Automated Cyber Threat Attribution via Computational Graph

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems face challenges in accurately detecting and attributing cyber threats due to the need for extensive manual effort and the difficulty in scaling, as well as the ability to conceal their presence, leading to potential misdirection and errors in threat actor identification.

Innovation Solution

A system for automated cyber physical threat campaign analysis and attribution, utilizing a multi-dimensional time series and graph store hybrid data service, automated planning service module, and directed computation graph module to gather and analyze network data, conduct simulations, and develop a threat profile based on internal and external data sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual correlation of evidence is used to attribute cyber threats, then analysis accuracy may be improved, but productivity and scalability deteriorate due to extensive manual labor required

Engineering Contradiction:
Improveattribution accuracyVSAvoidthreat analysis throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system enables automated self-service threat analysis by having the computational graph automatically ingest evidence data, perform correlation operations, and generate attribution results without requiring manual analyst intervention for each analysis case, thereby maintaining accuracy while dramatically improving throughput

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the manual mechanical process of evidence correlation with an automated computational graph system that uses distributed computing and algorithmic operations to perform the same analytical function, substituting human labor with automated computational processes

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If extensive evidence aggregation is performed to improve attribution accuracy, then measurement precision improves, but device complexity and loss of time increase

Engineering Contradiction:
Improvethreat actor identification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the complex evidence aggregation process into modular computational operations within the graph structure, where different node types handle specific evidence types and correlation logic, making the overall complex system manageable through structured decomposition

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The computational graph serves as a universal framework that can handle multiple types of evidence data, correlation operations, and analysis scenarios through a single unified system architecture, reducing overall system complexity despite the extensive processing performed

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If manual threat analysis processes are used, then adaptability to new threat types may be maintained, but productivity and response time deteriorate

Engineering Contradiction:
Improveflexibility in analyzing new threat typesVSAvoidthreat analysis time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The computational graph is designed to be dynamic and adaptable, allowing new evidence sources, correlation rules, and analysis parameters to be added or modified without requiring complete system redesign, enabling rapid adaptation to new threat types while maintaining automated high-speed processing

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary actions by pre-configuring the computational graph with correlation logic and evidence processing rules, so that when new threats are detected, the analysis can begin immediately using pre-prepared analytical frameworks rather than requiring manual setup each time

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10320827B2Automated cyber physical threat campaign analysis and attribution
Publication Date: 2019.06.11 QOMPLX INC
  • US10320827B2 patent drawing
  • US10320827B2 patent drawing
  • US10320827B2 patent drawing

AI summary

A system for automated cyber physical threat campaign analysis and attribution, comprising a multi-dimensional time series and graph hybrid data server, an automated planning service module, and a directed computation graph module. A dataset is gathered from a monitored network and aggregated into a cyber-physical systems graph. Cyberattack simulations on the monitored network are made using exogenously collected data as input. Metrics are generated based on the cyber-physical systems graph and results from the cyberattack simulations, and the generated metrics are used to develop a threat profile.