Multi-Level Event Abstraction for Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing threat detection techniques primarily focus on data transmission/reception and struggle to detect threats caused by factors other than data exchange, limiting their effectiveness in identifying various potential threats within a computer system.

Innovation Solution

A warning apparatus that acquires and abstracts event information at multiple levels, determines relevant threat information, and generates warning information based on the relevance and abstraction level, enabling the detection of various threats beyond data transmission/reception activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If threat detection focuses only on data transmission/reception activities, then detection simplicity is maintained, but detection coverage is limited

Engineering Contradiction:
Improvedetection coverageVSAvoiddetection mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments event information into multiple abstraction levels (first abstraction level with detailed event data, second abstraction level with summarized event data). This segmentation allows the system to detect threats at different levels of detail, expanding detection coverage without requiring a single complex detection mechanism to handle all cases.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an additional dimension of abstraction levels to organize event information. By representing events at both detailed and summarized levels simultaneously, the system can match threat patterns against event data at the appropriate level of abstraction, thereby expanding detection capabilities without linearly increasing complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If event information is represented at a single detailed level, then detection precision is high, but processing efficiency decreases

Engineering Contradiction:
Improvethreat detection efficiencyVSAvoidthreat detection accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent applies partial action by generating summarized event information (second abstraction level) that captures essential threat-relevant features without including all detailed event data. This partial representation maintains sufficient detection accuracy while significantly improving processing efficiency, as the summarized data can be quickly compared against threat patterns.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent changes the parameter of event information representation by creating multiple abstraction levels. The first level preserves detailed parameters for high-precision detection when needed, while the second level transforms parameters into summarized forms for efficient processing, allowing the system to balance precision and efficiency dynamically.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12001551B2Warning apparatus, control method, and program
Publication Date: 2024.06.04 NEC CORP
  • US12001551B2 patent drawing
  • US12001551B2 patent drawing
  • US12001551B2 patent drawing

AI summary

A warning apparatus (2000) acquires first detected event information (10) representing, at a first abstraction level, an event set being a set of events having occurred in a target system. The warning apparatus (2000) generates second detected event information (20) from the first detected event information (10). The second detected event information (20) represents, at a second abstraction level, the event set represented by the first detected event information (10). The warning apparatus (2000) determines, from among a plurality of pieces of threat information (30) each representing a threat activity, the threat information (30) having a high degree of relevance to at least either of the first detected event information (10) and the second detected event information (20). The warning apparatus (2000) generates warning information (40) relating to a threat being occurring in the target system, based on the determined threat information (30) and a matching level being an abstraction level associated with the detected event information having a high degree of relevance to the threat information (30).