Security Risk Identification via Event Feature Distributions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security monitoring approaches struggle to effectively identify anomalous, abnormal, or malicious user behavior, as such behavior may not be readily apparent, leading to inefficient utilization of security resources and potential security risks.

Innovation Solution

A method and system that analyze probability distributions of event features using categorical features extracted from event streams, allowing for real-time identification of security risk factors by constructing distributions based on categorical feature members and extracting string values from events.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If typical security monitoring approaches are employed, then security resources are utilized, but anomalous or malicious user behavior cannot be readily identified

Engineering Contradiction:
Improvedetection accuracyVSAvoidbehavior analysis difficulty
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent transforms categorical event features into probability distributions, changing the parameter representation from discrete categories to continuous probability values. This enables more nuanced detection of anomalous behavior by analyzing deviations from expected probability patterns rather than relying on simple threshold-based categorical matching.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent adds a probabilistic dimension to traditional categorical security event analysis. By constructing probability distributions over categorical features and analyzing their statistical properties, the system detects security risks in a new dimensional space that reveals patterns invisible to conventional monitoring approaches.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If indiscriminate security policies are applied to all user behavior, then security coverage is maintained, but security system resources are inefficiently utilized

Engineering Contradiction:
Improvesecurity coverageVSAvoidresource utilization efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies different levels of security scrutiny to different user behaviors based on their probability distribution characteristics. High-risk behaviors exhibiting significant deviations from normal patterns receive intensified monitoring and analysis, while routine behaviors follow standard procedures, optimizing resource allocation across the security system.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements selective deep analysis only for events that exhibit statistically significant anomalies in their probability distributions. Rather than uniformly applying complex analysis to all events, the system focuses computational resources on partial cases that warrant heightened attention, improving overall efficiency while maintaining adequate coverage.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11811799B2Identifying security risks using distributions of characteristic features extracted from a plurality of events
Publication Date: 2023.11.07 EVERFOX HOLDINGS LLC
  • US11811799B2 patent drawing
  • US11811799B2 patent drawing
  • US11811799B2 patent drawing

AI summary

A method, system and computer-usable medium for constructing a distribution of interrelated event features. The constructing a distribution of interrelated event features includes receiving a stream of events, the stream of events comprising a plurality of events; extracting features from the plurality of events; constructing a distribution of the features from the plurality of events; and, analyzing the distribution of the features from the plurality of events.