Dynamic Threat Scoring for Intrusion Detection Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network intrusion detection and prevention systems rely heavily on human experts for threat analysis, leading to inefficiencies due to information overload and the inability to accurately assess threats in real-time, often resulting in false positives and compromised network security.
Innovation Solution
A security expert system (SES) that automates threat analysis and response by continuously learning about network vulnerabilities, generating dynamic threat ratings, and taking corrective actions, such as blocking validated threats and containing compromised hosts, using heuristic data and user-supplied information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If IDS-based systems use hard coded threat values for intrusion detection, then the system can quickly identify attack types, but it cannot accurately assess the true threat level because it ignores target system information and generates false positives
Solution Approach 1:
The system dynamically changes the threat rating parameters from static hard-coded values to dynamic scores that incorporate multiple factors including target system information, attacker profile, and attack characteristics. This allows accurate threat assessment without sacrificing analysis speed, as the system automatically adjusts parameters based on real-time data.
Solution Approach 2:
An intermediary threat scoring system is introduced between the IDS detection engine and the security administrator. This intermediary automatically analyzes multiple data sources (target system details, attacker history, attack patterns) and produces a synthesized threat rating, eliminating the need for administrators to manually evaluate numerous raw parameters while improving accuracy.
2Measurement precision
If security administrators manually analyze security alarms generated by IDS systems, then thorough threat analysis can be performed, but the system cannot keep up with continuous alarm generation and may miss critical threats
Solution Approach 1:
The threat scoring system performs self-service by automatically gathering target system information, attacker profiles, and attack data, then synthesizing this information into threat ratings without human intervention. This automation maintains high accuracy while eliminating the time loss associated with manual analysis of numerous alarms.
Solution Approach 2:
The system implements feedback loops where threat scoring results are continuously refined based on outcomes and new information. The automated system learns from past threats and adjusts scoring algorithms, maintaining accuracy while operating at machine speed rather than human analysis speed.
3Reliability
If IDS systems generate comprehensive security alarms for all detected events, then complete threat coverage is achieved, but information overload occurs requiring review of hundreds of alarms that may not be viable threats
Solution Approach 1:
The threat scoring system applies local quality by treating each alarm individually with customized scoring based on its specific characteristics, target system, and attacker profile. Rather than uniform treatment of all alarms, each event receives a tailored threat rating that reflects its true significance, improving detection coverage while filtering out noise.
Solution Approach 2:
The system segments the alarm processing into distinct scoring components (target system factors, attacker factors, attack factors) that are independently evaluated and then combined. This segmentation allows comprehensive threat coverage through multiple evaluation dimensions while organizing information to improve the signal-to-noise ratio.
4Ease of operation
If IPS systems use hard coded threat values for attack blocking, then simple attack classification is achieved, but the system cannot discriminate threats against individual systems and may block legitimate traffic or miss targeted attacks
Solution Approach 1:
The system transitions from static hard-coded threat values to dynamic threat scoring that adapts to each specific situation. The scoring automatically adjusts based on target system characteristics, attacker behavior patterns, and attack context, providing both simple classification and sophisticated discrimination without increasing operational complexity.
Data Source
AI summary
Embodiments of the invention provide a security expert system (SES) that automates intrusion detection analysis and threat discovery that can use fuzzy logic and forward-chaining inference engines to approximate human reasoning process. Embodiments of the SES can analyze incoming security events and generate a threat rating that indicates the likelihood of an event or a series of events being a threat. In one embodiment, the threat rating is determined based on an attacker rating, a target rating, a valid rating, and, optionally, a negative rating. In one embodiment, the threat rating may be affected by a validation flag. The SES can analyze the criticality of assets and calibrate/recalibrate the severity of an attack accordingly to allow for triage. The asset criticality can have a user-defined value. This ability allows the SES to protect and defend critical network resources in a discriminating and selective manner if necessary (e.g., many attacks).


