Probabilistic Graph Cyberattack Detection in Cloud Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern cloud environments face challenges in dynamically and automatically adapting to changing attack vectors and targets, as traditional security methods struggle to detect complex, multi-step cyberattacks in real-time.
Innovation Solution
A method and system for detecting anomalous network activity using probabilistic unsupervised learning, which creates and updates profiles for virtual entities based on their network activity observations, and determines anomalies by comparing observed behavior against expected profiles.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security protection methods are used, then security policies can be enforced through micro-segmentation and security groups, but these methods cannot stop the abuse of permitted connections by external attackers, internally deployed malware or malicious insiders
Solution Approach 1:
The patent implements dynamic baseline adjustment by continuously learning normal network behavior patterns and adapting security thresholds in real-time. The system updates baselines based on observed traffic patterns, enabling it to dynamically respond to changing attack vectors while maintaining legitimate traffic flow. This resolves the contradiction by making security enforcement adaptive rather than static.
Solution Approach 2:
The system employs feedback mechanisms where detected anomalies and attack patterns are fed back into the baseline learning process. When new attack types are identified, the system adjusts its understanding of normal behavior and updates detection thresholds accordingly. This continuous feedback loop enables the system to improve security enforcement while reducing false positives from legitimate traffic variations.
2Adaptability or versatility
If traditional security methods are used, then network connections can be controlled through policies, but these methods cannot dynamically adapt to changing attack vectors and changing potential attack targets
Solution Approach 1:
The patent implements self-service through automated baseline learning and anomaly detection algorithms that automatically adapt to new attack patterns without human intervention. The system autonomously learns normal behavior patterns, identifies deviations, and adjusts detection parameters dynamically. This self-adapting capability provides high versatility against evolving threats while keeping operational complexity manageable through automation.
Solution Approach 2:
The system dynamically changes detection parameters and thresholds based on learned baseline behavior patterns. By continuously adjusting sensitivity parameters, time windows, and anomaly thresholds based on observed traffic characteristics, the system adapts to new attack vectors without requiring manual reconfiguration or increasing structural complexity.
3Measurement precision
If comprehensive monitoring is implemented to detect complex multi-step attacks, then detection accuracy improves, but real-time detection capability may be compromised due to processing complexity
Solution Approach 1:
The patent segments the attack detection process into multiple independent analysis layers: connection-level baseline validation, entity-level behavior analysis, and anomaly scoring. Each layer processes specific aspects of network traffic independently, allowing parallel processing that maintains real-time speed while achieving comprehensive detection accuracy through cumulative analysis across segments.
Solution Approach 2:
The system applies partial monitoring intensity dynamically by adjusting the depth of analysis based on risk levels. For low-risk traffic matching established baselines, minimal processing is applied. For suspicious patterns, the system intensifies monitoring and applies more comprehensive analysis. This graduated approach maintains real-time performance for most traffic while achieving high detection accuracy for potential attacks.
Data Source
AI summary
Various embodiments include systems and methods to implement a security platform providing cyberattack detection. The security platform may, with respect to a cloud compute environment, use audit log data that is associated with a particular domain of operational activity within the cloud compute environment. Based on multiple baseline profiles associated with the operational activity, the security platform may use a probabilistic graph to determine a behavioral anomaly. The security platform may, based on the behavioral anomaly, identify a cyberattack.


