Dynamic Threshold Disposition Scoring for Malicious Event Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security systems fail to accurately and efficiently identify malicious computing events, especially when new security information becomes available, and often use standardized metrics that do not cater to individual enterprise needs.

Innovation Solution

A method and system that determine initial and updated disposition scores for computing events based on current and new security information, adjust threshold disposition scores to optimize malware detection, and include modules for scoring, classification, calculation, and security protection to tailor security services to specific enterprise requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional security systems use standard threshold disposition scores for malware classification, then the system operates with simple and consistent rules, but the accuracy of malicious computing event detection is insufficient

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements dynamic threshold disposition scores that automatically adjust based on enterprise-specific security needs and event characteristics. The system moves from static, standardized thresholds to dynamic, adaptive thresholds that are tailored to each enterprise's risk profile and security requirements, thereby improving detection accuracy without requiring overly complex manual configuration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of threshold disposition scores from fixed standard values to variable values that adapt to different enterprises and computing events. By modifying this key parameter dynamically, the system achieves higher detection accuracy while maintaining operational simplicity through automated adjustment mechanisms.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If traditional security systems classify computing events using fixed threshold disposition scores, then the classification process is efficient and fast, but the ability to accurately identify malicious events when new security information becomes available is limited

Engineering Contradiction:
Improvedetection reliabilityVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a feedback mechanism where the system continuously monitors computing events, evaluates them against threshold disposition scores, and uses the outcomes to refine and adjust future classifications. When new security information becomes available, the system feeds this information back into the classification process, improving detection reliability while maintaining efficient response times through automated iterative improvement.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary classification of computing events using initial threshold disposition scores to enable rapid response to potential threats. This preliminary action allows efficient immediate classification while preserving the ability to re-evaluate and refine classifications as additional security information becomes available, thus balancing speed and reliability.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If traditional security systems apply uniform classification criteria across all enterprises, then the system is easy to operate and maintain, but it cannot be tailored to meet the specific security needs of individual enterprises

Engineering Contradiction:
Improvecustomization capabilityVSAvoidoperational simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent applies local quality by tailoring threshold disposition scores and classification criteria to the specific needs, risk profiles, and security requirements of individual enterprises. Rather than applying a uniform standard everywhere, the system customizes parameters locally for each enterprise while maintaining a consistent overall framework, thus achieving adaptability without sacrificing operational simplicity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs preliminary configuration and customization of security parameters for each enterprise before deployment, establishing enterprise-specific threshold disposition scores and classification criteria in advance. This preliminary action enables the system to operate with customized settings automatically, providing adaptability to individual enterprise needs while maintaining ease of operation during actual security monitoring.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10320818B2Systems and methods for detecting malicious computing events
Publication Date: 2019.06.11 CA TECH INC
  • US10320818B2 patent drawing
  • US10320818B2 patent drawing
  • US10320818B2 patent drawing

AI summary

The disclosed computer-implemented method for detecting malicious computing events may include (i) determining, for multiple computing events detected within an enterprise, an initial disposition score for each computing event based on currently-available security information, (ii) determining an initial classification of each computing event as malicious or non-malicious by comparing the initial disposition score of each computing event with a threshold disposition score, (iii) for each computing event, determining (a) an updated disposition score based on new security information (b) an updated classification, (iv) calculating a degree to which the threshold disposition score correctly identifies malicious computing events by determining a frequency with which the initial classification of each computing event matches the updated classification of the computing event, and (v) adjusting the threshold disposition score based on the degree to which the threshold disposition score correctly identifies malicious computing events.