Top-Down Cyber Threat Detection Using Attack-Vector Scenarios
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cyber security systems operate using a 'bottom-up' approach, relying on vast data collection from endpoints and correlation analysis, which requires significant computational resources and often results in false positive alerts, while neglecting the knowledge of known cyber threats.
Innovation Solution
A 'top-down' cyber security system that utilizes attack-vector scenarios and information about actual events to identify implemented cyber techniques, alerting users of potential attacks by matching actual events with known threat patterns.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a bottom-up approach is used to collect vast amounts of data from endpoints, then the system can identify cyber-attacks by correlating abnormal indications, but it requires a large amount of organizational computation resources and results in false positive alerts
Solution Approach 1:
The patent inverts the traditional bottom-up approach by implementing a top-down methodology. Instead of collecting all endpoint data and filtering for attacks, the system starts with known attack patterns from knowledge bases and proactively searches for matching events. This inversion fundamentally changes the data flow direction and processing logic, reducing computational overhead while maintaining detection accuracy.
Solution Approach 2:
The system performs preliminary actions by pre-loading attack patterns and tactics from knowledge bases into the security system before actual threat detection begins. This allows the system to have attack detection rules ready in advance, eliminating the need to process and analyze all endpoint events in real-time, thereby reducing computational resource consumption during active monitoring.
2Loss of information
If a bottom-up approach is used to collect all indications from endpoints, then the system can analyze events for attack identification, but it disregards the vast amount of knowledge accumulated in knowledge bases like MITRE ATT&CK
Solution Approach 1:
The patent inverts the traditional bottom-up approach by implementing a top-down methodology. Instead of collecting all endpoint data and filtering for attacks, the system starts with known attack patterns from knowledge bases and proactively searches for matching events. This inversion fundamentally changes the data flow direction and processing logic, reducing computational overhead while maintaining detection accuracy.
Solution Approach 2:
The patent introduces a knowledge base as an intermediary layer between threat detection and response actions. This knowledge base (e.g., MITRE ATT&CK framework) serves as a mediator that stores accumulated cyber threat knowledge, enabling the system to match observed events against known attack patterns without requiring complex real-time analysis of all endpoint data, thus reducing system complexity while improving knowledge utilization.
3Reliability
If a bottom-up approach relies on abnormal indications from endpoints, then the system can correlate these indications for attack detection, but it misses signs of cyber-attacks instituted by normal events
Solution Approach 1:
The patent inverts the traditional bottom-up approach by implementing a top-down methodology. Instead of collecting all endpoint data and filtering for attacks, the system starts with known attack patterns from knowledge bases and proactively searches for matching events. This inversion fundamentally changes the data flow direction and processing logic, reducing computational overhead while maintaining detection accuracy.
Solution Approach 2:
The patent applies partial action by focusing monitoring efforts only on events that match known attack patterns rather than analyzing all endpoint events. The system selectively applies detection rules based on the specific attack scenario being monitored, examining only the relevant portion of events that could indicate a threat, thereby missing fewer subtle attacks while reducing overall processing load.
Data Source
AI summary
A cyber security system, the cyber security system comprising a processing circuitry configured to: obtain: (a) an attack-vector scenario, the attack-vector scenario comprising a sequence of cyber tactics, each of the cyber tactics being associated with one or more respective cyber techniques which are possible manifestations of the corresponding cyber tactic in the context of the attack-vector scenario, each cyber technique is associated with a corresponding event type of a plurality of event types that can occur on one or more entities of an organizational network, wherein occurrence of an actual event of the respective event type indicates implementation of the respective cyber technique, and (b) information about actual events that occurred on the one or more entities of the organizational network.


