The KEA component harvests knowledge out of systems, sub-components and network communication interfaces that deal with health data sources in order to construct models and design methods capable of detecting threat patterns. Machine learning and broader data analytics methodologies are utilized, in order to develop classification models for revealing vulnerabilities and profiling threats. It consists of three sub-components,the Complex Event Processing-based Threat Detection (CEPTD), the Machine Learning-based Threat Detection (MLTD) and the Outlier Detection (OD). The CEPTD uses the Common Attack Patterns Enumeration and Classification (CAPEC) database as a source of predefined threat profiles for the construction of threat detection rules. The MLTD utilizes ML algorithms, which are trained with timestamped annotated events and intrusion incidents obtained by the systems that deal with health data, in order to identify threat patterns and report the patterns and the threats to the TIE component. Finally, the latter KEA sub-component, namely OD, encapsulates the outlier detection technique based on unsupervised learning.
Addressing target audiences and expressing needs
- Business partners – SMEs, Entrepreneurs, Large Corporations
- I/we wish to transfer my/our IPR to an interested party
- Collaboration
We are looking for other business partners, who can help us fulfil our market potential and collaborate with research and technology organisations. We, also, want to transfer our IPR to an interested party.
- Other Actors who can help us fulfil our market potential
- Research and Technology Organisations
- Academia/ Universities
R&D, Technology and Innovation aspects
Development of the tool and methodology have been completed. Prototype has been tested under lab conditions. Nest steps include validation and demonstration in relevant environments. Future collaborations and additional funding will be required to scale-up and perform demonstration in operational environments.
KEA follows a modular architecture paradigm where its sub-components utilize APIs for interconnection and sophisticated endpoints for external data exchange (both incoming data and output of results). This approach offers an increased flexibility in following the evolution of customer needs while it maintains high quality standards in supporting fully scalable solutions
KEA supports incoming information that is standardized and commonly used in several network monitoring applications such as timestamp annotated events, XL-SIEM output, network traffic monitoring (pcap files), Common Vulnerabilities and Exposures (CVEs) and Common Weakness Enumeration (CWEs). Additionally, KEA is delivered as a containerized software that can easily be replicated and deployed into multiple installation environments. These characteristics make KEA’s offering a consistent and robust solution for serving a broad spectrum of client needs in the context of intelligent cybersecurity threat patterns detection.
Increased cybersecurity needs for protecting the ever-growing suite of critical online services (e.g., health related services, public services) in contemporary societies, call for more intelligent threat detection and validation solutions. By offering reliable results combined with a flexible, replicable and scalable business model, KEA delivers long-term value that can help stakeholders to safeguard the quality and uninterrupted operation of crucial infrastructure for our society, environment and economy.

