression state; and implementing a control action for the activity, the identity, or a resource to which the identity is seeking to communicate.