Security Threat Prediction via Latent Attribute Similarity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computing security products fail to predict and prevent security threat attacks on enterprise computing resources, focusing mainly on post-attack measures rather than proactive protection.

Innovation Solution

A computer-implemented method that mathematically analyzes historical attack data to identify candidate security threat targets by determining similarity relationships between latent attributes of enterprise organizations, predicting future attacks, and performing remedial actions to protect those targets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security products (antivirus, firewall) are used to block attacks after detection, then basic protection is provided, but the ability to predict and prevent future attacks is lost

Engineering Contradiction:
Improveprotection effectivenessVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by analyzing historical attack data and identifying patterns before attacks occur. The system predicts future attacks by examining past attack behaviors, attacker tactics, and vulnerability exploitation patterns, then proactively implements protective measures before the predicted attacks materialize, transforming security from reactive to preventive

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system establishes a feedback loop by continuously monitoring actual attack outcomes and comparing them with predictions. This feedback mechanism refines the predictive model over time, improving accuracy by learning from real-world attack patterns and adjusting future predictions accordingly

Inventive Principle:
Principle #23Feedback

2Measurement precision

If comprehensive historical attack data is analyzed to predict future attacks, then prediction accuracy improves, but computational complexity and data processing requirements increase

Engineering Contradiction:
Improveprediction accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system extracts only the most relevant features and patterns from comprehensive historical attack data, such as attack timing patterns, targeted vulnerability types, and attacker behavior signatures. By selecting and extracting only the critical predictive indicators rather than processing all raw data, the system maintains high prediction accuracy while reducing computational complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transforms raw historical attack data into standardized parameters and metrics that capture essential attack patterns. By changing the representation of data from raw logs to structured parameters (e.g., attack frequency, vulnerability exploitation rates, temporal patterns), the system enables efficient analysis while preserving predictive information

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9948663B1Systems and methods for predicting security threat attacks
Publication Date: 2018.04.17 GEN DIGITAL INC
  • US9948663B1 patent drawing
  • US9948663B1 patent drawing
  • US9948663B1 patent drawing

AI summary

A computer-implemented method for predicting security threat attacks may include (1) identifying candidate security threat targets with latent attributes that describe features of the candidate security threat targets, (2) identifying historical attack data that describes which of the candidate security threat targets experienced an actual security threat attack, (3) determining a similarity relationship between latent attributes of at least one specific candidate security threat target and latent attributes of the candidate security threat targets that experienced an actual security threat attack according to the historical attack data, (4) predicting, based on the determined similarity relationship, that the specific candidate security threat target will experience a future security threat attack, and (5) performing at least one remedial action to protect the specific candidate security threat target in response to predicting the future security threat attack. Various other methods, systems, and computer-readable media are also disclosed.