Asset-Based Severity Scoring With Hypergraph Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cybersecurity protection systems often lack transparency in their scoring calculations, are slow in reporting notifications, and can produce inaccuracies or false positives, failing to account for the unique features of various networks, endpoints, and identities within protected environments.
Innovation Solution
An asset-based severity monitoring system that utilizes machine learning algorithms to generate criticality and behavioral scores, incorporating analyst feedback, and performs tailored remediation actions based on these scores, including automated responses to detected malicious operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional cybersecurity protection systems utilize scoring calculations, then they can provide security assessment, but the scoring process becomes artificially opaque and slow in reporting notifications
Solution Approach 1:
The patent segments the scoring system into multiple independent components: criticality score (based on asset importance), behavioral score (based on activity patterns), and risk score (combined output). Each component is calculated separately and then integrated, making the overall process more transparent and faster than monolithic scoring systems.
Solution Approach 2:
The patent introduces an intermediary machine learning model that acts as a mediator between raw security data and final risk scores. This ML intermediary processes data efficiently, providing both accuracy and speed, and serves as a transparent bridge that can be trained and optimized independently.
2Adaptability or versatility
If cybersecurity protection systems use general scoring methods, then they can provide broad coverage, but they produce inaccuracies and false positives by not accounting for unique features of networks, endpoints, and identities
Solution Approach 1:
The patent applies local quality by customizing the risk assessment for each specific asset (network, endpoint, identity) based on its unique characteristics. The criticality score is determined by asset-specific attributes, and the behavioral score is tailored to each asset's normal activity patterns, enabling accurate detection without false positives from one-size-fits-all approaches.
Solution Approach 2:
The system dynamically adapts to each asset's unique features by continuously learning normal behavioral patterns through machine learning. The behavioral score adjusts based on observed activity variations, allowing the system to maintain high accuracy across diverse cyber terrains while accounting for each asset's individual characteristics.
3Reliability
If cybersecurity systems perform comprehensive analysis of all processes, then they can detect threats accurately, but the system complexity and computational resources increase significantly
Solution Approach 1:
The system performs self-service through automated machine learning models that independently calculate criticality scores, behavioral scores, and risk scores without requiring complex manual analysis. The ML models self-adjust and optimize based on observed data, reducing system complexity while maintaining high detection reliability through automated, consistent scoring processes.
4Productivity
If cybersecurity systems rely on automated scoring without human feedback, then they can operate quickly, but they cannot learn from analyst expertise and reduce false positives
Solution Approach 1:
The patent implements feedback by allowing cybersecurity analysts to review and adjust risk scores generated by the automated system. Analyst feedback is incorporated to refine the machine learning models, reducing false positives over time while maintaining operational speed. The system balances automated quick scoring with human expertise validation.
Data Source
AI summary
Systems and methods are provided to determine a maliciousness level of an element using a hypergraph of neighbors. The method can include receiving the element; generating a hypergraph of neighbor target elements found in a database, the hypergraph comprising a set of nodes and a set of edges, wherein the set of nodes represents the neighbor target elements, and the set of edges represents connections between the neighbor target elements; classifying nodes and edges in the hypergraph; generating a maliciousness level profile for the element based on aggregation of nodes and edges in the hypergraph; linking information related to the element with the maliciousness level profile for the element; and performing an action based on a type of the element.


