Event Feature Extraction for Security Risk Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems face inefficiencies in identifying and managing risk associated with user behavior, as they often apply uniform policies without distinguishing between different types of user interactions, leading to inefficient resource utilization and challenges in detecting anomalous or malicious behavior.

Innovation Solution

A method and system for generating extracted features from events by receiving a stream of events, applying labels, and processing them to extract features, utilizing a processor, data bus, and non-transitory computer-readable storage medium with computer program code to analyze probability distributions of interrelated event features in real-time, enabling dynamic security oversight and resource management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If uniform security policies are applied to all user behavior, then security coverage is comprehensive, but security system resource utilization becomes inefficient

Engineering Contradiction:
Improvesecurity coverageVSAvoidresource utilization efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies different security policies and monitoring levels to different user behaviors based on their risk characteristics. High-risk behaviors receive enhanced scrutiny while low-risk behaviors receive standard monitoring, optimizing resource allocation while maintaining comprehensive security coverage

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts security parameters such as monitoring intensity, policy strictness, and resource allocation based on the risk level of detected user behaviors, transitioning from static uniform policies to adaptive parameter-based security management

Inventive Principle:
Principle #35Parameter changes

2Device complexity

If typical security monitoring approaches are used, then system simplicity is maintained, but detection of anomalous or malicious behavior becomes challenging

Engineering Contradiction:
Improvemonitoring system complexityVSAvoidanomaly detection capability
Core Design Contradiction:
Device complexityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent replaces traditional rule-based security monitoring with machine learning models that automatically learn and detect anomalous patterns in user behavior, substituting mechanical detection methods with intelligent analysis systems

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system introduces feature extraction and risk scoring intermediaries between raw event data and security decisions, enabling sophisticated anomaly detection while maintaining a modular architecture that manages complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If detailed analysis of all user events is performed, then detection accuracy is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvebehavior analysis accuracyVSAvoidevent processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent extracts only the most relevant features from user events for analysis, filtering out redundant information and focusing computational resources on critical behavior indicators that most strongly correlate with security risks

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs detailed analysis only on events that meet certain criteria or exhibit potential risk indicators, applying full analytical depth selectively rather than uniformly to all events, thus balancing accuracy with processing efficiency

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11436512B2Generating extracted features from an event
Publication Date: 2022.09.06 EVERFOX HOLDINGS LLC
  • US11436512B2 patent drawing
  • US11436512B2 patent drawing
  • US11436512B2 patent drawing

AI summary

A method, system and computer-usable medium for performing a feature generation operation. The performing a feature generation operation including: receiving a stream of events, the stream of events comprising a plurality of events; applying labels to applicable events from the plurality of events, the applying labels providing a labeled event; and, processing the labeled event to extract a feature from the labeled event, the processing providing a feature associated with an event.