Dynamic Policy Injection for Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems face challenges in effectively managing and visualizing vast amounts of security data to detect evolving threats in real-time, as static security rules fail to keep pace with dynamic user and application activities, leading to overwhelming alarms and resource constraints.

Innovation Solution

A threat intelligence platform that employs dynamic policies for real-time threat detection and analytics, providing a consolidated view of active threats and user activity, and enables adaptive authorization, content inspection, and enforcement through a policy bus for dynamic policy injection and communication across multiple enforcement entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static security rules are used, then device complexity is reduced, but adaptability to evolving threats deteriorates

Engineering Contradiction:
Improveadaptability to evolving threatsVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic security policies that automatically adapt to evolving threats based on real-time user behavior patterns and contextual information. The system transitions from static rules to dynamic decision-making where policies are continuously updated based on monitored user activities, device characteristics, and threat intelligence, enabling the security system to respond to new threats without manual rule updates.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs self-learning and self-adjustment by automatically analyzing user behavior patterns, device fingerprints, and security events to generate and refine security policies. The machine learning components enable the system to autonomously identify anomalies and update access control decisions without requiring continuous manual intervention, reducing operational complexity while improving adaptability.

Inventive Principle:
Principle #25Self-service

2Reliability

If real-time threat detection is implemented, then security effectiveness is improved, but data processing volume increases

Engineering Contradiction:
Improvesecurity effectivenessVSAvoiddata processing volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts and focuses analysis on critical security-relevant data elements such as user behavior patterns, device fingerprints, and contextual metadata, rather than processing all raw data uniformly. By selectively extracting only the necessary features for threat detection, the system maintains high security effectiveness while reducing the overall data processing burden through intelligent data filtering and feature selection.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary data processing and feature extraction at data collection points, pre-computing security-relevant attributes and filtering out irrelevant data before it enters the main analysis pipeline. This preliminary action reduces the volume of data requiring real-time processing while preserving the essential information needed for effective threat detection.

Inventive Principle:
Principle #10Preliminary action

3Difficulty of detecting and measuring

If comprehensive security monitoring is deployed, then threat detection capability is improved, but operational burden on security personnel increases

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidoperational burden on security personnel
Core Design Contradiction:
Difficulty of detecting and measuringVSEase of operation

Solution Approach 1:

The system implements continuous feedback loops where security events, user behaviors, and threat intelligence automatically trigger policy updates and alert security personnel only when anomalies are detected. The machine learning models continuously learn from security outcomes, automatically adjusting detection thresholds and priorities, which reduces the operational burden by eliminating routine manual analysis while maintaining high threat detection capability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces machine learning models and automated policy engines as intermediaries between raw security data and human operators. These intermediaries perform complex analysis, pattern recognition, and initial response actions, transforming the operational burden from manual data analysis to supervised review of automated decisions, thereby reducing the direct operational burden on security personnel.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If dynamic policies are implemented, then adaptability to user activity is improved, but system complexity increases

Engineering Contradiction:
Improveadaptability to user activityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the dynamic policy system into modular components including user behavior analysis modules, device fingerprinting modules, contextual analysis modules, and policy enforcement modules. Each module handles specific aspects of adaptability independently, making the overall complex system more manageable and easier to deploy. This segmentation allows each component to be optimized and maintained separately while contributing to the overall adaptability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11516255B2Dynamic policy injection and access visualization for threat detection
Publication Date: 2022.11.29 ORACLE INT CORP
  • US11516255B2 patent drawing
  • US11516255B2 patent drawing
  • US11516255B2 patent drawing

AI summary

The present disclosure relates generally to threat detection, and more particularly, to techniques for analyzing security events using dynamic policies and displaying a consolidated view of active threats and user activity including the dynamic policies being triggered by the active threats and user activity. Some aspects are directed to the concept of a policy bus for injecting and communicating the dynamic policies to multiple enforcement entities and the ability of the entities to respond to the policies dynamically. Other aspects are directed providing a consolidated view of active threat categories, a count of policies being triggered for each threat category, and associated trends. Yet other aspects are directed to providing a consolidated view of users, applications being accessed by users, and the access policies, if any, implicated by the such accesses.