Network Security Response Prediction via Language Model

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a lack of automatic tools for estimating the effectiveness of security breach responses and their impact on computer system availability, which hinders decision-making for security administrators.

Innovation Solution

A computer-implemented method that analyzes unlabeled network data to create a language model, processes security actions to generate a damage event list, and extracts security events to provide administrators with insights on response effectiveness and availability impact.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If security administrators manually evaluate security breach responses, then they can make informed decisions about response effectiveness and availability impact, but the process lacks automation and requires significant time and expertise

Engineering Contradiction:
Improveautomated security response evaluationVSAvoidtime for security decision-making
Core Design Contradiction:
Extent of automationVSLoss of time

Solution Approach 1:

The patent introduces a language model as an intermediary between raw security event data and administrator decision-making. The model translates complex security events into structured damage event lists and predictions, automating the evaluation process while maintaining accuracy. This intermediary handles the complex analysis work, freeing administrators from manual evaluation tasks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary analysis by pre-processing security events into damage event lists and generating predictions before administrators need to make decisions. By preparing evaluation data in advance and organizing it into structured formats, the system reduces the time required for actual decision-making while ensuring thorough analysis.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If comprehensive security analysis is performed on all network data, then accurate predictions of response effectiveness can be achieved, but the complexity of processing unlabeled network data increases significantly

Engineering Contradiction:
Improveprediction accuracy of security response effectivenessVSAvoidcomplexity of language model processing
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the complex task of security analysis into distinct components: event extraction, damage event list generation, and prediction generation. By dividing unlabeled network data into manageable security events and processing them through structured pipelines, the system achieves comprehensive analysis while reducing processing complexity through modular organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transforms unstructured network data into structured representations by changing parameters from raw data format to standardized security event formats. This parameter transformation enables accurate predictions while simplifying processing, as the language model operates on structured damage event lists rather than raw unlabeled data.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If security responses are implemented without prediction tools, then immediate response to breaches is possible, but the effectiveness and availability impact of responses cannot be estimated

Engineering Contradiction:
Improveeffectiveness of security breach responseVSAvoidease of security response decision-making
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements feedback by generating predictions about response effectiveness and availability impact before responses are executed. This feedback loop provides administrators with estimated outcomes of potential responses, enabling them to choose the most effective actions while understanding their impact on system availability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system enables self-service by automatically generating damage event lists and effectiveness predictions without requiring manual analysis. Administrators simply input security events, and the system autonomously performs the complex evaluation work, making reliable response selection easy while maintaining high prediction accuracy.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12132751B2Predicting security response impact
Publication Date: 2024.10.29 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12132751B2 patent drawing
  • US12132751B2 patent drawing
  • US12132751B2 patent drawing

AI summary

An approach to predicting the outcome of a computer security response. The approach can analyze an unlabeled set of network data and based on the analysis, create a language model of the network. The approach can process the language model to predict a reduction factor associated with network availability. The approach can further process the language model and a malicious sequence to predict an effectiveness factor associated with blocking the malicious sequence. The approach can output bot the reduction factor and the effectiveness factor to a network administrator for determining the applicability of the computer security response.