Dynamic Data Manipulation Detection via ML Rule Adaptation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems face challenges in accurately detecting data manipulation attacks within computer networks, leading to high false-positive and false-negative threat detections, which degrade system performance and compromise information security.
Innovation Solution
The system employs machine learning models to detect data manipulation attacks and dynamically adjusts rules based on user feedback, using a first machine learning model to generate alert vectors and a second model with natural language processing to interpret feedback and modify rule parameters, thereby reducing false detections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional rigid rules or criteria are used to determine data modification, then the system can detect potential threats, but the system produces a large number of false-positive and false-negative threat detections
Solution Approach 1:
The patent applies dynamics by transitioning from static rigid rules to dynamic machine learning models that continuously learn and adapt. The system uses trained machine learning models that can dynamically adjust their detection criteria based on patterns learned from historical data, enabling more accurate differentiation between legitimate data modifications and actual threats while reducing false positives and false negatives.
Solution Approach 2:
The patent implements parameter changes by using machine learning models that can adjust detection parameters and thresholds based on learned patterns. Instead of fixed rule parameters, the system dynamically modifies detection sensitivity and criteria through trained model parameters, allowing optimal balance between detection accuracy and false alarm reduction based on the specific characteristics of the data being monitored.
2Reliability
If the system analyzes data to determine further actions for false-positive threat detections, then the system can verify threats, but system resources are consumed and throughput is limited
Solution Approach 1:
The patent applies preliminary action by pre-training machine learning models on historical data before deployment. The models are prepared in advance with learned patterns and parameters, so when actual data monitoring begins, the system can immediately make accurate assessments without requiring extensive real-time analysis or verification resources. This preliminary training phase shifts computational burden from runtime verification to offline model preparation.
Solution Approach 2:
The system implements self-service through machine learning models that autonomously make detection decisions based on learned patterns. Once trained, the models independently evaluate data modifications and determine whether they represent threats without requiring manual analysis or additional verification steps, thereby reducing resource consumption and maintaining high throughput while ensuring reliable threat detection.
3Device complexity
If conventional rule-based systems are used, then the system can operate with simple structure, but the system cannot accurately distinguish between legitimate modifications and malicious attacks
Solution Approach 1:
The patent applies mechanics substitution by replacing the mechanical rule-based detection system with a machine learning-based intelligent system. Instead of relying on manually configured rigid rules, the system uses trained machine learning models that automatically learn detection patterns from data, substituting mechanical rule evaluation with intelligent pattern recognition that achieves superior detection accuracy while maintaining operational simplicity.
Solution Approach 2:
The patent implements copying by using machine learning models that replicate human expert decision-making patterns through training on historical data. The models learn to copy the judgment and analysis capabilities of security experts, enabling automated detection systems to achieve expert-level accuracy without requiring complex manual rule configurations or human intervention in the detection process.
Data Source
AI summary
A data manipulation detection device that includes an alert engine configured to receive data from a data source, apply a set of rules for a threat model to the data using a first machine learning model, and to obtain an alert vector in response to applying the set of rules to the data. The device further includes an alert feedback engine configured to receive alert feedback that includes text comments for the alert vector. The device further includes a natural language processing (NLP) training engine configured to identify the text comments for the alert status and identify keywords within the text comments associated with a rule parameter value for a rule. The NLP training engine is further configured to determine a new rule parameter value based on the identified keywords and modify a rule parameter value for the rule based on the new rule parameter value.


