Enterprise Network Threat Detection with Tiered ML Review

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack effective methods to manage and detect intermediate-level security threats in enterprise networks, requiring manual intervention and lacking automated tools for efficient threat characterization and prioritization.

Innovation Solution

An ensemble of machine learning techniques is used to categorize code as safe, unsafe, or intermediate, with human-readable analysis for unclear cases, and a local agent monitors endpoint activities to provide a compact data stream to a central facility for dynamic threat management, incorporating human intervention where necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated detection techniques are used to identify all threats, then productivity is improved, but measurement precision deteriorates for intermediate-level threats

Engineering Contradiction:
Improvethreat detection speedVSAvoidthreat characterization accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent segments threats into three categories: safe, unsafe, and intermediate. Automated detection techniques efficiently process safe and unsafe threats, while intermediate threats are flagged for human review. This segmentation allows the system to maintain high productivity for clear-cut cases while preserving measurement precision for ambiguous cases through human expertise.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary human review process for intermediate-level threats that automated systems cannot confidently classify. This intermediary step acts as a bridge between automated detection and final threat determination, ensuring that cases where automated precision is insufficient receive human expertise without compromising overall system productivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If manual intervention is used for all threat analysis, then measurement precision is improved, but productivity deteriorates

Engineering Contradiction:
Improvethreat characterization accuracyVSAvoidthreat detection speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent applies partial manual intervention only where necessary - specifically for intermediate-level threats that automated systems cannot confidently classify. The majority of threats (safe and unsafe categories) are processed automatically without human intervention, maintaining high productivity while applying human expertise precisely where it adds value for measurement precision.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The automated detection system serves itself by confidently classifying clear-cut threats without human intervention, freeing human analysts to focus exclusively on intermediate cases. This self-service capability of the automated system for unambiguous cases maximizes productivity while preserving measurement precision for complex cases through targeted human review.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If comprehensive monitoring of all endpoint activities is implemented, then measurement precision is improved, but device complexity and loss of information increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts and transmits only the essential elements of endpoint activity data needed for threat detection to the cloud-based analysis system. By taking out only the critical data elements rather than monitoring and storing all activities locally, the endpoint agent maintains simplicity while the cloud system achieves comprehensive analysis precision through access to relevant data without the complexity of processing everything locally.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent moves the complex analysis function from the endpoint dimension to the cloud dimension. The endpoint agent performs simple data collection and transmission, while the cloud-based system performs comprehensive threat analysis. This dimensional shift allows measurement precision to be improved through cloud-based comprehensive analysis without increasing endpoint device complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Measurement precision

If cloud-based analysis is used for all threats, then measurement precision is improved, but loss of time increases due to data transmission

Engineering Contradiction:
Improvethreat characterization accuracyVSAvoiddata transmission delay
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements local quality by enabling endpoint agents to perform immediate preliminary assessment and filtering of threats. Clear-cut threats are handled locally with rapid response, while only intermediate cases requiring cloud-based comprehensive analysis are transmitted. This local quality approach improves measurement precision for transmitted cases through cloud analysis while minimizing time loss by keeping simple cases local.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent performs preliminary threat assessment and categorization at the endpoint before cloud transmission. By conducting preliminary action to identify and filter intermediate cases, the system reduces the volume of data requiring cloud transmission and accelerates the overall detection process. Only cases needing cloud-based precision are transmitted, minimizing time loss while maintaining measurement precision where needed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12361358B2Enterprise network threat detection
Publication Date: 2025.07.15 SOPHOS LTD
  • US12361358B2 patent drawing
  • US12361358B2 patent drawing
  • US12361358B2 patent drawing

AI summary

In a threat management platform, a number of endpoints log events in an event data recorder. A local agent filters this data and feeds a filtered data stream to a central threat management facility. The central threat management facility can locally or globally tune filtering by local agents based on the current data stream, and can query local event data recorders for additional information where necessary or helpful in threat detection or forensic analysis. The central threat management facility also stores and deploys a number of security tools such as a web-based user interface supported by machine learning models to identify potential threats requiring human intervention and other models to provide human-readable context for evaluating potential threats.