Adaptive Cyber-Security Analytics Scoring Model

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber-security monitoring approaches either produce high-precision alerts with low false positives but struggle with evolving security threats, or they detect a broader range of violations with higher false positives, requiring extensive maintenance and less expert involvement.

Innovation Solution

A unified cyber-security monitoring system that automatically constructs and refines targeted and behavioral anomaly detectors using a correlation engine for adaptive scoring, incorporating data-mining and machine learning to improve detector performance and reduce false positives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If targeted event-based detection is used, then precision of security violation detection is improved, but adaptability to evolving threats deteriorates

Engineering Contradiction:
Improveprecision of security violation detectionVSAvoidadaptability to evolving threats
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent combines targeted event-based detection and behavioral anomaly detection into a unified scoring model. The scoring model integrates both approaches by computing scores from multiple detectors including targeted detectors (IDS, antivirus) and behavioral anomaly detectors (traffic clustering, alert correlation), then aggregates these scores to determine security violations. This merging allows the system to maintain the precision of targeted detection while gaining the adaptability of behavioral analysis.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system dynamically adapts by continuously learning from new security events and automatically updating the scoring model. The model evolves over time through machine learning techniques, adjusting weights and parameters based on incoming data without requiring manual reconfiguration. This dynamic behavior enables the system to adapt to evolving threats while maintaining detection precision.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If behavioral anomaly detection is used, then coverage of security violations is improved, but false positive rate increases

Engineering Contradiction:
Improvecoverage of security violationsVSAvoidfalse positive rate
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements feedback mechanisms where validation results from security analysts are fed back into the scoring model. When analysts validate or reject alerts, this information is used to refine the scoring model through automatic updates. The feedback loop allows the system to learn from false positives and adjust its behavior, reducing the false positive rate while maintaining broad coverage of security violations.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The scoring model acts as a composite structure that combines multiple detection approaches with different characteristics. By weighting and aggregating scores from various detectors (targeted and behavioral), the system creates a composite detection mechanism that balances the high coverage of behavioral detection with the low false positive rate of targeted detection.

Inventive Principle:
Principle #40Composite materials

3Measurement precision

If targeted detectors are maintained manually, then detection precision is improved, but complexity of maintenance increases

Engineering Contradiction:
Improvedetection precisionVSAvoidcomplexity of maintenance
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The scoring model performs self-service by automatically updating itself through machine learning from incoming security events. The system autonomously adjusts its parameters, weights, and detection thresholds without requiring manual intervention from security analysts. This self-service capability maintains detection precision while eliminating the complex manual maintenance previously required for targeted detectors.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system automatically changes its operational parameters through continuous learning. The scoring model adjusts its internal parameters (weights, thresholds, feature importance) based on patterns learned from security events, replacing the need for manual parameter tuning and maintenance while preserving detection precision.

Inventive Principle:
Principle #35Parameter changes

4Measurement precision

If extensive expert intervention is used, then detection accuracy is improved, but automation level deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoidautomation level
Core Design Contradiction:
Measurement precisionVSExtent of automation

Solution Approach 1:

The system uses feedback from expert validation to improve automation. Security analysts validate a subset of alerts, and this feedback is automatically processed to refine the scoring model. The system learns from expert decisions and automatically applies these learnings to future detections, progressively reducing the need for manual intervention while maintaining or improving detection accuracy.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The scoring model serves itself by automatically learning and updating from validation feedback without requiring continuous expert intervention. The system autonomously improves its detection accuracy through machine learning while minimizing the automation level deterioration, as experts only need to provide periodic validation rather than continuous manual tuning.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9032521B2Adaptive cyber-security analytics
Publication Date: 2015.05.12 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9032521B2 patent drawing
  • US9032521B2 patent drawing
  • US9032521B2 patent drawing

AI summary

Performing adaptive cyber-security analytics including a computer implemented method that includes receiving a report on a network activity. A score responsive to the network activity and to a scoring model is computed at a computer. The score indicates a likelihood of a security violation. The score is validated and the scoring model is automatically updated responsive to results of the validating. The network activity is reported as suspicious in response to the score being within a threshold of a security violation value.