Top-Down Cyber Threat Detection Using Attack-Vector Scenarios

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber security systems operate using a 'bottom-up' approach, relying on vast data collection from endpoints and correlation analysis, which requires significant computational resources and often results in false positive alerts, while neglecting the knowledge of known cyber threats.

Innovation Solution

A 'top-down' cyber security system that utilizes attack-vector scenarios and information about actual events to identify implemented cyber techniques, alerting users of potential attacks by matching actual events with known threat patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a bottom-up approach is used to collect vast amounts of data from endpoints, then the system can identify cyber-attacks by correlating abnormal indications, but it requires a large amount of organizational computation resources and results in false positive alerts

Engineering Contradiction:
Improvecyber-attack identification accuracyVSAvoidcomputational resources consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent inverts the traditional bottom-up approach by implementing a top-down methodology. Instead of collecting all endpoint data and filtering for attacks, the system starts with known attack patterns from knowledge bases and proactively searches for matching events. This inversion fundamentally changes the data flow direction and processing logic, reducing computational overhead while maintaining detection accuracy.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system performs preliminary actions by pre-loading attack patterns and tactics from knowledge bases into the security system before actual threat detection begins. This allows the system to have attack detection rules ready in advance, eliminating the need to process and analyze all endpoint events in real-time, thereby reducing computational resource consumption during active monitoring.

Inventive Principle:
Principle #10Preliminary action

2Loss of information

If a bottom-up approach is used to collect all indications from endpoints, then the system can analyze events for attack identification, but it disregards the vast amount of knowledge accumulated in knowledge bases like MITRE ATT&CK

Engineering Contradiction:
Improveknowledge base utilizationVSAvoidsystem architecture complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent inverts the traditional bottom-up approach by implementing a top-down methodology. Instead of collecting all endpoint data and filtering for attacks, the system starts with known attack patterns from knowledge bases and proactively searches for matching events. This inversion fundamentally changes the data flow direction and processing logic, reducing computational overhead while maintaining detection accuracy.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces a knowledge base as an intermediary layer between threat detection and response actions. This knowledge base (e.g., MITRE ATT&CK framework) serves as a mediator that stores accumulated cyber threat knowledge, enabling the system to match observed events against known attack patterns without requiring complex real-time analysis of all endpoint data, thus reducing system complexity while improving knowledge utilization.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a bottom-up approach relies on abnormal indications from endpoints, then the system can correlate these indications for attack detection, but it misses signs of cyber-attacks instituted by normal events

Engineering Contradiction:
Improveattack detection capabilityVSAvoidnormal event analysis capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent inverts the traditional bottom-up approach by implementing a top-down methodology. Instead of collecting all endpoint data and filtering for attacks, the system starts with known attack patterns from knowledge bases and proactively searches for matching events. This inversion fundamentally changes the data flow direction and processing logic, reducing computational overhead while maintaining detection accuracy.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent applies partial action by focusing monitoring efforts only on events that match known attack patterns rather than analyzing all endpoint events. The system selectively applies detection rules based on the specific attack scenario being monitored, examining only the relevant portion of events that could indicate a threat, thereby missing fewer subtle attacks while reducing overall processing load.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250133110A1A top-down cyber security system and method
Publication Date: 2025.04.24 CYTWIST LTD
  • US20250133110A1 patent drawing
  • US20250133110A1 patent drawing
  • US20250133110A1 patent drawing

AI summary

A cyber security system, the cyber security system comprising a processing circuitry configured to: obtain: (a) an attack-vector scenario, the attack-vector scenario comprising a sequence of cyber tactics, each of the cyber tactics being associated with one or more respective cyber techniques which are possible manifestations of the corresponding cyber tactic in the context of the attack-vector scenario, each cyber technique is associated with a corresponding event type of a plurality of event types that can occur on one or more entities of an organizational network, wherein occurrence of an actual event of the respective event type indicates implementation of the respective cyber technique, and (b) information about actual events that occurred on the one or more entities of the organizational network.