Dynamic Threshold Disposition Scoring for Malicious Event Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional security systems fail to accurately and efficiently identify malicious computing events, especially when new security information becomes available, and often use standardized metrics that do not cater to individual enterprise needs.
Innovation Solution
A method and system that determine initial and updated disposition scores for computing events based on current and new security information, adjust threshold disposition scores to optimize malware detection, and include modules for scoring, classification, calculation, and security protection to tailor security services to specific enterprise requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional security systems use standard threshold disposition scores for malware classification, then the system operates with simple and consistent rules, but the accuracy of malicious computing event detection is insufficient
Solution Approach 1:
The patent implements dynamic threshold disposition scores that automatically adjust based on enterprise-specific security needs and event characteristics. The system moves from static, standardized thresholds to dynamic, adaptive thresholds that are tailored to each enterprise's risk profile and security requirements, thereby improving detection accuracy without requiring overly complex manual configuration.
Solution Approach 2:
The system changes the parameter of threshold disposition scores from fixed standard values to variable values that adapt to different enterprises and computing events. By modifying this key parameter dynamically, the system achieves higher detection accuracy while maintaining operational simplicity through automated adjustment mechanisms.
2Reliability
If traditional security systems classify computing events using fixed threshold disposition scores, then the classification process is efficient and fast, but the ability to accurately identify malicious events when new security information becomes available is limited
Solution Approach 1:
The patent implements a feedback mechanism where the system continuously monitors computing events, evaluates them against threshold disposition scores, and uses the outcomes to refine and adjust future classifications. When new security information becomes available, the system feeds this information back into the classification process, improving detection reliability while maintaining efficient response times through automated iterative improvement.
Solution Approach 2:
The system performs preliminary classification of computing events using initial threshold disposition scores to enable rapid response to potential threats. This preliminary action allows efficient immediate classification while preserving the ability to re-evaluate and refine classifications as additional security information becomes available, thus balancing speed and reliability.
3Adaptability or versatility
If traditional security systems apply uniform classification criteria across all enterprises, then the system is easy to operate and maintain, but it cannot be tailored to meet the specific security needs of individual enterprises
Solution Approach 1:
The patent applies local quality by tailoring threshold disposition scores and classification criteria to the specific needs, risk profiles, and security requirements of individual enterprises. Rather than applying a uniform standard everywhere, the system customizes parameters locally for each enterprise while maintaining a consistent overall framework, thus achieving adaptability without sacrificing operational simplicity.
Solution Approach 2:
The system performs preliminary configuration and customization of security parameters for each enterprise before deployment, establishing enterprise-specific threshold disposition scores and classification criteria in advance. This preliminary action enables the system to operate with customized settings automatically, providing adaptability to individual enterprise needs while maintaining ease of operation during actual security monitoring.
Data Source
AI summary
The disclosed computer-implemented method for detecting malicious computing events may include (i) determining, for multiple computing events detected within an enterprise, an initial disposition score for each computing event based on currently-available security information, (ii) determining an initial classification of each computing event as malicious or non-malicious by comparing the initial disposition score of each computing event with a threshold disposition score, (iii) for each computing event, determining (a) an updated disposition score based on new security information (b) an updated classification, (iv) calculating a degree to which the threshold disposition score correctly identifies malicious computing events by determining a frequency with which the initial classification of each computing event matches the updated classification of the computing event, and (v) adjusting the threshold disposition score based on the degree to which the threshold disposition score correctly identifies malicious computing events.


