Processor-Level Cyber Attack Detection With Top-Down Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cyber security systems operate using a 'bottom-up' approach, collecting data from endpoints and relying on pre-defined event monitoring, which leads to high computational resource usage and false positive alerts, failing to detect attacks hidden at the processor level and missing breaches initiated by normal machine language instructions.
Innovation Solution
A 'top-down' cyber security system that analyzes machine language instructions at the processor level, using attack-vector scenarios and machine learning to identify implemented cyber techniques, alerting users of potential attacks and predicting next steps to prevent further tactics.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a bottom-up approach is used to collect and analyze all events from endpoints, then comprehensive attack detection is achieved, but computational resource consumption increases significantly
Solution Approach 1:
The patent extracts and analyzes only the critical machine language instructions from the vast amount of endpoint data, rather than processing all events. By taking out the essential processor-level instructions that indicate cyber techniques, the system achieves comprehensive attack detection while significantly reducing computational resource consumption.
Solution Approach 2:
The patent shifts the analysis from the application level (traditional bottom-up approach) to the processor level by analyzing machine language instructions. This dimensional change enables the system to detect attacks at their origin point with fewer resources, as processor-level analysis is more efficient than application-level event correlation.
2Ease of operation
If pre-defined event monitoring is used at the application level, then ease of implementation is maintained, but detection precision decreases due to false positives
Solution Approach 1:
Instead of monitoring application-level events and trying to detect attacks from abnormal indications, the patent inverts the approach by directly analyzing machine language instructions at the processor level. This inversion eliminates false positives caused by normal application-level variations while maintaining implementation feasibility through automated instruction analysis.
3Reliability
If all events are collected and correlated at the application level, then comprehensive coverage is achieved, but the system misses attacks hidden at the processor level
Solution Approach 1:
The patent performs preliminary analysis of machine language instructions at the processor level before attacks manifest at the application level. By detecting cyber techniques through their machine language signatures early in the attack chain, the system achieves comprehensive coverage including hidden processor-level attacks that would otherwise go undetected.
4Measurement precision
If abnormal indications are monitored for attack detection, then false positive rate is reduced, but attacks initiated by normal machine language instructions are missed
Solution Approach 1:
The patent segments the attack detection process into two parts: (1) identifying specific machine language instruction sequences that correspond to cyber techniques, and (2) correlating these segmented indicators with attack-vector scenarios. This segmentation enables the system to detect both abnormal and normal instructions that indicate attacks, achieving complete detection while maintaining precision through structured analysis.
Data Source
AI summary
A cyber security system, the cyber security system comprising a processing circuitry configured to: obtain: (a) an attack-vector scenario, the attack-vector scenario comprising a sequence of cyber tactics, and (b) information about actual sequences of machine language instructions that executed on the one or more processors: identify, based on the information, the cyber techniques that occurred on the organizational network by matching the actual sequences of machine language instructions with the at least one sequence of machine language instructions associated with the cyber techniques, and alert a user of the cyber security system of a potential cyber-attack upon determining that each of the cyber tactics forming the attack vector scenario, is associated with at least one of the implemented cyber techniques.


