Security Indicator Linkage Determination for Cyber-Attack Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current intrusion detection and prevention systems face challenges in effectively correlating different security indicators across various phases of a cyber-attack, leading to inefficient and delayed identification of attacks.
Innovation Solution
A security indicator linkage determination apparatus and method that utilize pattern mining, attack sequence generation, and prediction modules to establish temporal, spatial, and behavioral linkages between security indicators such as IP addresses, domains, and attack timings, enabling the identification of attack sequences and predicting potential attack phases.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional intrusion detection systems correlate security indicators using simple matching rules, then the system complexity remains low, but the attack identification accuracy and timeliness deteriorate
Solution Approach 1:
The system segments the attack correlation process into distinct phases (reconnaissance, infiltration, capture, exfiltration) with specific security indicators for each phase. This segmentation enables precise matching of indicators to attack phases, improving identification accuracy while managing complexity through structured organization of correlation rules.
Solution Approach 2:
The system introduces a temporal dimension to security indicator correlation by establishing sequential relationships between indicators across different attack phases. Instead of simple one-to-one matching, the system correlates indicators through time-ordered attack sequences, enhancing detection accuracy by capturing the evolution of attacks over time.
2Reliability
If the system monitors and correlates all security indicators across all attack phases, then the attack detection capability improves, but the processing time and computational resources increase
Solution Approach 1:
The system performs preliminary actions by pre-defining attack phase sequences and associated security indicators for each phase. When security events are detected, the system matches them against pre-established phase patterns, significantly reducing processing time compared to analyzing all indicators without pre-defined structures.
Solution Approach 2:
The system applies local quality by focusing correlation efforts on specific security indicators relevant to each attack phase rather than uniformly processing all indicators. Each attack phase has its own set of critical indicators, allowing the system to efficiently process only the most relevant data for current detection needs.
3Measurement precision
If the system uses detailed attack phase sequences with multiple security indicators, then the confidence in attack predictions increases, but the difficulty of implementing and maintaining the system increases
Solution Approach 1:
The system implements a universal attack phase framework that can accommodate multiple types of attacks (cyber-attacks, physical attacks) through a common structure of phases and indicators. This multi-functionality allows the system to handle diverse attack scenarios while maintaining a consistent implementation approach, reducing the difficulty of deployment and maintenance.
Data Source
AI summary
According to an example, security indicator linkage determination may include parsing input data that is used to determine a plurality of sequences of steps that are involved in attacks. A linkage selected from temporal, spatial, and/or behavioral linkages may be applied to the parsed input data to determine the plurality of sequences of steps. A security indicator that is related to a potential attack may be received. The plurality of sequences of steps may be used to determine whether the security indicator matches a step in one of the plurality of sequences of steps. In response to a determination that the security indicator matches a step in one of the plurality of sequences of steps, linkage between the security indicator and another security indicator from the one of the plurality of sequences of steps that are involved in the attacks may be identified.


