Probabilistic Graph Cyberattack Detection in Cloud Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern cloud environments face challenges in dynamically and automatically adapting to changing attack vectors and targets, as traditional security methods struggle to detect complex, multi-step cyberattacks in real-time.

Innovation Solution

A method and system for detecting anomalous network activity using probabilistic unsupervised learning, which creates and updates profiles for virtual entities based on their network activity observations, and determines anomalies by comparing observed behavior against expected profiles.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security protection methods are used, then security policies can be enforced through micro-segmentation and security groups, but these methods cannot stop the abuse of permitted connections by external attackers, internally deployed malware or malicious insiders

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidabuse of permitted connections
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic baseline adjustment by continuously learning normal network behavior patterns and adapting security thresholds in real-time. The system updates baselines based on observed traffic patterns, enabling it to dynamically respond to changing attack vectors while maintaining legitimate traffic flow. This resolves the contradiction by making security enforcement adaptive rather than static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs feedback mechanisms where detected anomalies and attack patterns are fed back into the baseline learning process. When new attack types are identified, the system adjusts its understanding of normal behavior and updates detection thresholds accordingly. This continuous feedback loop enables the system to improve security enforcement while reducing false positives from legitimate traffic variations.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If traditional security methods are used, then network connections can be controlled through policies, but these methods cannot dynamically adapt to changing attack vectors and changing potential attack targets

Engineering Contradiction:
Improvedynamic adaptation to attack vectorsVSAvoidsecurity system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements self-service through automated baseline learning and anomaly detection algorithms that automatically adapt to new attack patterns without human intervention. The system autonomously learns normal behavior patterns, identifies deviations, and adjusts detection parameters dynamically. This self-adapting capability provides high versatility against evolving threats while keeping operational complexity manageable through automation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically changes detection parameters and thresholds based on learned baseline behavior patterns. By continuously adjusting sensitivity parameters, time windows, and anomaly thresholds based on observed traffic characteristics, the system adapts to new attack vectors without requiring manual reconfiguration or increasing structural complexity.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If comprehensive monitoring is implemented to detect complex multi-step attacks, then detection accuracy improves, but real-time detection capability may be compromised due to processing complexity

Engineering Contradiction:
Improveattack detection accuracyVSAvoidreal-time detection speed
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The patent segments the attack detection process into multiple independent analysis layers: connection-level baseline validation, entity-level behavior analysis, and anomaly scoring. Each layer processes specific aspects of network traffic independently, allowing parallel processing that maintains real-time speed while achieving comprehensive detection accuracy through cumulative analysis across segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies partial monitoring intensity dynamically by adjusting the depth of analysis based on risk levels. For low-risk traffic matching established baselines, minimal processing is applied. For suspicious patterns, the system intensifies monitoring and applies more comprehensive analysis. This graduated approach maintains real-time performance for most traffic while achieving high detection accuracy for potential attacks.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250148014A1Cyberattack detection using probabilistic graphical models
Publication Date: 2025.05.08 INTSIGHTS CYBER INTELLIGENCE LTD
  • US20250148014A1 patent drawing
  • US20250148014A1 patent drawing
  • US20250148014A1 patent drawing

AI summary

Various embodiments include systems and methods to implement a security platform providing cyberattack detection. The security platform may, with respect to a cloud compute environment, use audit log data that is associated with a particular domain of operational activity within the cloud compute environment. Based on multiple baseline profiles associated with the operational activity, the security platform may use a probabilistic graph to determine a behavioral anomaly. The security platform may, based on the behavioral anomaly, identify a cyberattack.