Threat Actor Attribution via Data Normalization and Association Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information handling systems face challenges in attributing threat actors to threat indicators and predicting future attacks effectively, which hampers their ability to respond adequately to security threats.

Innovation Solution

A system and method that normalize threat indicator data, ingest events and alerts, assign probabilities to threat actor groups, and predict future threat events by using normalization schemes, fuzzy logic, and statistical models to determine associations and probabilities, ultimately applying countermeasures based on a threat resistance score.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional threat analysis methods are used, then manual analysis can be performed, but the system cannot accurately attribute threat actors to threat indicators or predict future attacks

Engineering Contradiction:
Improveattribution accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the threat analysis process into distinct modules: data normalization module, association analysis module, attribution module, and prediction module. Each module handles specific aspects of threat analysis independently, enabling accurate actor attribution while maintaining manageable system complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces normalized threat indicator data as an intermediary representation that bridges raw threat data and attribution analysis. By normalizing diverse threat indicators into a standardized format with associated metadata, the system enables accurate actor attribution without directly comparing complex raw data structures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive threat data is collected and analyzed, then accurate attribution and prediction can be achieved, but the processing time and computational resources increase

Engineering Contradiction:
Improveprediction accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary normalization of threat indicator data, converting diverse threat indicators into a standardized format with pre-computed metadata and associations. This preliminary processing enables faster attribution and prediction analysis by eliminating the need for complex real-time data transformation during threat analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system replaces manual threat analysis mechanisms with automated computational processes that use normalized data structures and pre-computed associations. This substitution enables rapid processing of comprehensive threat data through algorithmic analysis rather than manual inspection, significantly reducing analysis time while maintaining accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10587640B2System and method for attribution of actors to indicators of threats to a computer system and prediction of future threat actions
Publication Date: 2020.03.10 SOPHOS INC
  • US10587640B2 patent drawing
  • US10587640B2 patent drawing
  • US10587640B2 patent drawing

AI summary

An information handling system performs a method for analyzing attacks against a networked system of information handling systems. The method includes detecting a threat indicator, representing the threat indicator in part by numerical parameters, normalizing the numerical parameters, calculating one or more measures of association between the threat indicator and other threat indicators, finding an association of the threat indicator with another threat indicator based upon the normalized numerical parameters, and assigning to the threat indicator a probability that a threat actor group caused the attack, wherein the threat actor group was assigned to the other threat indicator. In some embodiments, the normalizing may include transforming a distribution of the numerical parameters to a distribution with a standard deviation of 1 and a mean of 0. In some embodiments, the normalizing may include applying an empirical cumulative distribution function. In some embodiments, the one or more measures of association between the threat indicator and other threat indicators may include a Kendall's tau between the threat indicator and the other threat indicators, a covariance between the threat indicator and the other threat indicators; or a conditional entropy between the threat indicator and the other threat indicators.