Weak Indicator Correlation for Cyber-Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity solutions face challenges in accurately detecting cyber-attacks due to high false positives and false negatives, as malicious software operations can resemble legitimate network communications, making it difficult to identify indicators of compromise.
Innovation Solution
A rules-based system and method that uses correlation logic to group weak indicators into strong indicators by applying prescribed correlation rules, analyzing temporal relationships and weightings, to determine if they correspond to known malicious patterns, thereby improving malware detection accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional IOC detection methods are used to monitor network traffic, then security administrators can identify indicators of compromise, but the system experiences high false positives and false negatives because malware operations resemble legitimate communications
Solution Approach 1:
The patent combines multiple weak indicators into a single strong indicator through correlation logic. Individual indicators that show suspicious behavior patterns are merged and analyzed together, allowing the system to distinguish malicious activity from legitimate communications more accurately. This combination approach reduces false positives by requiring multiple corroborating signals before triggering an alert.
Solution Approach 2:
The patent segments the detection process into multiple stages: collecting individual indicators, evaluating their strength, correlating related indicators, and generating final alerts. This segmentation allows the system to process network traffic in manageable units and apply different analysis techniques at each stage, improving overall detection precision while maintaining reliability.
2Reliability
If cybersecurity systems monitor all network traffic for indicators of compromise, then they can detect cyber-attacks, but the complexity of analyzing and evaluating large volumes of data increases
Solution Approach 1:
The patent applies local quality by assigning different evaluation criteria to different types of indicators based on their specific characteristics. Each indicator is assessed according to its own weight and relevance, allowing the system to handle diverse data types efficiently. This localized approach simplifies the overall analysis complexity by treating each indicator according to its specific nature rather than applying a uniform complex analysis to all data.
Solution Approach 2:
The patent implements partial action by focusing analysis resources on indicators that meet certain threshold criteria for suspiciousness. Rather than analyzing every single data point in depth, the system performs preliminary filtering and concentrates detailed analysis only on indicators that show potential malicious patterns, thereby reducing overall analysis complexity while maintaining comprehensive detection coverage.
3Loss of information
If cybersecurity systems generate alerts for every detected indicator of compromise, then security administrators receive comprehensive information, but the volume of alerts makes it difficult to prioritize and respond to actual threats
Solution Approach 1:
The patent extracts only the most significant information by generating alerts based on strong indicators rather than every individual indicator. The correlation logic filters out redundant or low-significance findings, extracting only the critical threat information that requires administrator attention. This extraction approach maintains information completeness for actual threats while eliminating noise that complicates prioritization.
Data Source
AI summary
A method for detecting a cyber-attack is described. The method features (i) collecting a first plurality of weak indicators, (ii) grouping a second plurality of weak indicators from the first plurality of weak indicators where the second plurality of weak indicators being lesser in number than the first plurality of weak indicators, and (iii) performing a correlation operation between the second plurality of weak indicators and one or more patterns or sequences of indicators associated with known malware. A weak indicator of the first plurality of weak indicators corresponds to data that, by itself, is not definitive as to whether the data is associated with a cyber-attack being conducted on a source of the weak indicator.


