Automated Cyber Threat Attribution via Computational Graph
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems face challenges in accurately detecting and attributing cyber threats due to the need for extensive manual effort and the difficulty in scaling, as well as the ability to conceal their presence, leading to potential misdirection and errors in threat actor identification.
Innovation Solution
A system for automated cyber physical threat campaign analysis and attribution, utilizing a multi-dimensional time series and graph store hybrid data service, automated planning service module, and directed computation graph module to gather and analyze network data, conduct simulations, and develop a threat profile based on internal and external data sources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual correlation of evidence is used to attribute cyber threats, then analysis accuracy may be improved, but productivity and scalability deteriorate due to extensive manual labor required
Solution Approach 1:
The system enables automated self-service threat analysis by having the computational graph automatically ingest evidence data, perform correlation operations, and generate attribution results without requiring manual analyst intervention for each analysis case, thereby maintaining accuracy while dramatically improving throughput
Solution Approach 2:
The patent replaces the manual mechanical process of evidence correlation with an automated computational graph system that uses distributed computing and algorithmic operations to perform the same analytical function, substituting human labor with automated computational processes
2Measurement precision
If extensive evidence aggregation is performed to improve attribution accuracy, then measurement precision improves, but device complexity and loss of time increase
Solution Approach 1:
The system segments the complex evidence aggregation process into modular computational operations within the graph structure, where different node types handle specific evidence types and correlation logic, making the overall complex system manageable through structured decomposition
Solution Approach 2:
The computational graph serves as a universal framework that can handle multiple types of evidence data, correlation operations, and analysis scenarios through a single unified system architecture, reducing overall system complexity despite the extensive processing performed
3Adaptability or versatility
If manual threat analysis processes are used, then adaptability to new threat types may be maintained, but productivity and response time deteriorate
Solution Approach 1:
The computational graph is designed to be dynamic and adaptable, allowing new evidence sources, correlation rules, and analysis parameters to be added or modified without requiring complete system redesign, enabling rapid adaptation to new threat types while maintaining automated high-speed processing
Solution Approach 2:
The system performs preliminary actions by pre-configuring the computational graph with correlation logic and evidence processing rules, so that when new threats are detected, the analysis can begin immediately using pre-prepared analytical frameworks rather than requiring manual setup each time
Data Source
AI summary
A system for automated cyber physical threat campaign analysis and attribution, comprising a multi-dimensional time series and graph hybrid data server, an automated planning service module, and a directed computation graph module. A dataset is gathered from a monitored network and aggregated into a cyber-physical systems graph. Cyberattack simulations on the monitored network are made using exogenously collected data as input. Metrics are generated based on the cyber-physical systems graph and results from the cyberattack simulations, and the generated metrics are used to develop a threat profile.


