Adaptive Data Collection for Security Alerts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Electronic devices face security issues due to inadequate data collection strategies that can lead to missed alerts and potential security threats from entities outside the scope of detected alerts, causing malfunctions or data loss.

Innovation Solution

An adaptive data collector and intelligent response module are implemented within security systems to dynamically adjust data collection based on contextual information such as severity, anomaly, risk, and type of alerts, ensuring relevant data is collected and appropriate remediation actions are taken for entities within and outside the alert scope.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data collection is increased to detect all potential security threats, then security detection capability is improved, but system resource consumption and data processing load increase

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by adjusting data collection intensity based on alert context. Different data collection strategies are applied to different alert types and severity levels, rather than using a uniform approach. This allows the system to collect comprehensive data for high-severity alerts while using minimal collection for low-severity ones, optimizing resource usage while maintaining security detection capability.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamics by making the data collection strategy adaptive and changeable based on real-time conditions. The system dynamically adjusts what data to collect based on alert context, entity relationships, and security priorities. This dynamic approach allows the system to respond to changing security threats while managing resource consumption efficiently.

Inventive Principle:
Principle #15Dynamics

2Productivity

If data collection is limited to reduce resource consumption, then system efficiency is improved, but security threat detection capability deteriorates

Engineering Contradiction:
Improvesystem efficiencyVSAvoidsecurity threat detection capability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies parameter changes by modifying data collection parameters based on alert context. Different parameters such as data volume, collection frequency, and scope are adjusted according to the severity and type of alert. This allows the system to maintain high efficiency for routine alerts while ensuring comprehensive data collection for critical security threats.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent segments the data collection process into different levels and categories based on alert context. Rather than treating all data collection equally, the system divides it into priority levels, collecting essential data for all alerts and additional contextual data for high-priority alerts. This segmentation maintains system efficiency while ensuring thorough detection when needed.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If comprehensive data is collected for all entities, then analysis accuracy is improved, but data processing time and complexity increase

Engineering Contradiction:
Improveanalysis accuracyVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-identifying and prioritizing entities that are most relevant to security alerts based on their relationships to alerted entities. Before full analysis, the system pre-screens entities to determine which ones require detailed data collection and which can be processed with minimal data. This preliminary triage maintains analysis accuracy for critical entities while reducing overall processing time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts and focuses on the most critical data and entities relevant to each alert, rather than processing all available data uniformly. By identifying and extracting only the essential entities and data points needed for analysis, the system maintains high measurement precision for security-critical elements while significantly reducing data processing time and complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If data collection scope is expanded to include entities outside alert scope, then security coverage is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoiddata collection complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a unified data collection framework that handles both alerted entities and related external entities through the same system components. The same adaptive data collector and analysis mechanisms serve multiple purposes: processing direct alert subjects and investigating related entities outside the immediate alert scope. This multi-functionality improves security coverage without proportionally increasing device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240411868A1Adaptive data collection for alerts
Publication Date: 2024.12.12 BLACKBERRY LTD
  • US20240411868A1 patent drawing
  • US20240411868A1 patent drawing
  • US20240411868A1 patent drawing

AI summary

In some examples, a system monitors operations in at least one electronic device in which entities are started, created, or modified, and generates an alert based on the monitoring. The system adapts an amount of data collected based on contextual information associated with the alert, where the adapting of the amount of data collected comprises determining whether to include or exclude data associated with a subset of the entities based on any relationships of the subset of the entities to an entity associated with the alert.