Endpoint Security Action Prediction Without Threat-Level Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing endpoint security solutions, such as rule-based and AI-driven systems, often require manual analysis and have delays in addressing emerging security issues, and lack efficiency in determining appropriate remedial actions.
Innovation Solution
A multi-label classification data model that directly predicts security actions based on detected events, trained with security event patterns and corresponding actions, enabling real-time protection of endpoints.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If rule-based strategies are used to determine security responses, then security issues can be addressed with standardized procedures, but manual analysis and rule creation are required causing delays in fixing emerging security issues
Solution Approach 1:
The system enables security endpoints to automatically determine and execute remedial actions through the machine learning model without requiring manual analysis by security providers. The model independently analyzes security events, predicts appropriate actions, and implements them, eliminating the time-consuming manual rule creation and analysis process while maintaining reliable standardized responses
Solution Approach 2:
The patent replaces the mechanical process of manual rule-based analysis with an automated machine learning system. The ML model substitutes human analysts and manual rule creation processes, using trained patterns to automatically determine security responses, thereby eliminating delays associated with manual intervention while preserving standardized security procedures
2Measurement precision
If AI models are used to identify threats by classifying events as threats or anomalies, then threat detection capability is improved, but additional techniques are still needed to determine appropriate remedial actions
Solution Approach 1:
The patent combines threat detection and remedial action determination into a single integrated machine learning model. Instead of using separate AI models for detection and separate rule-based systems for response determination, the invention merges these functions into one unified model that directly predicts appropriate remedial actions from security events, thereby maintaining high detection accuracy while reducing overall system complexity
Solution Approach 2:
The machine learning model serves multiple functions simultaneously: it detects threats, classifies security events, and determines appropriate remedial actions all in one process. This multi-functional approach eliminates the need for additional separate techniques to determine remedial actions, reducing complexity while maintaining precise threat identification capabilities
3Adaptability or versatility
If manual analysis is performed to determine security responses, then customized security strategies can be developed, but the process requires numerous manual steps and delays response time
Solution Approach 1:
The system automatically analyzes security events and generates customized security responses without requiring manual intervention. The machine learning model independently determines appropriate remedial actions based on the specific security events detected, eliminating numerous manual steps while maintaining the ability to develop customized security strategies adapted to each situation
Solution Approach 2:
The machine learning model is pre-trained with extensive security event data and corresponding remedial actions, enabling it to automatically determine customized security strategies without manual analysis. The preliminary training phase captures diverse security scenarios and responses, allowing the system to quickly adapt to new threats and generate customized strategies automatically when security events occur
Data Source
Figure 1~2
Figure 3
Figure 4~5
AI summary
A set of endpoint security events that reflect known security issues is defined and collected. A corresponding set of endpoint security actions to protect the endpoints is defined and implemented. Machine learning is used to build a data model to reflect the relation between endpoint security events and endpoint security actions. The data model is able to predict the security actions directly from the security events, without the intermediate step of determining a threat level. An endpoint application is developed to use the data model directly and apply the security actions whenever security events occur.