Predictive Cybersecurity Query Generation via Bayesian Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity investigation methods are manual, lack predictive capabilities, and are resource-intensive, leading to prolonged detection and response times, making organizations vulnerable to cyber threats due to their inability to automatically adapt to evolving attack contexts and requiring constant maintenance by security experts.

Innovation Solution

A system that generates predictive cybersecurity investigation queries using a Bayesian Belief Network engine to analyze evidence sets, predicting historical and future attacker actions, and optimizing queries based on the success rate of previous queries, allowing for automated root-cause analysis and quick remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual cybersecurity investigation methods are used, then security experts can analyze attacks, but the process is resource-intensive and time-consuming

Engineering Contradiction:
Improveattack detection capabilityVSAvoiddetection and response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables automated self-service investigation by using machine learning models to automatically analyze security alerts, predict attacker actions, and generate investigation queries without requiring constant manual intervention from security experts

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical analysis processes with automated computational systems that use machine learning algorithms to predict attacker behavior and generate investigation queries, substituting human expertise with algorithmic analysis

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual investigation methods are used, then attacks can be analyzed, but constant maintenance by security experts is required

Engineering Contradiction:
Improveattack analysis capabilityVSAvoidautomated adaptation capability
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The system implements dynamic adaptation by continuously learning from new attack patterns and evidence, allowing the machine learning models to automatically update their predictions and investigation strategies without manual reconfiguration

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops where investigation results and new attack evidence are fed back into the machine learning models to continuously improve prediction accuracy and adapt to evolving attack patterns

Inventive Principle:
Principle #23Feedback

3Measurement precision

If comprehensive evidence analysis is performed, then accurate attack detection is achieved, but resource consumption increases

Engineering Contradiction:
Improveattack detection accuracyVSAvoidinvestigation efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system performs preliminary analysis by predicting attacker actions and prioritizing investigation queries before full evidence analysis is conducted, allowing security teams to focus resources on the most promising investigation paths

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies partial analysis by generating targeted investigation queries based on predicted attacker actions rather than analyzing all evidence comprehensively, achieving sufficient detection accuracy with reduced resource consumption

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20230328095A1Generation of Predictive Cybersecurity Data Queries
Publication Date: 2023.10.12 CYBEREASON INC
  • US20230328095A1 patent drawing
  • US20230328095A1 patent drawing
  • US20230328095A1 patent drawing

AI summary

A computing system identifies an evidence set associated with a detected cybersecurity attack. The evidence set includes logs representing security alerts associated with the detected cybersecurity attack. The computing system analyzes the evidence set to predict actions taken by a malicious actor, the actions comprising historical actions and future actions. The computing system analyzes the predicted actions to classify the historical actions and future actions taken by the malicious actor. The computing system generates a query for analyzing the evidence set based on the classified historical actions and future actions.