Method for determining likely malicious behavior based on abnormal behavior pattern comparison
A method for a cyber threat defense system is provided. The method comprises receiving a first abnormal behavior pattern where the first abnormal behavior pattern represents behavior on a first network deviating from a normal benign behavior of that network; and receiving a second abnormal behavior pattern where the second abnormal behavior pattern representing either behavior on the first network or on a second network deviating from a normal benign behavior of that network. The method further comprises comparing the first and second abnormal behavior patterns to determine a similarity score between the first and second abnormal behavior patterns and determining, based on the comparison, that the first abnormal behavior pattern likely corresponds to malicious behavior when the similarity score is above a threshold. A corresponding non-transitory computer readable medium is also provided.
1 . A method for a cyber threat defense system, comprising:
using an inoculation module from a first cyber threat defense system protecting a first network to generate an inoculation notice having an inoculation pattern to warn about and supply one or more suggested remediation actions to take against a potential breach state of normal behavior representing a first abnormal behavior pattern, which corresponds to a cyber threat that could harm one or more target devices in a second network, where the inoculation module uses a communication module to send the inoculation notice to the one or more target devices on the second network protected by an affiliated cyber threat defense system via at least one output port;
receiving the first abnormal behavior pattern, the first abnormal behavior pattern representing behavior on the first network deviating from a normal benign behavior defined in relation to a first benign behavior benchmark of the first network;
receiving a second abnormal behavior pattern, the second abnormal behavior pattern representing behavior on the second network deviating from a normal benign behavior defined in relation to a second benign behavior benchmark of the second network;
comparing the first and second abnormal behavior patterns to determine a similarity score between the first and second abnormal behavior patterns;
determining, based on the comparison, that the first abnormal behavior pattern likely corresponds to malicious behavior when the similarity score is above a threshold;
using an autonomous response module in the cyber threat defense system, rather than a human taking an action, to cause one or more autonomous actions to be taken to contain the cyber threat corresponding to the malicious behavior when a threat risk parameter from a cyber threat module in the cyber threat defense system is equal to or above an actionable threshold, based upon the one or more suggested remediation actions contained in the inoculation notice; and
using the cyber threat module's configured cooperation with the autonomous response module, to cause the one or more autonomous actions to be taken to contain the cyber threat, which improves computing devices in the first network by limiting an impact of the cyber threat from consuming unauthorized CPU cycles, memory space, and power consumption in the computing devices via responding to the cyber threat without waiting for some human intervention, wherein the autonomous response module initiates the one or more autonomous actions to surgically counteract malicious activity indicated by at least one of the first and the second abnormal behavior patterns, without disrupting normal network behavior.
2 . The method of claim 1 , wherein receiving the first abnormal behavior pattern comprises:
comparing input data monitoring the first network to at least one machine-learning model trained on a normal benign behavior of the first network using a normal behavior benchmark describing parameters corresponding to a normal pattern of activity of the first network to determine that a network behavior of the first network deviates from the normal benign behavior of the first network;
analyzing the network behavior of the first network to extract first metadata that describes how the network behavior of the first network deviates from the normal benign behavior of the first network; and
generating the first abnormal behavior pattern using the first metadata.
3 . The method of claim 2 , wherein the first abnormal behavior pattern is generated by encoding the first metadata into a single value, a vector or a matrix.
4 . The method of claim 1 , wherein when the second abnormal behavior pattern represents behavior on the first network deviating from a normal benign behavior of that network, receiving the second abnormal behavior pattern comprises:
comparing input data monitoring the first network to at least one machine-learning model trained on a normal benign behavior of the first network using a normal behavior benchmark describing parameters corresponding to a normal pattern of activity of the first network to determine that a network behavior of the first network deviates from the normal benign behavior of the first network;
analyzing the network behavior of the first network to extract second metadata that describes how the network behavior of the first network deviates from the normal benign behavior of the first network; and
generating the second abnormal behavior pattern using the second metadata.
5 . The method of claim 4 , wherein the second abnormal behavior pattern is generated by encoding the second metadata into a single value, a vector or a matrix.
6 . The method of claim 1 , wherein when the second abnormal behavior pattern represents behavior on the second network deviating from a normal benign behavior of that network, receiving the second abnormal behavior pattern comprises:
comparing input data monitoring the second network to at least one machine-learning model trained on a normal benign behavior of the second network using a normal behavior benchmark describing parameters corresponding to a normal pattern of activity of the second network to determine that a network behavior of the second network deviates from the normal benign behavior of the second network;
analyzing the network behavior of the second network to extract second metadata that describes how the network behavior of the second network deviates from the normal benign behavior of the second network; and
generating the second abnormal behavior pattern using the second metadata.
7 . The method of claim 1 , wherein receiving the second abnormal behavior pattern comprises selecting one abnormal behavior pattern from a plurality of stored abnormal behavior patterns as the second abnormal behavior pattern.
8 . The method of claim 7 , wherein the method is repeated such that the first abnormal behavior pattern is compared against each of the stored abnormal behavior patterns.
