Automatic Incident Generator for DLP Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Data Loss Prevention (DLP) systems require manual configuration, leading to errors, increased costs, and delayed responses to changing threat environments, as they rely on pre-defined rules that are slow to adapt to new patterns of malicious activities.
Innovation Solution
An Automatic Incident Generator (AIG) system that compares ongoing events to a database of known incident signatures, using a Degree of Variance function to automatically detect and generate new incidents, allowing for immediate response to potential security threats by identifying patterns similar to previously investigated incidents.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual configuration of DLP rules is used, then system reliability is improved through human expertise, but productivity deteriorates due to slow response to changing threats
Solution Approach 1:
The system performs self-configuration by automatically generating detection rules from incident data without human intervention. The rule generator analyzes incident patterns and creates new detection rules autonomously, eliminating the need for manual configuration while maintaining high detection accuracy through learned patterns.
Solution Approach 2:
The system implements a feedback loop where detected incidents are fed back into the rule generation process. When new incidents are detected, they are analyzed and used to refine and update detection rules, creating a continuous improvement cycle that adapts to evolving threats automatically.
2Measurement precision
If manual configuration of DLP rules is used, then detection precision is improved through expert knowledge, but device complexity increases due to manual intervention requirements
Solution Approach 1:
The system autonomously generates and updates detection rules without requiring manual configuration. The rule generator automatically analyzes incident data, identifies patterns, and creates precise detection rules, eliminating complex manual configuration processes while maintaining high detection precision.
Solution Approach 2:
The patent replaces manual mechanical configuration processes with an automated computational system. Instead of manually creating and updating rules, the system uses algorithmic analysis of incident data to generate rules automatically, substituting human manual work with automated processing.
3Ease of operation
If pre-defined rules are used, then ease of operation is improved through simplicity, but adaptability deteriorates due to inability to respond to new threat patterns
Solution Approach 1:
The system transitions from static pre-defined rules to dynamic adaptive rules. Detection rules are continuously updated based on analyzed incident patterns, allowing the system to adapt to new threat patterns while maintaining operational simplicity through automated updates without requiring manual reconfiguration.
Solution Approach 2:
The system uses feedback from detected incidents to continuously adapt detection rules. When new threat patterns are identified through incident analysis, the rule generator automatically updates rules to detect these patterns, enabling the system to adapt to evolving threats while maintaining ease of operation through automated processes.
Data Source
AI summary
A system for automatic recognition of security incidents includes a processor coupled to a memory storing instructions, the processor being configured to implement the instructions for an automatic incident generator (AIG) with at least one type of events related to the system, and access to a repository of information about previously recorded incidents with the events related to these previously recorded incidents, to monitor a plurality of events, identify sequences of events including suspected signatures that are capable of constituting an incident, calculate a degree of variance (DoV) of the suspected signatures and at least one signature related to a previously recorded incident, compare the DoV to at least one threshold and, if the DoV is less (or less or equal) to the threshold, identify the incident and optionally initiate the workflow related to the identified incident.


