Multi-Level Event Abstraction for Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing threat detection techniques primarily focus on data transmission/reception and struggle to detect threats caused by factors other than data exchange, limiting their effectiveness in identifying various potential threats within a computer system.
Innovation Solution
A warning apparatus that acquires and abstracts event information at multiple levels, determines relevant threat information, and generates warning information based on the relevance and abstraction level, enabling the detection of various threats beyond data transmission/reception activities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If threat detection focuses only on data transmission/reception activities, then detection simplicity is maintained, but detection coverage is limited
Solution Approach 1:
The patent segments event information into multiple abstraction levels (first abstraction level with detailed event data, second abstraction level with summarized event data). This segmentation allows the system to detect threats at different levels of detail, expanding detection coverage without requiring a single complex detection mechanism to handle all cases.
Solution Approach 2:
The patent introduces an additional dimension of abstraction levels to organize event information. By representing events at both detailed and summarized levels simultaneously, the system can match threat patterns against event data at the appropriate level of abstraction, thereby expanding detection capabilities without linearly increasing complexity.
2Productivity
If event information is represented at a single detailed level, then detection precision is high, but processing efficiency decreases
Solution Approach 1:
The patent applies partial action by generating summarized event information (second abstraction level) that captures essential threat-relevant features without including all detailed event data. This partial representation maintains sufficient detection accuracy while significantly improving processing efficiency, as the summarized data can be quickly compared against threat patterns.
Solution Approach 2:
The patent changes the parameter of event information representation by creating multiple abstraction levels. The first level preserves detailed parameters for high-precision detection when needed, while the second level transforms parameters into summarized forms for efficient processing, allowing the system to balance precision and efficiency dynamically.
Data Source
AI summary
A warning apparatus (2000) acquires first detected event information (10) representing, at a first abstraction level, an event set being a set of events having occurred in a target system. The warning apparatus (2000) generates second detected event information (20) from the first detected event information (10). The second detected event information (20) represents, at a second abstraction level, the event set represented by the first detected event information (10). The warning apparatus (2000) determines, from among a plurality of pieces of threat information (30) each representing a threat activity, the threat information (30) having a high degree of relevance to at least either of the first detected event information (10) and the second detected event information (20). The warning apparatus (2000) generates warning information (40) relating to a threat being occurring in the target system, based on the determined threat information (30) and a matching level being an abstraction level associated with the detected event information having a high degree of relevance to the threat information (30).


