Dynamic Decision-Making Threshold for Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for detecting malicious events in communication networks do not consider use-case specific characteristics of different devices, leading to high costs due to manual threshold settings that result in false positives and false negatives, and do not utilize risk and cost values for decision-making.

Innovation Solution

A device and method for dynamically determining a decision-making threshold by obtaining environment threat data, computing anomaly predictions, and adapting the threshold based on target metric scores that include cost values and performance metrics such as precision, recall, and F1 score, to optimize anomaly detection for different devices and network topologies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a pre-defined default threshold is used for anomaly detection, then the system is simple to operate, but it results in high false positive and false negative rates across different device types

Engineering Contradiction:
Improvethreshold configurationVSAvoidthreat detection accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent implements dynamic threshold adjustment by continuously learning from labeled threat events and metric scores. The threshold is no longer static but adapts over time based on environmental feedback, allowing the system to maintain high detection accuracy across different device types without manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs self-optimization by automatically adjusting thresholds based on its own performance metrics and labeled data. Through the feedback loop involving metric score computation and threshold adaptation, the system improves its own detection accuracy without external intervention, reducing false positives and false negatives autonomously.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If manual threshold setting is performed for different device types, then detection accuracy improves, but operational complexity and costs increase significantly

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidthreshold management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a universal threshold adaptation mechanism that works across all device types (handheld devices, IoT devices, etc.) through a common learning framework. Instead of requiring separate manual configurations for each device type, the system uses a unified approach that automatically adapts to different device characteristics through metric score computation and feedback-based threshold adjustment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements a feedback loop where metric scores are computed based on labeled threat events and current thresholds, then used to adapt and optimize thresholds for future detections. This continuous feedback mechanism eliminates the need for complex manual threshold management while maintaining high detection accuracy across diverse device types.

Inventive Principle:
Principle #23Feedback

3Reliability

If a low threshold is set to reduce false negatives, then more threats are detected, but false positive rate increases leading to higher operational costs

Engineering Contradiction:
Improvethreat detection completenessVSAvoidoperational cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent dynamically changes the threshold parameter based on computed metric scores and labeled threat events. Instead of using a fixed low threshold that generates many false positives, the system adjusts the threshold parameter adaptively, finding the optimal balance between detecting all threats and minimizing false positives, thereby reducing operational costs while maintaining detection completeness.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

Through the feedback mechanism, the system learns from the consequences of threshold settings. When false positives occur, the metric scores reflect this, and the threshold adaptation process adjusts future thresholds to reduce such occurrences. This feedback-driven optimization reduces operational costs by minimizing unnecessary responses to false alarms while maintaining reliable threat detection.

Inventive Principle:
Principle #23Feedback

4Loss of energy

If a high threshold is set to reduce false positives, then operational costs decrease, but false negative rate increases compromising security

Engineering Contradiction:
Improveoperational costVSAvoidthreat detection completeness
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The system dynamically adjusts the threshold parameter upward or downward based on computed metric scores and security requirements. Instead of using a permanently high threshold that would miss threats, the system adapts the parameter to maintain security reliability while controlling operational costs, ensuring that the threshold is high enough to reduce false positives but low enough to detect actual threats.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The feedback loop ensures that when false negatives occur (threats missed due to high threshold), the metric scores capture this performance degradation. The threshold adaptation process then adjusts future thresholds to prevent such occurrences, maintaining security reliability while still benefiting from reduced false positives. This feedback mechanism prevents the system from compromising security in pursuit of cost reduction.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240289458A1Method and Device Relating to Decision-Making Threshold
Publication Date: 2024.08.29 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20240289458A1 patent drawing
  • US20240289458A1 patent drawing
  • US20240289458A1 patent drawing

AI summary

A method for determining a Decision-Making Threshold, DMT, comprising obtaining environment threat data (104) comprising one or more events, each event associated with a label providing an indication of a threat event. The method further comprises obtaining the target metric scores (204); computing anomaly predictions relating to if the events are malicious or not and comparing the anomaly predictions with a DMT to obtain malicious threat predictions. The method further comprises computing current metric scores (303) for the environment threat data using at least the labels and the malicious threat predictions for the environment threat data; comparing the computed current metric scores with the target metric scores and adapting the DMT depending on if the computed metric scores are within a range of the target metric scores or not.