Dynamic Data Manipulation Detection via ML Rule Adaptation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems face challenges in accurately detecting data manipulation attacks within computer networks, leading to high false-positive and false-negative threat detections, which degrade system performance and compromise information security.

Innovation Solution

The system employs machine learning models to detect data manipulation attacks and dynamically adjusts rules based on user feedback, using a first machine learning model to generate alert vectors and a second model with natural language processing to interpret feedback and modify rule parameters, thereby reducing false detections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional rigid rules or criteria are used to determine data modification, then the system can detect potential threats, but the system produces a large number of false-positive and false-negative threat detections

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidfalse-positive and false-negative rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent applies dynamics by transitioning from static rigid rules to dynamic machine learning models that continuously learn and adapt. The system uses trained machine learning models that can dynamically adjust their detection criteria based on patterns learned from historical data, enabling more accurate differentiation between legitimate data modifications and actual threats while reducing false positives and false negatives.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements parameter changes by using machine learning models that can adjust detection parameters and thresholds based on learned patterns. Instead of fixed rule parameters, the system dynamically modifies detection sensitivity and criteria through trained model parameters, allowing optimal balance between detection accuracy and false alarm reduction based on the specific characteristics of the data being monitored.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If the system analyzes data to determine further actions for false-positive threat detections, then the system can verify threats, but system resources are consumed and throughput is limited

Engineering Contradiction:
Improvethreat verification accuracyVSAvoidsystem throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-training machine learning models on historical data before deployment. The models are prepared in advance with learned patterns and parameters, so when actual data monitoring begins, the system can immediately make accurate assessments without requiring extensive real-time analysis or verification resources. This preliminary training phase shifts computational burden from runtime verification to offline model preparation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service through machine learning models that autonomously make detection decisions based on learned patterns. Once trained, the models independently evaluate data modifications and determine whether they represent threats without requiring manual analysis or additional verification steps, thereby reducing resource consumption and maintaining high throughput while ensuring reliable threat detection.

Inventive Principle:
Principle #25Self-service

3Device complexity

If conventional rule-based systems are used, then the system can operate with simple structure, but the system cannot accurately distinguish between legitimate modifications and malicious attacks

Engineering Contradiction:
Improvedetection system structureVSAvoidattack detection accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent applies mechanics substitution by replacing the mechanical rule-based detection system with a machine learning-based intelligent system. Instead of relying on manually configured rigid rules, the system uses trained machine learning models that automatically learn detection patterns from data, substituting mechanical rule evaluation with intelligent pattern recognition that achieves superior detection accuracy while maintaining operational simplicity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent implements copying by using machine learning models that replicate human expert decision-making patterns through training on historical data. The models learn to copy the judgment and analysis capabilities of security experts, enabling automated detection systems to achieve expert-level accuracy without requiring complex manual rule configurations or human intervention in the detection process.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11528296B2Unauthorized data manipulation detection
Publication Date: 2022.12.13 BANK OF AMERICA CORP
  • US11528296B2 patent drawing
  • US11528296B2 patent drawing
  • US11528296B2 patent drawing

AI summary

A data manipulation detection device that includes an alert engine configured to receive data from a data source, apply a set of rules for a threat model to the data using a first machine learning model, and to obtain an alert vector in response to applying the set of rules to the data. The device further includes an alert feedback engine configured to receive alert feedback that includes text comments for the alert vector. The device further includes a natural language processing (NLP) training engine configured to identify the text comments for the alert status and identify keywords within the text comments associated with a rule parameter value for a rule. The NLP training engine is further configured to determine a new rule parameter value based on the identified keywords and modify a rule parameter value for the rule based on the new rule parameter value.