Automated Data Triage System for Network Malware Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The detection of malware and malicious activity on networks is a labor-intensive task, requiring analysts to manually sift through tracking logs and other information to discern patterns and gain context, which is inefficient and time-consuming.

Innovation Solution

A data analysis system that receives raw data items from monitored networks, filters out non-relevant data, enriches them with contextual information, scores them, and prioritizes them using algorithms, allowing analysts to focus on high-priority 'data item leads' through an interactive and dynamic user interface for efficient analysis and triage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual analysis of tracking logs and network information is performed, then contextual understanding and pattern recognition can be achieved, but the process becomes labor-intensive and time-consuming

Engineering Contradiction:
Improvecontextual understandingVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent introduces an automated data analysis system that acts as an intermediary between raw network data and human analysts. The system automatically performs data collection, enrichment, scoring, and triage functions, providing pre-processed and prioritized information to analysts. This intermediary system handles the time-consuming manual tasks while preserving the analytical quality through automated scoring algorithms and contextual enrichment processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical manual analysis process with an automated computer-based system. Instead of analysts manually reviewing tracking logs and network information, the system automatically collects data from multiple sources, enriches it with contextual information, scores data items using algorithms, and presents prioritized results. This substitution dramatically reduces analysis time while maintaining or improving accuracy through consistent automated processing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If comprehensive data enrichment and analysis are performed on all raw data items, then detection accuracy improves, but system complexity and processing overhead increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by providing different levels of enrichment and analysis to different data items based on their characteristics and priority scores. Rather than uniformly processing all data items with the same level of detail, the system enriches and analyzes data items selectively based on their relevance and potential threat level. This approach maintains high detection accuracy for critical items while reducing overall system complexity through differentiated processing.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes parameters such as enrichment depth, analysis intensity, and processing priority based on data item characteristics. The system dynamically adjusts processing parameters using scoring algorithms that evaluate data relevance, threat level, and contextual factors. This parameter adaptation allows the system to maintain high detection accuracy for high-priority items while reducing processing overhead for lower-priority data, effectively managing system complexity.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If all raw data items are processed and reviewed individually, then thorough analysis is achieved, but productivity and efficiency decrease

Engineering Contradiction:
Improveanalysis thoroughnessVSAvoidanalysis throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements preliminary action by automatically performing data enrichment, scoring, and triage before presenting data to analysts. The system pre-processes raw data items by collecting relevant information from multiple sources, enriching them with contextual data, and calculating priority scores using algorithms. This preliminary processing ensures thorough analysis is performed automatically on all items while allowing analysts to focus their productivity on reviewing and making decisions about the already-prepared high-priority items.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the analysis process into distinct automated and manual components. The system automatically handles data collection, enrichment, scoring, and filtering tasks, then segments the remaining high-priority items for human analyst review. This segmentation allows thorough automated processing of all data while maintaining high productivity by limiting manual review to only the most relevant items identified through automated scoring and triage.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11580680B2Systems and interactive user interfaces for dynamic retrieval, analysis, and triage of data items
Publication Date: 2023.02.14 PALANTIR TECHNOLOGIES INC
  • US11580680B2 patent drawing
  • US11580680B2 patent drawing
  • US11580680B2 patent drawing

AI summary

Embodiments of the present disclosure relate to a data analysis system that may receive data comprising a plurality of raw data items from one or more data sources, such as a monitoring agent located in a monitored network. The received data may be scored using one or more scoring rules and/or algorithms, with raw data items satisfying a score threshold designated as “data item leads.” Raw data items associated with a data item lead may be searched and displayed to the user via an interactive user interface. The data analysis system may be used to execute searches and additional enrichments against the received raw data items. The data analysis system may group received raw data items based upon shared attribute values. The data analysis system may be used to categorize received data and construct timelines, histograms, and/or other visualizations based upon the various attributes of the raw data items.