Automated Data Triage System for Network Malware Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The detection of malware and malicious activity on networks is a labor-intensive task, requiring analysts to manually sift through tracking logs and other information to discern patterns and gain context, which is inefficient and time-consuming.
Innovation Solution
A data analysis system that receives raw data items from monitored networks, filters out non-relevant data, enriches them with contextual information, scores them, and prioritizes them using algorithms, allowing analysts to focus on high-priority 'data item leads' through an interactive and dynamic user interface for efficient analysis and triage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual analysis of tracking logs and network information is performed, then contextual understanding and pattern recognition can be achieved, but the process becomes labor-intensive and time-consuming
Solution Approach 1:
The patent introduces an automated data analysis system that acts as an intermediary between raw network data and human analysts. The system automatically performs data collection, enrichment, scoring, and triage functions, providing pre-processed and prioritized information to analysts. This intermediary system handles the time-consuming manual tasks while preserving the analytical quality through automated scoring algorithms and contextual enrichment processes.
Solution Approach 2:
The patent replaces the mechanical manual analysis process with an automated computer-based system. Instead of analysts manually reviewing tracking logs and network information, the system automatically collects data from multiple sources, enriches it with contextual information, scores data items using algorithms, and presents prioritized results. This substitution dramatically reduces analysis time while maintaining or improving accuracy through consistent automated processing.
2Reliability
If comprehensive data enrichment and analysis are performed on all raw data items, then detection accuracy improves, but system complexity and processing overhead increase
Solution Approach 1:
The patent applies local quality by providing different levels of enrichment and analysis to different data items based on their characteristics and priority scores. Rather than uniformly processing all data items with the same level of detail, the system enriches and analyzes data items selectively based on their relevance and potential threat level. This approach maintains high detection accuracy for critical items while reducing overall system complexity through differentiated processing.
Solution Approach 2:
The patent changes parameters such as enrichment depth, analysis intensity, and processing priority based on data item characteristics. The system dynamically adjusts processing parameters using scoring algorithms that evaluate data relevance, threat level, and contextual factors. This parameter adaptation allows the system to maintain high detection accuracy for high-priority items while reducing processing overhead for lower-priority data, effectively managing system complexity.
3Measurement precision
If all raw data items are processed and reviewed individually, then thorough analysis is achieved, but productivity and efficiency decrease
Solution Approach 1:
The patent implements preliminary action by automatically performing data enrichment, scoring, and triage before presenting data to analysts. The system pre-processes raw data items by collecting relevant information from multiple sources, enriching them with contextual data, and calculating priority scores using algorithms. This preliminary processing ensures thorough analysis is performed automatically on all items while allowing analysts to focus their productivity on reviewing and making decisions about the already-prepared high-priority items.
Solution Approach 2:
The patent segments the analysis process into distinct automated and manual components. The system automatically handles data collection, enrichment, scoring, and filtering tasks, then segments the remaining high-priority items for human analyst review. This segmentation allows thorough automated processing of all data while maintaining high productivity by limiting manual review to only the most relevant items identified through automated scoring and triage.
Data Source
AI summary
Embodiments of the present disclosure relate to a data analysis system that may receive data comprising a plurality of raw data items from one or more data sources, such as a monitoring agent located in a monitored network. The received data may be scored using one or more scoring rules and/or algorithms, with raw data items satisfying a score threshold designated as “data item leads.” Raw data items associated with a data item lead may be searched and displayed to the user via an interactive user interface. The data analysis system may be used to execute searches and additional enrichments against the received raw data items. The data analysis system may group received raw data items based upon shared attribute values. The data analysis system may be used to categorize received data and construct timelines, histograms, and/or other visualizations based upon the various attributes of the raw data items.


