Building Risk Scoring Using NLP Threat Prioritization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current building security systems face challenges in efficiently processing and analyzing the high volume of data from various sources, leading to a need for extensive resources and personnel to manage alarms and threats, as they struggle to categorize and prioritize potential threats effectively.
Innovation Solution
A building management system utilizing a Natural Language Processing (NLP) engine to categorize and prioritize threat events by processing descriptions from multiple data sources, generating standardized threat objects, and employing an expiry time prediction model to manage threat duration, along with geofencing to determine threat relevance and dynamic asset threat weighting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual review and monitoring of alarms is performed by security operators and analysts, then threat detection accuracy is improved, but resource requirements and operational costs increase significantly
Solution Approach 1:
The patent introduces an automated analysis system that acts as an intermediary between raw alarm data and security operators. This system processes alarm data, performs risk analysis, and generates prioritized threat assessments, thereby reducing the manual review burden while maintaining detection accuracy through automated preprocessing and filtering mechanisms
Solution Approach 2:
The patent replaces the mechanical manual review process with an automated computational system that uses algorithms to analyze alarm data, assess risks, and prioritize threats. This substitution eliminates the need for extensive human resources in initial screening while preserving detection capabilities through automated pattern recognition and risk scoring
2Adaptability or versatility
If extensive manual monitoring of multiple alarm sources is performed, then comprehensive threat coverage is improved, but operational complexity and personnel requirements increase
Solution Approach 1:
The patent implements a universal analysis platform that can process multiple types of alarm data from various sources simultaneously. The system performs diverse functions including data ingestion, normalization, risk analysis, and reporting within a single integrated architecture, thereby achieving comprehensive threat coverage without proportionally increasing operational complexity
Solution Approach 2:
The patent segments the complex monitoring task into distinct modular components: data ingestion modules for different alarm sources, normalization layers for standardizing data formats, risk analysis engines for assessing threats, and prioritization systems for ordering alerts. This segmentation allows comprehensive coverage while managing complexity through organized, reusable modules
3Loss of information
If high volume alarm data is processed manually, then detailed threat analysis is improved, but processing time and response efficiency deteriorate
Solution Approach 1:
The patent performs preliminary automated processing of alarm data including filtering, normalization, and initial risk assessment before presenting information to operators. This preliminary action preserves detailed analysis capabilities by pre-organizing and pre-processing data, allowing operators to focus on high-value decisions without manual preprocessing time
Solution Approach 2:
The patent implements continuous automated processing of alarm streams with real-time risk analysis and dynamic prioritization. The system operates continuously to maintain up-to-date threat assessments without interruption, ensuring detailed analysis is available immediately when needed without manual processing delays
Data Source
AI summary
A building management system includes one or more computer-readable storage media having instructions stored thereon that, when executed by one or more processors, cause the one or more processors to receive threats, the threats each indicating an incident affecting a dynamic risk score associated with an asset, wherein one or more of the threats are current threats that are active at a current point in time and one or more of the threats are historic threats that were active at one or more past times. The instructions cause the one or more processors to generate, based on the one or more current threats, the dynamic risk score at the current point in time, generate, based on the one or more historic threats, a baseline risk score, and cause a user interface to display an indication of the dynamic risk score at the current point in time and an indication of the baseline risk score.


