Event Distribution Analysis for Security Risk Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems face challenges in efficiently identifying and managing risk associated with user behavior, as they often apply uniform policies without distinguishing between different types of interactions, leading to inefficient resource utilization and difficulty in detecting anomalous or malicious behavior.

Innovation Solution

A method and system that analyze probability distributions of interrelated event features in real-time, using a processor and data bus with a non-transitory computer-readable storage medium to extract features from event streams, identify items of interest, and generate distribution values, enabling more nuanced security oversight.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If uniform security policies are applied to all user behavior, then security coverage is comprehensive, but security resource utilization becomes inefficient

Engineering Contradiction:
Improvesecurity coverageVSAvoidsecurity resource utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies different security policies and levels of oversight to different user behaviors based on their risk characteristics. High-risk behaviors receive intensified scrutiny while low-risk behaviors receive standard monitoring, creating localized quality variations in security application that optimize resource allocation while maintaining comprehensive coverage

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts security parameters such as monitoring intensity, policy strictness, and resource allocation based on the risk assessment of different user behaviors. This allows the security system to adapt its operational parameters to match the actual threat level, improving efficiency without compromising reliability

Inventive Principle:
Principle #35Parameter changes

2Device complexity

If typical security monitoring approaches are used, then system complexity is low, but detection of anomalous or malicious behavior becomes difficult

Engineering Contradiction:
Improvemonitoring approach complexityVSAvoiddetection of anomalous behavior
Core Design Contradiction:
Device complexityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements dynamic security monitoring that adapts to user behavior patterns in real-time. The system continuously learns from observed behaviors and adjusts its detection thresholds and focus areas, enabling it to identify anomalous behaviors that static monitoring approaches would miss, while maintaining manageable system complexity through adaptive rather than purely rule-based mechanisms

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11810012B2Identifying event distributions using interrelated events
Publication Date: 2023.11.07 EVERFOX HOLDINGS LLC
  • US11810012B2 patent drawing
  • US11810012B2 patent drawing
  • US11810012B2 patent drawing

AI summary

A method, system and computer-usable medium for identifying probability distributions. The identifying probability distributions includes receiving a stream of events, the stream of events comprising a plurality of events; extracting features from the plurality of events, at least some extracted features corresponding to interrelated events; identifying items of interest based upon the interrelated events; and, generating a distribution value based upon the items of interest.