9 . The method of claim 8 , wherein the method is repeated either until the first abnormal behavior pattern is found to have a similarity score above the threshold when compared with one of the stored abnormal behavior patterns or until the first abnormal behavior pattern is compared against each of the stored abnormal behavior patterns.
10 . The method of claim 1 , wherein the first abnormal behavior pattern is not known to correspond to malicious behavior and wherein the second abnormal behavior pattern corresponds to behavior of a known specific threat actor corresponding to the cyber threat.
11 . The method of claim 10 , wherein the second abnormal behavior pattern includes an encoding of metadata that enables the comparison with the first abnormal behavior pattern to identify that the first abnormal behavior corresponds to the specific threat actor but that does not necessarily identify a specific attack.
12 . The method of claim 11 , wherein receiving the second abnormal behavior pattern comprises providing known compromise instances from the specific threat actor to a neural network to determine the second abnormal behavior pattern corresponding to behavior of that specific threat actor.
13 . The method of claim 12 , wherein the method further comprises, if the similarity score between the first and second abnormal behavior patterns is above the threshold, updating, by the neural network, the second abnormal behavior pattern based on the first abnormal behavior pattern being determined behavior of the specific threat actor.
14 . The method of claim 1 , wherein the first abnormal behavior pattern and the second abnormal behavior pattern are not known to correspond to the malicious behavior.
15 . The method of claim 14 , wherein the first abnormal behavior pattern and the second abnormal behavior pattern have been compared to known patterns of malicious behavior and found not to match the known patterns of malicious behavior.
16 . The method of claim 1 , wherein when it is determined that the first abnormal behavior pattern likely corresponds to the malicious behavior, sending the inoculation notice having the inoculation pattern describing the first abnormal behavior pattern to the one or more target devices to warn of the potential cyber threat, where the inoculation notice is stored in a network-accessible inoculation database.
17 . The method of claim 16 , further comprising determining a first remediation action in response to the potential cyber threat, wherein the inoculation notice includes the first remediation action, where the inoculation module generates the inoculation notice containing incident data describing a breach state by a user or device, acting as a network entity, to warn other computing devices of the potential cyber threat as well as provide the first remediation action instruction to describe at least one action to remediate the breach state, and wherein the autonomous response module is configured to automatically generate the remediation action instruction from the inoculation notice when the cyber threat is determined to be similar to the potential cyber threat described in the inoculation notice based upon the first remediation action, where the inoculation notice includes an outside data set collected from at least one data source outside the first network describing at least one of an outside action and an outside state related to the cyber threat.
18 . The method of claim 1 , further comprising, when it is determined that the first abnormal behavior pattern likely corresponds to the malicious behavior, presenting a description of the first abnormal behavior pattern to a user analyst for review.
19 . A non-transitory computer readable medium including executable instructions that, when executed with one or more processors, cause a cyber threat defense system to perform the method of claim 1 .
20 . A cyber threat defense system, comprising:
one or more processing components; and
a non-transitory computer readable medium;
an inoculation module stored on the non-transitory computer readable medium configured in a first cyber threat defense system that protects a first network configured to generate an inoculation notice having an inoculation pattern to warn about and supply one or more suggested remediation actions to take against a potential breach state of normal behavior representing a first abnormal behavior pattern, which corresponds to a cyber threat that could harm one or more target devices in a second network, where the inoculation module is configured to use a communication module to send the inoculation notice to the one or more target devices on the second network protected by an affiliated cyber threat defense system via at least one output port;
where the one or more target devices in the second network are configured to receive the first abnormal behavior pattern, where the first abnormal behavior pattern represents behavior on the first network deviating from a normal benign behavior defined in relation to a first benign behavior benchmark of the first network;
where the one or more target devices in the second network are configured to receive a second abnormal behavior pattern, where the second abnormal behavior pattern representing behavior on the second network deviating from a normal benign behavior defined in relation to a second benign behavior benchmark of the second network;
where the affiliated cyber threat defense system is configured to compare the first and second abnormal behavior patterns to determine a similarity score between the first and second abnormal behavior patterns;
where the affiliated cyber threat defense system is configured to determine, based on the comparison, that the first abnormal behavior pattern likely corresponds to malicious behavior when the similarity score is above a threshold;
where the affiliated cyber threat defense system is configured to use an autonomous response module in the cyber threat defense system, rather than a human taking an action, to cause one or more autonomous actions to be taken to contain the cyber threat corresponding to the malicious behavior when a threat risk parameter from a cyber threat module in the cyber threat defense system is equal to or above an actionable threshold, based upon the one or more suggested remediation actions contained in the inoculation notice, and
where the cyber threat module is configured to cooperate with the autonomous response module to cause the one or more autonomous actions to be taken to contain the cyber threat, which improves computing devices in the first network by limiting an impact of the cyber threat from consuming unauthorized CPU cycles, memory space, and power consumption in the computing devices via responding to the cyber threat without waiting for some human intervention,
wherein the autonomous response module is configured to initiate the one or more autonomous actions to surgically counteract malicious activity indicated by at least one of the first and the second abnormal behavior patterns, without disrupting normal network behavior.