AI Threat Mitigation Across Security Subsystems in Real Time
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The complexity of computer attacks is increasing, and existing threat mitigation systems struggle to effectively monitor and respond to security events across multiple computing systems and subsystems, often relying on outdated methods like predefined rules or signature-based detection.
Innovation Solution
A threat mitigation system that utilizes AI/ML processes to analyze data from various security-relevant subsystems, combining and processing information to generate analysis data, allowing for real-time detection and response to security events, including autonomous threat mitigation plans based on threat levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional predefined rules or signature-based detection methods are used, then the system is simpler to implement, but it cannot effectively detect sophisticated and evolving security threats
Solution Approach 1:
The patent replaces traditional mechanical rule-based detection systems with AI/ML-based automated analysis systems. The AI/ML processes automatically analyze security events, consolidate data from multiple sources, and generate threat assessments without relying on predefined rules or signatures, enabling detection of sophisticated threats while reducing manual configuration complexity
Solution Approach 2:
The system implements self-service through autonomous threat mitigation plans that are automatically generated and executed by the AI/ML processes. The system consolidates data from multiple security subsystems, autonomously analyzes threats, and executes remediation actions without requiring constant human intervention, improving detection reliability while managing complexity through automation
2Measurement precision
If data from multiple security subsystems is consolidated and analyzed in real-time, then the ability to detect sophisticated threats improves, but the processing time and computational resources increase
Solution Approach 1:
The patent applies preliminary action by pre-consolidating data from multiple security subsystems into unified data structures and pre-configuring AI/ML analysis models. Security events are normalized and prepared in advance, allowing the AI/ML processes to perform rapid analysis when threats occur, improving both accuracy and response speed
Solution Approach 2:
The system maintains continuous analysis of security events through persistent AI/ML processes that constantly monitor and evaluate consolidated data from multiple sources. This continuous operation allows the system to detect threats in real-time without interruption, maintaining high measurement precision while optimizing processing efficiency through sustained analytical operations
3Productivity
If autonomous threat mitigation plans are implemented, then the response speed to severe threats improves, but the risk of false positives and incorrect automated actions increases
Solution Approach 1:
The patent implements feedback mechanisms where the AI/ML processes continuously evaluate the effectiveness of executed threat mitigation actions. The system monitors outcomes of automated responses, learns from results, and adjusts future decision-making to reduce false positives. This feedback loop maintains high response speed while improving action accuracy over time through adaptive learning
Solution Approach 2:
The system dynamically adjusts analysis and response parameters based on threat severity levels and contextual information. The AI/ML processes modify detection thresholds, analysis depth, and mitigation aggressiveness according to real-time conditions, enabling fast response to severe threats while maintaining reliability by scaling back for lower-severity events where false positives are more costly
Data Source
AI summary
A computer-implemented method, computer program product and computing system for identifying an event that concerns a network entity on a computer platform; obtaining entity data for the network entity from a plurality of data sources, thus defining a plurality of network entity data portions; and combining the plurality of network entity data portions to form consolidated network entity data for the network entity.


