Threat Mitigation System Using Attack Simulation Training

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of computer attacks is increasing, making it challenging for existing technologies to effectively mitigate threats, and there is a need for systems that can process large quantities of unstructured data to detect security events within computing platforms.

Innovation Solution

A computer-implemented method using Artificial Intelligence (AI) and Machine Learning (ML) to define a training routine for specific attacks, generating a simulation of the attack within a controlled test environment, allowing trainees to view and respond to the simulation, and determining the effectiveness of their responses, which can be executed on a computing device or stored on a computer-readable medium.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional threat detection methods are used, then the system can operate with simple processing, but it cannot effectively detect complex and evolving attacks

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces simulation environments and training routines as intermediary components between the threat detection system and actual attacks. These simulations act as mediators that allow the system to learn and adapt to complex attack patterns without directly exposing the production system to real threats, thereby improving detection accuracy while managing complexity through controlled experimentation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by conducting training routines and generating simulations before actual threat detection occurs. Attack simulations are created and executed in advance to train detection algorithms, allowing the system to prepare for potential threats and improve its detection capabilities proactively rather than reactively

Inventive Principle:
Principle #10Preliminary action

2Reliability

If large quantities of unstructured data are processed to detect security events, then threat detection capability improves, but data processing complexity and resource requirements increase

Engineering Contradiction:
Improvesecurity event detection reliabilityVSAvoiddata processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the large quantity of unstructured data into manageable simulation cases and training scenarios. By dividing the data processing task into discrete simulation runs with specific attack patterns, the system can process complex data sets systematically, improving detection reliability while managing processing complexity through structured segmentation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates copies of attack patterns through simulation environments rather than processing raw unstructured data directly. These simulated attack copies allow the system to learn from threat patterns in a controlled manner, reducing the complexity of processing actual unstructured security data while maintaining detection reliability

Inventive Principle:
Principle #26Copying

3Productivity

If attack simulations are generated and executed in controlled environments, then training effectiveness can be measured, but the system requires additional infrastructure and resources

Engineering Contradiction:
Improvethreat response training efficiencyVSAvoidinfrastructure complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The simulation environment is designed as a universal platform that serves multiple functions: training detection algorithms, evaluating response effectiveness, and testing security configurations. This multi-functional approach allows the same infrastructure to support various training scenarios and evaluation metrics, improving training efficiency while reducing the need for separate specialized systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11709946B2Threat mitigation system and method
Publication Date: 2023.07.25 RELIAQUEST HOLDINGS LLC
  • US11709946B2 patent drawing
  • US11709946B2 patent drawing
  • US11709946B2 patent drawing

AI summary

A computer-implemented method, computer program product and computing system for: defining a training routine for a specific attack of a computing platform; and generating a simulation of the specific attack by executing the training routine within a controlled test environment.