Weak Indicator Correlation for Cyber-Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity solutions face challenges in accurately detecting cyber-attacks due to high false positives and false negatives, as malicious software operations can resemble legitimate network communications, making it difficult to identify indicators of compromise.

Innovation Solution

A rules-based system and method that uses correlation logic to group weak indicators into strong indicators by applying prescribed correlation rules, analyzing temporal relationships and weightings, to determine if they correspond to known malicious patterns, thereby improving malware detection accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional IOC detection methods are used to monitor network traffic, then security administrators can identify indicators of compromise, but the system experiences high false positives and false negatives because malware operations resemble legitimate communications

Engineering Contradiction:
Improvedetection accuracyVSAvoidfalse positive rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent combines multiple weak indicators into a single strong indicator through correlation logic. Individual indicators that show suspicious behavior patterns are merged and analyzed together, allowing the system to distinguish malicious activity from legitimate communications more accurately. This combination approach reduces false positives by requiring multiple corroborating signals before triggering an alert.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent segments the detection process into multiple stages: collecting individual indicators, evaluating their strength, correlating related indicators, and generating final alerts. This segmentation allows the system to process network traffic in manageable units and apply different analysis techniques at each stage, improving overall detection precision while maintaining reliability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If cybersecurity systems monitor all network traffic for indicators of compromise, then they can detect cyber-attacks, but the complexity of analyzing and evaluating large volumes of data increases

Engineering Contradiction:
Improvedetection coverageVSAvoidanalysis complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by assigning different evaluation criteria to different types of indicators based on their specific characteristics. Each indicator is assessed according to its own weight and relevance, allowing the system to handle diverse data types efficiently. This localized approach simplifies the overall analysis complexity by treating each indicator according to its specific nature rather than applying a uniform complex analysis to all data.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by focusing analysis resources on indicators that meet certain threshold criteria for suspiciousness. Rather than analyzing every single data point in depth, the system performs preliminary filtering and concentrates detailed analysis only on indicators that show potential malicious patterns, thereby reducing overall analysis complexity while maintaining comprehensive detection coverage.

Inventive Principle:
Principle #16Partial or excessive action

3Loss of information

If cybersecurity systems generate alerts for every detected indicator of compromise, then security administrators receive comprehensive information, but the volume of alerts makes it difficult to prioritize and respond to actual threats

Engineering Contradiction:
Improveinformation completenessVSAvoidalert prioritization
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent extracts only the most significant information by generating alerts based on strong indicators rather than every individual indicator. The correlation logic filters out redundant or low-significance findings, extracting only the critical threat information that requires administrator attention. This extraction approach maintains information completeness for actual threats while eliminating noise that complicates prioritization.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10601848B1Cyber-security system and method for weak indicator detection and correlation to generate strong indicators
Publication Date: 2020.03.24 MANDIANT LLC
  • US10601848B1 patent drawing
  • US10601848B1 patent drawing
  • US10601848B1 patent drawing

AI summary

A method for detecting a cyber-attack is described. The method features (i) collecting a first plurality of weak indicators, (ii) grouping a second plurality of weak indicators from the first plurality of weak indicators where the second plurality of weak indicators being lesser in number than the first plurality of weak indicators, and (iii) performing a correlation operation between the second plurality of weak indicators and one or more patterns or sequences of indicators associated with known malware. A weak indicator of the first plurality of weak indicators corresponds to data that, by itself, is not definitive as to whether the data is associated with a cyber-attack being conducted on a source of the weak indicator.