Enterprise Cybersecurity Defense System Using ML Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity systems fail to effectively detect and mitigate cyberattacks due to their inability to correlate information across multiple domains, leading to compromised operational integrity and potential unauthorized access to data and resources.

Innovation Solution

An Enterprise Cybersecurity Defense System (eCDS) that integrates machine learning-based user behavior and system access models to detect anomalies and implement adaptive mitigation actions, combining identity and access restrictions with predictive detection and active defense mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing detection systems use traditional security measures, then basic security protection is provided, but the ability to correlate information across multiple domains is insufficient leading to missed attacks

Engineering Contradiction:
Improvedetection reliabilityVSAvoidinformation correlation capability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security domains (network security, identity management, access control, endpoint protection) into a unified correlation engine that processes events across all domains simultaneously. This integration enables the system to detect attacks that span multiple domains by correlating events that would be invisible to isolated traditional security systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The correlation engine serves multiple functions simultaneously: it correlates events across domains, detects anomalies, identifies attack patterns, and triggers coordinated responses. This multi-functional approach consolidates what would traditionally require separate systems into a single unified platform that addresses both detection reliability and operational complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If machine learning models are trained on historical data, then detection accuracy improves, but the system cannot detect zero-day attacks or novel attack vectors

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidresponse to novel attacks
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts its detection models through continuous learning from new events and feedback loops. The machine learning components are retrained periodically with fresh data from the correlation engine, enabling the system to detect previously unknown attack patterns while maintaining high precision for known threat types.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms where detected anomalies and confirmed attacks feed back into the training data reservoir. This feedback loop enables the machine learning models to continuously refine their detection accuracy and adapt to evolving attack vectors, resolving the tension between precision for known threats and adaptability for novel attacks.

Inventive Principle:
Principle #23Feedback

3Speed

If real-time correlation of events across multiple domains is implemented, then attack detection speed improves, but computational resources and processing complexity increase

Engineering Contradiction:
Improveattack detection speedVSAvoidcomputational resource consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The correlation engine applies different processing intensities to different event types and domains based on their security significance. High-priority events from critical domains receive intensive real-time correlation analysis, while lower-priority events undergo lighter processing. This localized quality approach maintains fast detection for critical threats while reducing overall computational resource consumption.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs partial correlation analysis for most events using efficient algorithms, reserving intensive computational resources only for high-value events that trigger deeper analysis. This selective processing strategy enables real-time detection speed for the majority of events while controlling total computational resource usage through targeted application of processing intensity.

Inventive Principle:
Principle #16Partial or excessive action

4Loss of time

If automated mitigation actions are implemented, then response time to attacks improves, but false positives may cause unnecessary system disruptions

Engineering Contradiction:
Improveresponse timeVSAvoidmitigation accuracy
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The system performs preliminary analysis and correlation of events before automatically triggering mitigation actions. This preliminary step filters out false positives by cross-referencing multiple data sources and verifying attack patterns, ensuring that automated responses are both timely and accurate, thus reducing unnecessary disruptions while maintaining fast response to genuine threats.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11799893B2Cybersecurity detection and mitigation system using machine learning and advanced data correlation
Publication Date: 2023.10.24 PAYPAL INC
  • US11799893B2 patent drawing
  • US11799893B2 patent drawing
  • US11799893B2 patent drawing

AI summary

Computer system security is often implemented using rules-based systems (e.g., allow traffic to this network port, deny it for those network ports; user A is allowed access to these files, but not those files). In enterprises, multiple such systems may be deployed, but fail to be able to intelligently handle anomalies that may technically be permissible but in reality represents a high possibility that there is an underlying threat or problem. The present disclosure describes the ability to build adaptive models using machine learning techniques that integrate data from multiple different domains (e.g. user identity domain, system device domain) and allow for automated decision making and mitigation actions that can provide greater effectiveness than previous systems allowed.