Targeted Attack Detection via Resource-Specific Metrics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security solutions for computer-based environments are unable to effectively distinguish between malicious payloads and targeted attacks, which are sophisticated and directed at specific resources, leading to challenges in detection and false positive reporting.
Innovation Solution
A protection system intercepts traffic and generates threat attack detection metrics (TADMs) using data from data collection agents, combining conventional detection methods with resource-specific evaluations to identify and alert on targeted attacks, allowing only non-malicious traffic to pass through.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional threat detection approaches (signature-based, statistical modeling, heuristic rules) are used to detect payloads, then detection coverage is improved, but the ability to distinguish targeted attacks from general malicious payloads deteriorates
Solution Approach 1:
The detection system is segmented into two distinct evaluation layers: first, conventional threat detection approaches identify suspect payloads; second, TADM evaluation specifically assesses whether suspect payloads reference protected system resources. This segmentation allows each layer to specialize in its strength while collectively resolving the contradiction between broad detection coverage and precise targeted attack identification.
Solution Approach 2:
TADM metrics serve as an intermediary evaluation layer between conventional threat detection and final targeted attack determination. The TADM metrics bridge the gap by providing resource-specific reference data that enables precise identification of targeted attacks without compromising the broad detection capabilities of conventional approaches.
2Measurement precision
If TADM evaluation is applied to all suspect payloads, then targeted attack detection accuracy is improved, but system complexity and processing overhead increase
Solution Approach 1:
The system performs preliminary threat detection using conventional approaches before applying TADM evaluation. By pre-identifying suspect payloads, the system prepares the groundwork for subsequent TADM assessment, ensuring that resource-specific evaluation is applied only where necessary rather than to all traffic uniformly.
Solution Approach 2:
TADM evaluation is applied partially rather than universally - specifically to suspect payloads identified by conventional detection methods. This partial application approach maintains high targeted attack detection accuracy while avoiding the excessive complexity and processing overhead that would result from applying TADM evaluation to all incoming traffic.
3Adaptability or versatility
If resource-specific metrics (TADMs) are collected and maintained for protected systems, then targeted attack detection capability is improved, but information management complexity increases
Solution Approach 1:
The TADM metric framework is designed to be universal and adaptable across different protected systems and resource types. Rather than creating specialized detection mechanisms for each system, the same TADM evaluation approach can assess various resources (databases, files, applications, libraries) using consistent resource identifier matching, reducing information management complexity while maintaining high detection capability.
Data Source
AI summary
Systems and methods for targeted attack detection. A protection system intercepts traffic destined for a protected system and only traffic identified as non-malicious is allowed to pass thereto. Data collection agents (DCAs) instantiated at protected systems report information concerning protected system resources to the protection system, which creates from that information a set of threat attack detection metrics (TADMs) by which it evaluates payloads of the intercepted traffic. In particular, the intercepted traffic is assessed using conventional threat detection approaches to identify suspect payloads. The suspect payloads are additionally evaluated against the TADMs to determine if they contain any references to specific resources of the protected system. For those of the suspect payloads for which the TADM evaluation reveals positive results, the protection system provides an alert that a targeted attack has been recognized.

