Custom Predictive Security Models for Enterprise Network Adaptation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security analytics solutions face challenges in adapting to variances within a population at scale, requiring human expertise for offline machine learning, and lack user-friendly interfaces for customizing online predictive models without data science expertise.

Innovation Solution

A system that allows data scientists to define and deploy custom predictive security models using familiar data science tools, enabling online machine learning without software engineering expertise, and provides a user interface for combining native and custom models to create machine learning use cases, leveraging Predictive Model Markup Language (PMML) for model logic and data aggregation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If offline machine learning is used with manual model training by data scientists, then model accuracy and customization can be achieved, but the system becomes difficult to adapt to population variances at scale and requires significant human expertise

Engineering Contradiction:
Improvemodel accuracyVSAvoidadaptability to population variances
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system segments the population into distinct groups (e.g., employees by department, location, or role) and trains separate predictive models for each segment. This allows the system to capture population variances through group-specific models while maintaining overall system accuracy. Each segment can be modeled independently, enabling the system to adapt to different behavioral patterns across the population.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If on-line machine learning is used for automatic model training, then the system can automatically adapt to population variances, but it becomes more difficult for end users to create customized models without data science expertise

Engineering Contradiction:
Improveautomatic adaptation to population variancesVSAvoidease of model customization
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system introduces a visual model builder interface as an intermediary between the user and the complex on-line machine learning algorithms. Users can define their custom models through intuitive visual elements (drag-and-drop components, parameter sliders) rather than programming or complex configuration. The system translates these visual definitions into executable on-line learning models, making advanced functionality accessible to non-experts while maintaining automatic adaptation capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If custom predictive models are deployed without a standardized interface, then model flexibility is maintained, but the deployment process becomes complex and time-consuming requiring software engineering expertise

Engineering Contradiction:
Improvemodel flexibilityVSAvoiddeployment time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system provides pre-built model templates and predefined data aggregation logic that are prepared in advance. Users can select from template models (e.g., anomaly detection, classification, regression) and customize them by simply providing their specific parameters and data sources, rather than building models from scratch. This preliminary preparation of common patterns and structures significantly reduces deployment time while maintaining flexibility for custom applications.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11699116B2System and method for custom security predictive methods
Publication Date: 2023.07.11 INTERSET SOFTWARE
  • US11699116B2 patent drawing
  • US11699116B2 patent drawing
  • US11699116B2 patent drawing

AI summary

A system and method is described for providing custom predictive models for detecting electronic security threats within an enterprise computer network. The custom models may be defined in a declarative language. The custom models, along with native models, may be combined together to provide custom machine learning (ML) use cases.