Cyber Security Restoration Engine Prioritizes Network Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cybersecurity systems are inadequate in effectively detecting and mitigating cyber threats, particularly advanced persistent threats that evade detection by creating low-level anomalies, leading to potential system compromise.

Innovation Solution

An AI-based cybersecurity system comprising multiple engines that cooperate to identify, mitigate, and restore from cyber threats by prioritizing nodes in a network based on severity scores, using machine-learning algorithms to detect anomalies, autonomously take remediation actions, and simulate cyberattacks to preempt escalations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional cybersecurity products are used to detect and prioritize cyber threats, then basic threat detection capability is provided, but advanced persistent threats that create low-level anomalies can evade detection and compromise the system

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsystem security
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system segments threat detection into multiple specialized AI engines: one for detecting cyber threats, another for simulating cyberattacks, and a restoration engine for remediation. Each engine focuses on specific aspects of security, allowing the system to detect both obvious and subtle anomalies that single-conventional products miss

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary action by simulating cyberattacks before actual threats compromise the system. The AI-based simulation engine proactively identifies vulnerable nodes and potential attack vectors, enabling preventive remediation before real threats can exploit the same weaknesses

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the system restores all nodes involved in a cyber attack, then complete system recovery is achieved, but the time and resources required for restoration increase significantly

Engineering Contradiction:
Improvesystem recovery completenessVSAvoidrestoration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The restoration engine applies local quality by prioritizing restoration based on node severity scores. Instead of uniform restoration, it focuses remediation resources on high-severity nodes that pose the greatest risk, achieving effective system recovery with reduced time and resources compared to restoring all nodes equally

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system uses feedback from AI-based simulations to inform restoration priorities. Simulation results provide feedback about which nodes are most vulnerable and likely to be compromised, allowing the restoration engine to anticipate and prioritize critical nodes for faster recovery

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20230403294A1Cyber security restoration engine
Publication Date: 2023.12.14 DARKTRACE HLDG LTD
  • US20230403294A1 patent drawing
  • US20230403294A1 patent drawing
  • US20230403294A1 patent drawing

AI summary

A cyber security restoration engine prioritizes nodes in a graph of nodes in a computer network or system that are involved in a cyber attack for remediation actions. The cyber security restoration engine performs this prioritization by, for each node, determining one or more edges linking the node to other nodes in the graph, the edges representing interactions between two nodes; obtaining metadata indicative of a type of interaction between two nodes connected by the edge and the roles of the two nodes in that interaction; determining how severe the interaction represented by that edge is within the context of the cyber attack, based on the metadata of that edge; and determining a severity score for the node by combining the severity score for each of the one or more edges connected to the node. The cyber security restoration engine prioritizes nodes for remediation action based on the severity scores for the nodes.