Dynamic Risk Score Aggregation for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large enterprise computer networks face challenges in providing effective security due to the strain on network security systems from continuous growth and diverse user devices, making it difficult to process security alerts and deploy remediation measures efficiently.

Innovation Solution

The implementation of a method for dynamic aggregation of indicators of compromise (IOCs) across multiple categories, where weights are adjusted based on the number of IOCs, allowing for enhanced risk score generation and automated action triggering to improve security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network security systems process all security alerts from diverse user devices in large enterprise networks, then security coverage is improved, but system resources are strained and processing efficiency deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments security alerts into multiple risk categories (e.g., low, medium, high risk) based on indicator characteristics. This segmentation allows the system to process different types of alerts with appropriate priorities, preventing resource exhaustion from processing all alerts uniformly while maintaining comprehensive security coverage through categorized handling.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent dynamically adjusts weightings assigned to different risk categories based on the number of indicators present. When fewer indicators are detected, higher weightings are applied to ensure thorough processing. When many indicators are present, weightings are reduced to prevent system overload. This parameter adjustment resolves the contradiction by adapting processing intensity to current system conditions.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If network security systems increase processing depth for each indicator, then detection precision is improved, but processing time increases and productivity decreases

Engineering Contradiction:
Improvedetection precisionVSAvoidprocessing speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements dynamic weighting adjustment where the processing depth and resource allocation for indicators change based on real-time conditions. When the system detects a high volume of indicators, it automatically reduces processing depth for individual indicators to maintain overall productivity. When indicators are few, the system increases processing depth for maximum precision. This dynamic adaptation resolves the contradiction between detection precision and processing speed.

Inventive Principle:
Principle #15Dynamics

3Reliability

If the system assigns high weights to all indicators, then risk detection sensitivity is improved, but false positives increase and measurement precision deteriorates

Engineering Contradiction:
Improverisk detection sensitivityVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent applies different weightings to different risk categories rather than uniform weighting. High-risk indicators receive higher weights than low-risk indicators, creating local quality differentiation. This approach maintains high detection sensitivity for critical threats while reducing false positives by not over-weighting minor or spurious indicators, thus resolving the contradiction between sensitivity and precision.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts weight parameters based on the number and type of indicators detected. When many indicators are present, the system reduces individual weightings to prevent false positives. When few indicators are detected, the system increases weightings to maintain sensitivity. This parameter adaptation resolves the contradiction by matching weighting intensity to current detection context.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11151246B2Risk score generation with dynamic aggregation of indicators of compromise across multiple categories
Publication Date: 2021.10.19 EMC IP HLDG CO LLC
  • US11151246B2 patent drawing
  • US11151246B2 patent drawing
  • US11151246B2 patent drawing

AI summary

A method in an illustrative embodiment comprises receiving a plurality of indicators relating to an entity of a computer network, arranging the indicators in a plurality of categories of increasing risk, assigning weights to the indicators in the categories as a function of the number of categories and the number of indicators in each category, generating a risk score for the indicators based at least in part on the assigned weights, and initiating at least one automated action relating to the entity of the computer network based at least in part on the risk score. The risk score generation is configured such that a weighted contribution to the risk score of indicators in a relatively low one of the categories decreases as a number of indicators in a relatively high one of the categories increases. Similarly, a weighted contribution to the risk score of indicators in a relatively low one of the categories increases as a number of indicators in a relatively high one of the categories decreases.