Cybersecurity Threat Prediction via Event Correlation Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity solutions are inadequate in detecting and mitigating complex multi-vector attack campaigns, such as APTs, due to a lack of agility, adaptability, and automatic decision-making capabilities, leading to increased risk of undetected threats and inefficient resource utilization.

Innovation Solution

A cybersecurity system that proactively predicts threats by correlating security events, determining correlation and prediction scores, and executing mitigation actions based on a security policy to block attack propagation and expansion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If current security solutions are used for detection and mitigation, then basic security monitoring is maintained, but the system lacks agility and adaptability to detect and mitigate evolving multi-vector attack campaigns such as APTs

Engineering Contradiction:
Improveadaptability to evolving threatsVSAvoiddetection reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The security system dynamically adapts its detection and mitigation strategies based on evolving threat patterns. The system continuously learns from new attack vectors and adjusts its security policies in real-time, transforming from a static defense mechanism to a dynamic one that can respond to multi-vector attack campaigns and APTs as they evolve.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes its operational parameters including detection thresholds, correlation rules, and mitigation strategies based on the specific characteristics of detected threats. By adjusting these parameters dynamically, the system maintains high detection reliability while adapting to new attack patterns without requiring complete system redesign.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If manual decision-making processes are used by system administrators, then trust in security solutions is maintained through human oversight, but the time needed to mitigate attacks increases significantly

Engineering Contradiction:
Improveautomatic decision-making capabilityVSAvoidmitigation time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-defining security policies, correlation rules, and mitigation strategies before attacks occur. When threats are detected, the system can automatically execute pre-planned mitigation actions without requiring manual administrator intervention, significantly reducing response time while maintaining operational control through predefined policies.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security system enables self-service automated decision-making capabilities that allow it to autonomously detect, analyze, and mitigate threats without continuous human oversight. The system serves itself by automatically adjusting security parameters, correlating events, and executing mitigation actions based on learned patterns and predefined policies.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If current security solutions generate high levels of false positive alerts, then comprehensive monitoring is achieved, but system administrators cannot trust the solutions and must manually perform decision-making

Engineering Contradiction:
Improvealert accuracyVSAvoidresource utilization efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system implements feedback mechanisms where detection results, false positives, and mitigation outcomes are continuously analyzed and fed back into the learning model. This feedback loop allows the system to refine its detection algorithms, reduce false positives over time, and improve alert accuracy while maintaining comprehensive monitoring capabilities.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system replaces manual mechanical decision-making processes with automated intelligent systems that use machine learning and pattern recognition to analyze security events. This substitution reduces false positives by applying consistent analytical rules and frees administrators from manual decision-making, improving resource utilization efficiency.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If mitigation actions are not executed proactively in advance, then current attack responses are sufficient, but the system cannot predict or prevent future exploitation attempts or block attack propagation to other targets

Engineering Contradiction:
Improveproactive protection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies preliminary anti-action by proactively executing mitigation actions before attacks can propagate or cause damage. When potential threats are detected through correlation analysis, the system preemptively blocks attack vectors, isolates affected systems, and prevents exploitation attempts before they can succeed, thereby enhancing reliable protection without requiring overly complex system architecture.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10505953B2Proactive prediction and mitigation of cyber-threats
Publication Date: 2019.12.10 CYBEREASON INC
  • US10505953B2 patent drawing
  • US10505953B2 patent drawing
  • US10505953B2 patent drawing

AI summary

A cyber-security system and method for proactively predicting cyber-security threats are provided. The method comprises receiving a plurality of security events classified to different groups of events; correlating the plurality of received security events to classify potential cyber-security threats to a set of correlation types; determining a correlation score for each classified potential cyber-security threat; and determining a prediction score for each classified potential cyber-security threat, wherein the prediction score is determined based in part on the correlation score.