Adaptive Security Actions for Network Risk Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Secure Access Service Edge (SASE) services rely on manually generated rules for mitigating security risks, which can be tedious, inaccurate, and lead to high false alarm rates, causing unnecessary inconvenience to users.

Innovation Solution

The method involves defining event costs and action costs, creating prediction models for each user to predict security events and their severity, and generating an action list to block permissions based on these predictions and costs, allowing for adaptive and optimized action decisions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manually generated rules are used to block permissions based on risk scores, then security risk mitigation is achieved, but false alarm rate increases and user convenience deteriorates

Engineering Contradiction:
Improvesecurity risk mitigationVSAvoidfalse alarm rate
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the parameter basis for decision-making from static manually-generated rules to dynamic multi-factor parameters including event costs, action costs, and predictive risk scores. This allows the system to adjust blocking decisions based on weighted combinations of multiple parameters rather than single threshold rules, reducing false alarms while maintaining security.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements feedback mechanisms where the system continuously learns from blocked and unblocked events, adjusting prediction models and cost parameters accordingly. This feedback loop enables the system to refine its decision-making over time, reducing false alarms while improving security detection accuracy.

Inventive Principle:
Principle #23Feedback

2Reliability

If manually generated rules are used to block permissions, then security risk mitigation is achieved, but system complexity and maintenance burden increase

Engineering Contradiction:
Improvesecurity risk mitigationVSAvoidrule maintenance complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables the system to automatically generate and update its own security policies through machine learning prediction models that continuously analyze event data and adjust blocking decisions. This self-service capability eliminates the need for manual rule creation and maintenance, reducing system complexity while maintaining effective security mitigation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual rule-generation process with automated machine learning systems that predict security risks and generate blocking decisions algorithmically. This substitution transforms the complex manual process of creating and maintaining security rules into an automated computational process.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If aggressive blocking actions are taken based on risk thresholds, then security protection is improved, but user convenience and productivity deteriorate

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies different blocking actions to different users and permissions based on local characteristics such as user role, permission importance, and predicted event severity. Instead of uniform aggressive blocking, the system tailors actions to specific contexts, maintaining security protection while preserving user convenience for low-risk scenarios.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial blocking actions where only specific permissions are blocked rather than complete user blocking. The system applies the minimum necessary blocking action to mitigate detected risks while allowing other permissions to remain functional, thus maintaining productivity while providing security protection.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12074898B1Adaptive actions for responding to security risks in computer networks
Publication Date: 2024.08.27 TREND MICRO INC
  • US12074898B1 patent drawing
  • US12074898B1 patent drawing
  • US12074898B1 patent drawing

AI summary

System and method for taking actions to mitigate security risks in a computer network are disclosed. The costs of security events and taking actions to block permissions granted to users are defined. For each of the users, prediction models are created, one for each of the security events. Using prediction models of a selected user, predictions on whether the security events will occur and/or predictions of severity if the security events actually occur are generated. For the selected user, an action list that indicates whether or not to take actions to block particular permissions granted to the selected user is generated based at least on the predictions, costs of the events, and costs of the permissions.