Processor-Level Cyber Attack Detection With Top-Down Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber security systems operate using a 'bottom-up' approach, collecting data from endpoints and relying on pre-defined event monitoring, which leads to high computational resource usage and false positive alerts, failing to detect attacks hidden at the processor level and missing breaches initiated by normal machine language instructions.

Innovation Solution

A 'top-down' cyber security system that analyzes machine language instructions at the processor level, using attack-vector scenarios and machine learning to identify implemented cyber techniques, alerting users of potential attacks and predicting next steps to prevent further tactics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a bottom-up approach is used to collect and analyze all events from endpoints, then comprehensive attack detection is achieved, but computational resource consumption increases significantly

Engineering Contradiction:
Improveattack detection capabilityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts and analyzes only the critical machine language instructions from the vast amount of endpoint data, rather than processing all events. By taking out the essential processor-level instructions that indicate cyber techniques, the system achieves comprehensive attack detection while significantly reducing computational resource consumption.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent shifts the analysis from the application level (traditional bottom-up approach) to the processor level by analyzing machine language instructions. This dimensional change enables the system to detect attacks at their origin point with fewer resources, as processor-level analysis is more efficient than application-level event correlation.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of operation

If pre-defined event monitoring is used at the application level, then ease of implementation is maintained, but detection precision decreases due to false positives

Engineering Contradiction:
Improvesystem implementation easeVSAvoidattack detection accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

Instead of monitoring application-level events and trying to detect attacks from abnormal indications, the patent inverts the approach by directly analyzing machine language instructions at the processor level. This inversion eliminates false positives caused by normal application-level variations while maintaining implementation feasibility through automated instruction analysis.

Inventive Principle:
Principle #13The other way round (Inversion)

3Reliability

If all events are collected and correlated at the application level, then comprehensive coverage is achieved, but the system misses attacks hidden at the processor level

Engineering Contradiction:
Improvedetection coverageVSAvoidprocessor-level attack detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent performs preliminary analysis of machine language instructions at the processor level before attacks manifest at the application level. By detecting cyber techniques through their machine language signatures early in the attack chain, the system achieves comprehensive coverage including hidden processor-level attacks that would otherwise go undetected.

Inventive Principle:
Principle #10Preliminary action

4Measurement precision

If abnormal indications are monitored for attack detection, then false positive rate is reduced, but attacks initiated by normal machine language instructions are missed

Engineering Contradiction:
Improvefalse positive reductionVSAvoidattack detection completeness
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent segments the attack detection process into two parts: (1) identifying specific machine language instruction sequences that correspond to cyber techniques, and (2) correlating these segmented indicators with attack-vector scenarios. This segmentation enables the system to detect both abnormal and normal instructions that indicate attacks, achieving complete detection while maintaining precision through structured analysis.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240396924A1A top-down cyber security system and method
Publication Date: 2024.11.28 CYTWIST LTD
  • US20240396924A1 patent drawing
  • US20240396924A1 patent drawing
  • US20240396924A1 patent drawing

AI summary

A cyber security system, the cyber security system comprising a processing circuitry configured to: obtain: (a) an attack-vector scenario, the attack-vector scenario comprising a sequence of cyber tactics, and (b) information about actual sequences of machine language instructions that executed on the one or more processors: identify, based on the information, the cyber techniques that occurred on the organizational network by matching the actual sequences of machine language instructions with the at least one sequence of machine language instructions associated with the cyber techniques, and alert a user of the cyber security system of a potential cyber-attack upon determining that each of the cyber tactics forming the attack vector scenario, is associated with at least one of the implemented cyber techniques.