Endpoint Security Action Prediction Without Threat-Level Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing endpoint security solutions, such as rule-based and AI-driven systems, often require manual analysis and have delays in addressing emerging security issues, and lack efficiency in determining appropriate remedial actions.

Innovation Solution

A multi-label classification data model that directly predicts security actions based on detected events, trained with security event patterns and corresponding actions, enabling real-time protection of endpoints.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If rule-based strategies are used to determine security responses, then security issues can be addressed with standardized procedures, but manual analysis and rule creation are required causing delays in fixing emerging security issues

Engineering Contradiction:
Improvestandardization of security responseVSAvoiddelay in fixing emerging security issues
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables security endpoints to automatically determine and execute remedial actions through the machine learning model without requiring manual analysis by security providers. The model independently analyzes security events, predicts appropriate actions, and implements them, eliminating the time-consuming manual rule creation and analysis process while maintaining reliable standardized responses

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical process of manual rule-based analysis with an automated machine learning system. The ML model substitutes human analysts and manual rule creation processes, using trained patterns to automatically determine security responses, thereby eliminating delays associated with manual intervention while preserving standardized security procedures

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If AI models are used to identify threats by classifying events as threats or anomalies, then threat detection capability is improved, but additional techniques are still needed to determine appropriate remedial actions

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidcomplexity of determining remedial actions
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent combines threat detection and remedial action determination into a single integrated machine learning model. Instead of using separate AI models for detection and separate rule-based systems for response determination, the invention merges these functions into one unified model that directly predicts appropriate remedial actions from security events, thereby maintaining high detection accuracy while reducing overall system complexity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The machine learning model serves multiple functions simultaneously: it detects threats, classifies security events, and determines appropriate remedial actions all in one process. This multi-functional approach eliminates the need for additional separate techniques to determine remedial actions, reducing complexity while maintaining precise threat identification capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If manual analysis is performed to determine security responses, then customized security strategies can be developed, but the process requires numerous manual steps and delays response time

Engineering Contradiction:
Improvecustomization of security strategyVSAvoidmanual steps required
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system automatically analyzes security events and generates customized security responses without requiring manual intervention. The machine learning model independently determines appropriate remedial actions based on the specific security events detected, eliminating numerous manual steps while maintaining the ability to develop customized security strategies adapted to each situation

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The machine learning model is pre-trained with extensive security event data and corresponding remedial actions, enabling it to automatically determine customized security strategies without manual analysis. The preliminary training phase captures diverse security scenarios and responses, allowing the system to quickly adapt to new threats and generate customized strategies automatically when security events occur

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4091084B1Endpoint security using an action prediction model
Publication Date: 2025.07.09 ABSOLUTE SOFTWARE CORPORATION
  • EP4091084B1 patent drawingFigure 1~2
  • EP4091084B1 patent drawingFigure 3
  • EP4091084B1 patent drawingFigure 4~5

AI summary

A set of endpoint security events that reflect known security issues is defined and collected. A corresponding set of endpoint security actions to protect the endpoints is defined and implemented. Machine learning is used to build a data model to reflect the relation between endpoint security events and endpoint security actions. The data model is able to predict the security actions directly from the security events, without the intermediate step of determining a threat level. An endpoint application is developed to use the data model directly and apply the security actions whenever security events occur.