Building Risk Cards for NLP-Based Threat Prioritization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security platforms face challenges in efficiently processing and analyzing the vast amount of data from building sensors, security cameras, and external sources, leading to a high demand for resources and security personnel to manage alarms and threats.
Innovation Solution
The implementation of a building management system that utilizes a Natural Language Processing (NLP) engine to categorize and prioritize threat events, reducing the need for manual review by generating standardized threat objects and allowing for automated risk analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a large number of security operators and analysts are deployed to review and monitor alarms, then the system can handle the volume of threat data, but the resource requirements and operational costs increase significantly
Solution Approach 1:
The system implements automated self-service through the NLP engine that independently processes threat descriptions, categorizes events, and generates standardized threat objects without human intervention. The automated risk analysis system evaluates threat data, determines risk levels, and prioritizes alarms automatically, enabling the system to serve itself in processing and analyzing threat information.
Solution Approach 2:
The patent replaces the mechanical human review process with an automated computational system. The NLP engine uses natural language processing algorithms to analyze threat descriptions, and the risk analysis system uses computational models to evaluate risk levels, substituting human operators with automated electronic processing systems that can handle larger volumes of data more efficiently.
2Measurement precision
If manual review of all threat events is performed, then accurate categorization and risk assessment can be achieved, but the processing time and resource consumption increase
Solution Approach 1:
The NLP engine serves as an intermediary between raw threat descriptions and the risk analysis system. It processes natural language threat descriptions, extracts key information, and transforms unstructured text into standardized threat objects that the risk analysis system can efficiently evaluate, bridging the gap between raw data and analytical processing.
Solution Approach 2:
The system transforms the parameter representation of threat data from unstructured natural language descriptions into structured standardized threat objects with defined parameters. This parameter transformation enables automated risk analysis by converting qualitative threat descriptions into quantifiable data that can be processed efficiently by computational algorithms.
3Reliability
If all threat data is processed in detail, then comprehensive risk analysis can be performed, but the computational resources and processing complexity increase
Solution Approach 1:
The NLP engine extracts only the essential and relevant information from threat descriptions to create standardized threat objects. Instead of processing all raw data in detail, the system extracts key parameters such as threat type, location, severity indicators, and contextual information, filtering out redundant data and focusing computational resources on the most critical threat characteristics.
Solution Approach 2:
The system segments the threat processing workflow into distinct modular components: the NLP engine for text processing and threat object generation, and the risk analysis system for risk evaluation and prioritization. This segmentation allows each component to specialize in specific tasks, reducing overall system complexity while maintaining comprehensive risk analysis capabilities.
Data Source
AI summary
A building management system includes one or more computer-readable storage media having instructions stored thereon that, when executed by one or more processors, cause the one or more processors to receive threats, the threats each indicating an incident affecting a dynamic risk score associated with an asset, wherein one or more of the threats are current threats that are active at a current point in time and one or more of the threats are historic threats that were active at one or more past times. The instructions cause the one or more processors to generate, based on the one or more current threats, the dynamic risk score at the current point in time, generate, based on the one or more historic threats, a baseline risk score, and cause a user interface to display an indication of the dynamic risk score at the current point in time and an indication of the baseline risk score.


