Context-Aware Malicious Activity Warning System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in distinguishing between benign and malicious activity on computer networks, as granting access rights for benign activities can inadvertently allow malicious activities, and current methods require manual effort to review indicators, leading to inefficiencies in detecting and evaluating potential malicious behavior.

Innovation Solution

A context-aware warning system that automatically collects and analyzes indicators, generates alerts, and provides an interactive user interface for auditors, allowing for efficient evaluation and prioritization of alerts through automated scoring and dynamic re-grouping, filtering, and updating based on past findings and auditor feedback.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If access rights are granted for benign activity, then benign activity can be performed, but malicious activity becomes possible

Engineering Contradiction:
Improveaccess rights for benign activityVSAvoidmalicious activity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system dynamically changes parameters (risk scores, alert thresholds) based on contextual analysis of entity behavior, allowing access rights to be adjusted in real-time without completely restricting benign activity

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements feedback loops where auditor responses to alerts refine future risk assessments, allowing the system to learn from past decisions and improve differentiation between benign and malicious activity over time

Inventive Principle:
Principle #23Feedback

2Measurement precision

If manual review of indicators is performed, then accurate detection of malicious activity is achieved, but time and effort requirements increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidreview time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system introduces an automated scoring mechanism as an intermediary that pre-evaluates indicators and generates prioritized alerts, reducing the manual review burden while maintaining detection accuracy through contextual analysis

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system applies partial automation by focusing manual review efforts only on high-priority alerts that exceed dynamically adjusted thresholds, rather than requiring review of all indicators

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If comprehensive indicators are collected for analysis, then detection accuracy improves, but system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the complex analysis task into distinct components: automated collection of indicators, contextual analysis, scoring mechanisms, and alert generation, allowing each component to be optimized independently

Inventive Principle:
Principle #1Segmentation

4Productivity

If automated scoring and filtering are implemented, then productivity increases, but false positives may increase

Engineering Contradiction:
Improvealert evaluation efficiencyVSAvoidfalse positive rate
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements dynamic threshold adjustment where alert thresholds adapt based on auditor feedback and historical data, allowing the system to maintain high productivity while reducing false positives over time through continuous learning

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11770390B2Context-aware network-based malicious activity warning systems
Publication Date: 2023.09.26 PALANTIR TECHNOLOGIES INC
  • US11770390B2 patent drawing
  • US11770390B2 patent drawing
  • US11770390B2 patent drawing

AI summary

A computer system is configured to generate alerts related to malicious activity on an audited computing system. The computing system is provided with instructions to receive activity information associated with activity of an entity performed in an audited computing network, access contextual information associated with the entity, determine, based on the contextual information, a set of weights associated with the activity information and combine the weight and the entity activity information to generate a risk score. In response to the risk score satisfying a threshold value, the computer system may generate an alert, and, in response to receiving a user input associated with the alert, update the set of weights. In certain embodiments, the updated weights may be used for determining the risk score of future alerts.