Document Execution Threat Detection With ML-Based Remedial Actions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Document execution environments are vulnerable to malicious threats and activities, necessitating a system to identify and respond to such malicious behavior.

Innovation Solution

A machine learned model is trained on a set of information representing incidents of malicious behavior and remedial actions, enabling it to detect and recommend mitigation strategies within a document execution environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures are used to protect documents in an online execution environment, then basic security is provided, but the system cannot effectively identify and respond to sophisticated malicious behavior

Engineering Contradiction:
Improvesecurity effectivenessVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system employs machine learning models that automatically analyze document execution activity and identify malicious behavior patterns without requiring manual security configuration. The models self-adjust to detect threats based on trained patterns of malicious activity, reducing the need for complex manual security rule management while improving detection reliability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Traditional mechanical security measures (manual rules, static filters) are replaced with intelligent machine learning systems that dynamically analyze behavior patterns. The patent substitutes automated ML-based detection for manual security configuration, enabling the system to adapt to sophisticated threats without proportionally increasing operational complexity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If comprehensive monitoring of document execution activity is implemented to detect malicious behavior, then detection accuracy improves, but system performance and processing speed may deteriorate

Engineering Contradiction:
Improvemalicious behavior detection accuracyVSAvoiddocument processing speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system applies machine learning models selectively to analyze only the portions of document execution activity that exhibit suspicious patterns. Rather than comprehensively analyzing every single action, the ML models identify and focus on anomalous behavior sequences, achieving high detection accuracy while minimizing the performance overhead associated with monitoring all activity

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The machine learning models continuously learn from and adapt to new malicious behavior patterns while maintaining steady detection performance. The system sustains accurate threat detection over time without requiring increasing computational resources, as the models are designed to maintain consistent processing efficiency despite the ongoing nature of threat evolution

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If a machine learning model is trained on extensive malicious behavior data to improve detection capability, then detection reliability improves, but training time and computational resources increase

Engineering Contradiction:
Improvemalicious behavior detection reliabilityVSAvoidmodel training time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary training of machine learning models using historical malicious behavior data before deployment to production environments. By pre-training models with extensive malicious activity patterns in advance, the system achieves high detection reliability from the start of operational use, avoiding the need for time-consuming training during live document processing

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs techniques to optimize model training parameters and architecture to reduce training time while maintaining detection reliability. By adjusting learning rates, batch sizes, and model complexity parameters, the system achieves efficient training that balances comprehensive malicious behavior pattern recognition with acceptable training time and computational resource consumption

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12585764B2Malicious behavior detection and mitigation in a document execution environment
Publication Date: 2026.03.24 DOCUSIGN INC
  • US12585764B2 patent drawing
  • US12585764B2 patent drawing
  • US12585764B2 patent drawing

AI summary

A document execution engine that receives a document for execution within a document execution environment. The document execution engine may also detect activity within the document execution environment associated with the received document, and apply the trained machine learned model to the detected activity to determine if the detected activity is representative of malicious behavior and, in response to determining that the detected activity is representative of malicious behavior, to identify remedial actions that can mitigate the malicious behavior. The document execution engine may also provide, to a device of a user, a recommendation to perform the identified remedial actions.