Targeted Attack Detection via Resource-Specific Metrics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security solutions for computer-based environments are unable to effectively distinguish between malicious payloads and targeted attacks, which are sophisticated and directed at specific resources, leading to challenges in detection and false positive reporting.

Innovation Solution

A protection system intercepts traffic and generates threat attack detection metrics (TADMs) using data from data collection agents, combining conventional detection methods with resource-specific evaluations to identify and alert on targeted attacks, allowing only non-malicious traffic to pass through.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional threat detection approaches (signature-based, statistical modeling, heuristic rules) are used to detect payloads, then detection coverage is improved, but the ability to distinguish targeted attacks from general malicious payloads deteriorates

Engineering Contradiction:
Improvedetection coverageVSAvoidtargeted attack identification accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The detection system is segmented into two distinct evaluation layers: first, conventional threat detection approaches identify suspect payloads; second, TADM evaluation specifically assesses whether suspect payloads reference protected system resources. This segmentation allows each layer to specialize in its strength while collectively resolving the contradiction between broad detection coverage and precise targeted attack identification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

TADM metrics serve as an intermediary evaluation layer between conventional threat detection and final targeted attack determination. The TADM metrics bridge the gap by providing resource-specific reference data that enables precise identification of targeted attacks without compromising the broad detection capabilities of conventional approaches.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If TADM evaluation is applied to all suspect payloads, then targeted attack detection accuracy is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvetargeted attack detection accuracyVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary threat detection using conventional approaches before applying TADM evaluation. By pre-identifying suspect payloads, the system prepares the groundwork for subsequent TADM assessment, ensuring that resource-specific evaluation is applied only where necessary rather than to all traffic uniformly.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

TADM evaluation is applied partially rather than universally - specifically to suspect payloads identified by conventional detection methods. This partial application approach maintains high targeted attack detection accuracy while avoiding the excessive complexity and processing overhead that would result from applying TADM evaluation to all incoming traffic.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If resource-specific metrics (TADMs) are collected and maintained for protected systems, then targeted attack detection capability is improved, but information management complexity increases

Engineering Contradiction:
Improvetargeted attack detection capabilityVSAvoidinformation management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The TADM metric framework is designed to be universal and adaptable across different protected systems and resource types. Rather than creating specialized detection mechanisms for each system, the same TADM evaluation approach can assess various resources (databases, files, applications, libraries) using consistent resource identifier matching, reducing information management complexity while maintaining high detection capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11258809B2Targeted attack detection system
Publication Date: 2022.02.22 WALLARM INC
  • US11258809B2 patent drawing
  • US11258809B2 patent drawing

AI summary

Systems and methods for targeted attack detection. A protection system intercepts traffic destined for a protected system and only traffic identified as non-malicious is allowed to pass thereto. Data collection agents (DCAs) instantiated at protected systems report information concerning protected system resources to the protection system, which creates from that information a set of threat attack detection metrics (TADMs) by which it evaluates payloads of the intercepted traffic. In particular, the intercepted traffic is assessed using conventional threat detection approaches to identify suspect payloads. The suspect payloads are additionally evaluated against the TADMs to determine if they contain any references to specific resources of the protected system. For those of the suspect payloads for which the TADM evaluation reveals positive results, the protection system provides an alert that a targeted attack has been recognized.