Decision-Tree Security Event Quantification Across Threat Sources

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer security tools lack the ability to effectively leverage information from multiple and disparate sources to mitigate computer security attacks, failing to accurately analyze, quantify risk, generate remediative steps, and prioritize responses.

Innovation Solution

A system utilizing a decision tree to test security objects, linking nodes to security engines for threat parameter determination, including classification, vulnerability assessment, and threat attribute analysis, enabling efficient remediation strategies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security engines are used to analyze security objects from disparate sources, then the comprehensiveness of security analysis is improved, but the system complexity increases

Engineering Contradiction:
Improvesecurity analysis comprehensivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides security analysis into multiple specialized security engines, each handling specific types of security objects or analysis tasks. This segmentation allows comprehensive coverage of different security domains while keeping each engine's complexity manageable and focused on specific functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The decision tree structure serves as a universal framework that can route various types of security objects to appropriate security engines. This multi-functional structure enables a single system to handle diverse security analysis tasks through a common organizational mechanism.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If a decision tree structure is implemented to organize security engines, then the ease of operation is improved, but the device complexity increases

Engineering Contradiction:
Improvesecurity object analysis efficiencyVSAvoiddecision tree structure complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The decision tree structure is pre-configured with rules and thresholds that automatically determine which security engines should analyze specific security objects. This preliminary organization eliminates the need for manual routing decisions during operation, improving ease of use while the structure itself manages the complexity.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If security objects are tested through multiple security engines, then the measurement precision of security parameters is improved, but the loss of time increases

Engineering Contradiction:
Improvesecurity parameter accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies partial analysis by routing security objects to only those security engines relevant to their type and risk level, rather than submitting all objects to every engine. This selective approach maintains measurement precision for critical parameters while reducing unnecessary analysis time for lower-risk objects.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system uses feedback mechanisms where initial analysis results from one security engine can influence whether additional engines are activated. This adaptive approach ensures thorough analysis when needed while avoiding redundant processing, balancing precision requirements against time consumption.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12417292B2Quantification of security events using behavioral, analytical, and threat intelligence attributes
Publication Date: 2025.09.16 QUALYS
  • US12417292B2 patent drawing
  • US12417292B2 patent drawing
  • US12417292B2 patent drawing

AI summary

A system for testing a security object is disclosed. The system comprises processors and memory storing a plurality of security engines and instructions that, when executed by the processors, causes the system to: access a decision tree comprising a first node and a plurality of second nodes; link a first leaf node of the decision tree with a first security engine; link a second leaf node of the decision tree with a second security engine; receive a security object comprising a digital asset that is attackable using one or more attack execution operations; and test the security object using the decision tree to determine a security threat parameter for the security object. The security threat parameter may be used to prioritize one or more remediation steps for mitigating against the one or more attack execution operations associated with the digital asset.