Enterprise Network Threat Detection with Tiered ML Review
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems lack effective methods to manage and detect intermediate-level security threats in enterprise networks, requiring manual intervention and lacking automated tools for efficient threat characterization and prioritization.
Innovation Solution
An ensemble of machine learning techniques is used to categorize code as safe, unsafe, or intermediate, with human-readable analysis for unclear cases, and a local agent monitors endpoint activities to provide a compact data stream to a central facility for dynamic threat management, incorporating human intervention where necessary.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If automated detection techniques are used to identify all threats, then productivity is improved, but measurement precision deteriorates for intermediate-level threats
Solution Approach 1:
The patent segments threats into three categories: safe, unsafe, and intermediate. Automated detection techniques efficiently process safe and unsafe threats, while intermediate threats are flagged for human review. This segmentation allows the system to maintain high productivity for clear-cut cases while preserving measurement precision for ambiguous cases through human expertise.
Solution Approach 2:
The patent introduces an intermediary human review process for intermediate-level threats that automated systems cannot confidently classify. This intermediary step acts as a bridge between automated detection and final threat determination, ensuring that cases where automated precision is insufficient receive human expertise without compromising overall system productivity.
2Measurement precision
If manual intervention is used for all threat analysis, then measurement precision is improved, but productivity deteriorates
Solution Approach 1:
The patent applies partial manual intervention only where necessary - specifically for intermediate-level threats that automated systems cannot confidently classify. The majority of threats (safe and unsafe categories) are processed automatically without human intervention, maintaining high productivity while applying human expertise precisely where it adds value for measurement precision.
Solution Approach 2:
The automated detection system serves itself by confidently classifying clear-cut threats without human intervention, freeing human analysts to focus exclusively on intermediate cases. This self-service capability of the automated system for unambiguous cases maximizes productivity while preserving measurement precision for complex cases through targeted human review.
3Measurement precision
If comprehensive monitoring of all endpoint activities is implemented, then measurement precision is improved, but device complexity and loss of information increase
Solution Approach 1:
The patent extracts and transmits only the essential elements of endpoint activity data needed for threat detection to the cloud-based analysis system. By taking out only the critical data elements rather than monitoring and storing all activities locally, the endpoint agent maintains simplicity while the cloud system achieves comprehensive analysis precision through access to relevant data without the complexity of processing everything locally.
Solution Approach 2:
The patent moves the complex analysis function from the endpoint dimension to the cloud dimension. The endpoint agent performs simple data collection and transmission, while the cloud-based system performs comprehensive threat analysis. This dimensional shift allows measurement precision to be improved through cloud-based comprehensive analysis without increasing endpoint device complexity.
4Measurement precision
If cloud-based analysis is used for all threats, then measurement precision is improved, but loss of time increases due to data transmission
Solution Approach 1:
The patent implements local quality by enabling endpoint agents to perform immediate preliminary assessment and filtering of threats. Clear-cut threats are handled locally with rapid response, while only intermediate cases requiring cloud-based comprehensive analysis are transmitted. This local quality approach improves measurement precision for transmitted cases through cloud analysis while minimizing time loss by keeping simple cases local.
Solution Approach 2:
The patent performs preliminary threat assessment and categorization at the endpoint before cloud transmission. By conducting preliminary action to identify and filter intermediate cases, the system reduces the volume of data requiring cloud transmission and accelerates the overall detection process. Only cases needing cloud-based precision are transmitted, minimizing time loss while maintaining measurement precision where needed.
Data Source
AI summary
In a threat management platform, a number of endpoints log events in an event data recorder. A local agent filters this data and feeds a filtered data stream to a central threat management facility. The central threat management facility can locally or globally tune filtering by local agents based on the current data stream, and can query local event data recorders for additional information where necessary or helpful in threat detection or forensic analysis. The central threat management facility also stores and deploys a number of security tools such as a web-based user interface supported by machine learning models to identify potential threats requiring human intervention and other models to provide human-readable context for evaluating potential threats.


