Remote Endpoint Event Prioritization by Asset-Based Threat Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing endpoint security systems struggle to effectively prioritize security events from remote endpoints due to the sheer volume of events, leading to false positives and critical events being buried in noise, and previous prioritization methods are reactive and unable to adapt to new attack patterns.

Innovation Solution

Prioritize events based on the attributes of the endpoints they originate from, including sensitive data presence, timing, asset value, and threat reputation, using a scoring algorithm that adjusts weights based on user preferences.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all security events are collected and reviewed, then comprehensive security monitoring is achieved, but the volume of events makes analysis impractical and critical events get buried in noise

Engineering Contradiction:
Improvecomprehensive security monitoringVSAvoidevent analysis efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts and prioritizes only the most critical security events from the overwhelming volume of collected events. By calculating risk scores and filtering events based on asset value, sensitivity, and threat level, the system extracts the essential few critical events that require immediate attention, rather than presenting all events equally for review.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary risk scoring mechanism that mediates between event collection and event analysis. This intermediary layer calculates risk scores based on multiple factors (asset value, data sensitivity, threat reputation) and prioritizes events accordingly, serving as a bridge that transforms the raw event stream into a manageable prioritized list for security analysts.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If traditional pattern matching methods are used for event prioritization, then events matching known attack patterns are identified, but the system is reactive and cannot adapt to new attack patterns

Engineering Contradiction:
Improveattack detection accuracyVSAvoidadaptability to new attacks
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent changes the parameters used for event prioritization from static pattern matching to dynamic risk scoring. Instead of relying solely on predefined attack patterns, the system calculates risk scores based on multiple changing parameters including asset value, data sensitivity, threat reputation, and contextual factors. This allows the system to adapt to new attack patterns by evaluating emerging threats against current asset states rather than requiring pre-programmed patterns.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces dynamics into the prioritization system by continuously updating risk scores based on current system state, recent events, and changing threat landscapes. The risk scoring mechanism is dynamic rather than static, allowing the system to adapt to new attack patterns as they emerge by re-evaluating events based on current asset values and threat reputations rather than relying on fixed historical patterns.

Inventive Principle:
Principle #15Dynamics

3Reliability

If event prioritization is based solely on likelihood of security breach, then high-probability events are prioritized, but events with lower probability but higher impact are overlooked

Engineering Contradiction:
Improvesecurity risk assessmentVSAvoidprioritization decision-making
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by differentiating the importance of different events based on their specific context and impact potential. Rather than using a uniform prioritization criterion, the system evaluates each event's local characteristics including the specific asset involved, the sensitivity of data accessed, and the potential business impact. This allows high-impact low-probability events to be prioritized when their local quality indicators (asset criticality, data sensitivity) indicate severe potential consequences.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent performs preliminary action by pre-calculating and storing asset values, data sensitivity levels, and threat reputations before events occur. This preliminary characterization of assets and threats enables the system to quickly prioritize events based on their potential impact rather than requiring complex real-time analysis of breach probability alone. Events are pre-sorted by their potential consequences, ensuring high-impact events are surfaced regardless of their immediate likelihood.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250342257A1Systems and methods for asset based event prioritization for remote endpoint security
Publication Date: 2025.11.06 OPEN TEXT CORPORATION
  • US20250342257A1 patent drawing
  • US20250342257A1 patent drawing
  • US20250342257A1 patent drawing

AI summary

Systems and methods for event threat prioritization are provided. In some embodiments, an event priority engine receives event data detected by event agents executing on devices. The events are prioritized and ranked according to threat scores for events generated according to threat indicators which are fed event data and threat data. In some embodiments, security systems may take the approach of prioritizing events based on the endpoints from which they originate using attributes associated with those endpoints. In this way, events can be prioritized at least in part based on the damage to the enterprise that may occur if those events were to compromise security, not just the likelihood of those events actually resulting in a security breach.