Adaptive Risk Policy Generation from Organizational Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing risk detection systems face challenges in adapting quickly to unique customer data and attack types, leading to potential losses during the learning period of risk engines, with generic policies resulting in high false positives and requiring significant customer effort to create proprietary rules.

Innovation Solution

A data-driven method for generating adaptive policies by identifying relevant features, calculating probabilities, and determining intervention rates to detect risk-related events, which can be applied during the learning phase of risk engines and beyond.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If generic policies are used in risk detection systems, then implementation is simple and immediate, but false positives increase and detection accuracy deteriorates

Engineering Contradiction:
Improvepolicy implementation simplicityVSAvoidrisk detection accuracy
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The system performs preliminary actions by automatically extracting features and generating policies before the risk engine's learning period begins. This allows tailored policies to be ready in advance, eliminating the need to wait for the risk engine to learn from data while avoiding generic policy limitations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by automatically extracting relevant features from organizational data and generating tailored policies without requiring manual intervention. The process autonomously identifies patterns, calculates probabilities, and creates intervention strategies, freeing customers from manual policy creation efforts.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If manual policy creation is performed by customers, then policies can be highly tailored to unique environments, but significant customer effort and time are required

Engineering Contradiction:
Improvepolicy tailoring capabilityVSAvoidcustomer effort and time investment
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs self-service by automatically extracting features, calculating probabilities, and generating tailored policies without requiring manual customer input. This maintains high adaptability to unique organizational environments while eliminating the time and effort customers would otherwise need to invest in policy creation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces the mechanical process of manual policy creation with an automated machine learning-based approach. Instead of customers manually crafting policies, the system uses algorithms to automatically generate tailored policies from organizational data, maintaining customization while eliminating manual labor.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If risk engines undergo learning period to adapt to unique data and attack types, then detection accuracy improves, but potential losses occur during the learning period

Engineering Contradiction:
Improverisk detection reliabilityVSAvoidlosses during learning period
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system performs preliminary policy generation before the risk engine's learning period begins. By extracting features and creating tailored policies in advance, the system provides immediate protective action during the learning period, preventing losses that would otherwise occur while the risk engine adapts to unique data and attack types.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary layer of automatically generated policies that bridge the gap between generic policies and fully adapted risk engine performance. These intermediary policies provide tailored protection during the learning period, mediating between the need for immediate protection and the risk engine's ongoing adaptation process.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If proprietary rules are created to address specific organizational needs, then detection performance optimizes, but device complexity and implementation difficulty increase

Engineering Contradiction:
Improverisk detection performanceVSAvoidpolicy system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system maintains high detection performance through self-service automation. By automatically extracting features, calculating probabilities, and generating tailored policies, the system achieves proprietary rule effectiveness without requiring manual creation. This eliminates the complexity associated with manual policy development while maintaining optimized detection performance.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the parameters of policy generation from manual specification to automated calculation. Instead of customers manually defining complex rules, the system automatically determines policy parameters based on extracted features and calculated probabilities, achieving optimized performance while reducing implementation complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11113650B2Automated generation of adaptive policies from organizational data for detection of risk-related events
Publication Date: 2021.09.07 EMC IP HLDG CO LLC
  • US11113650B2 patent drawing
  • US11113650B2 patent drawing
  • US11113650B2 patent drawing

AI summary

Techniques are provided for generating adaptive policies from organization data for detection of risk-related events. One method comprises obtaining features identified in organization data of an organization for a risk analysis, wherein a given feature comprises a plurality of data values, wherein each data value for the given feature comprises a discrete value of the given feature or a range of values for the given feature; obtaining a probability of occurrence associated with each data value based on the organization data; identifying a plurality of candidate anomalous data values based on the probabilities of occurrence; determining an intervention rate for a plurality of combinations of the candidate anomalous data values; and generating policies for the organization using the combinations of candidate anomalous data values based on a corresponding intervention rate. The generated policies are used to detect one or more risk-related events.