Cloud Network Security Rule Updates Using ML Event Clustering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computer network security systems, such as web application firewalls, face challenges in quickly identifying potentially threatening events and require substantial time and expertise to configure rules for effective threat detection and response, leading to inefficient and delayed security measures.

Innovation Solution

A machine learning-based approach that automatically analyzes detected events, clusters them into groups, and generates updated security system configurations, reducing the need for manual triage and expertise through automated rule generation and deployment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration of security rules is performed, then security effectiveness is improved, but time consumption and operational complexity increase

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system automatically generates and applies security rules by analyzing detected events and clustering them into patterns, eliminating the need for manual configuration while maintaining effective security coverage. The machine learning model processes events autonomously to create actionable security configurations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system transforms raw event data into clustered security rules by changing the representation parameters of events into actionable configuration parameters, enabling automatic rule generation that maintains security effectiveness without manual intervention.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If manual triage of events is performed, then security accuracy is improved, but operational complexity and expertise requirements increase

Engineering Contradiction:
Improvesecurity accuracyVSAvoidoperational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The machine learning model autonomously performs event analysis and rule generation, replacing manual triage operations. The system self-adjusts to improve accuracy over time through continuous learning from detected events without requiring human expertise.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The clustering algorithm acts as an intermediary between raw event data and security rules, automatically processing and organizing events into meaningful patterns that translate to accurate security configurations without human intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If automated rule generation is implemented, then deployment speed is improved, but system complexity increases

Engineering Contradiction:
Improvedeployment speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent replaces manual mechanical configuration processes with automated machine learning-based rule generation, significantly increasing deployment speed. The system substitutes human expertise with algorithmic processing that operates continuously and scales efficiently.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20260012473A1Techniques for operating a computer network security system in a cloud computing environment
Publication Date: 2026.01.08 RAPID7 INC
  • US20260012473A1 patent drawing
  • US20260012473A1 patent drawing
  • US20260012473A1 patent drawing

AI summary

Machine learning techniques for updating a configuration of a computer network security system operating in a cloud computing environment. The techniques include obtaining a plurality of datasets containing information about a respective plurality of events detected by the computer network security system in the cloud computing environment; generating, using at least one trained ML model, a plurality of signatures representing the plurality of events, the generating comprising processing the plurality of datasets using the at least one trained ML model to obtain the plurality of signatures; clustering the plurality of signatures to obtain signature clusters representing clusters of events in the plurality of events; identifying a particular event cluster from among the clusters of events; and updating the configuration of the computer network security system based on characteristics of events in the identified particular event cluster.