Dynamic Risk Score Aggregation for Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large enterprise computer networks face challenges in providing effective security due to the strain on network security systems from continuous growth and diverse user devices, making it difficult to process security alerts and deploy remediation measures efficiently.
Innovation Solution
The implementation of a method for dynamic aggregation of indicators of compromise (IOCs) across multiple categories, where weights are adjusted based on the number of IOCs, allowing for enhanced risk score generation and automated action triggering to improve security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network security systems process all security alerts from diverse user devices in large enterprise networks, then security coverage is improved, but system resources are strained and processing efficiency deteriorates
Solution Approach 1:
The patent segments security alerts into multiple risk categories (e.g., low, medium, high risk) based on indicator characteristics. This segmentation allows the system to process different types of alerts with appropriate priorities, preventing resource exhaustion from processing all alerts uniformly while maintaining comprehensive security coverage through categorized handling.
Solution Approach 2:
The patent dynamically adjusts weightings assigned to different risk categories based on the number of indicators present. When fewer indicators are detected, higher weightings are applied to ensure thorough processing. When many indicators are present, weightings are reduced to prevent system overload. This parameter adjustment resolves the contradiction by adapting processing intensity to current system conditions.
2Measurement precision
If network security systems increase processing depth for each indicator, then detection precision is improved, but processing time increases and productivity decreases
Solution Approach 1:
The patent implements dynamic weighting adjustment where the processing depth and resource allocation for indicators change based on real-time conditions. When the system detects a high volume of indicators, it automatically reduces processing depth for individual indicators to maintain overall productivity. When indicators are few, the system increases processing depth for maximum precision. This dynamic adaptation resolves the contradiction between detection precision and processing speed.
3Reliability
If the system assigns high weights to all indicators, then risk detection sensitivity is improved, but false positives increase and measurement precision deteriorates
Solution Approach 1:
The patent applies different weightings to different risk categories rather than uniform weighting. High-risk indicators receive higher weights than low-risk indicators, creating local quality differentiation. This approach maintains high detection sensitivity for critical threats while reducing false positives by not over-weighting minor or spurious indicators, thus resolving the contradiction between sensitivity and precision.
Solution Approach 2:
The system dynamically adjusts weight parameters based on the number and type of indicators detected. When many indicators are present, the system reduces individual weightings to prevent false positives. When few indicators are detected, the system increases weightings to maintain sensitivity. This parameter adaptation resolves the contradiction by matching weighting intensity to current detection context.
Data Source
AI summary
A method in an illustrative embodiment comprises receiving a plurality of indicators relating to an entity of a computer network, arranging the indicators in a plurality of categories of increasing risk, assigning weights to the indicators in the categories as a function of the number of categories and the number of indicators in each category, generating a risk score for the indicators based at least in part on the assigned weights, and initiating at least one automated action relating to the entity of the computer network based at least in part on the risk score. The risk score generation is configured such that a weighted contribution to the risk score of indicators in a relatively low one of the categories decreases as a number of indicators in a relatively high one of the categories increases. Similarly, a weighted contribution to the risk score of indicators in a relatively low one of the categories increases as a number of indicators in a relatively high one of the categories decreases.


