Event Feature Extraction for Security Risk Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security systems face inefficiencies in identifying and managing risk associated with user behavior, as they often apply uniform policies without distinguishing between different types of user interactions, leading to inefficient resource utilization and challenges in detecting anomalous or malicious behavior.
Innovation Solution
A method and system for generating extracted features from events by receiving a stream of events, applying labels, and processing them to extract features, utilizing a processor, data bus, and non-transitory computer-readable storage medium with computer program code to analyze probability distributions of interrelated event features in real-time, enabling dynamic security oversight and resource management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If uniform security policies are applied to all user behavior, then security coverage is comprehensive, but security system resource utilization becomes inefficient
Solution Approach 1:
The patent applies different security policies and monitoring levels to different user behaviors based on their risk characteristics. High-risk behaviors receive enhanced scrutiny while low-risk behaviors receive standard monitoring, optimizing resource allocation while maintaining comprehensive security coverage
Solution Approach 2:
The system dynamically adjusts security parameters such as monitoring intensity, policy strictness, and resource allocation based on the risk level of detected user behaviors, transitioning from static uniform policies to adaptive parameter-based security management
2Device complexity
If typical security monitoring approaches are used, then system simplicity is maintained, but detection of anomalous or malicious behavior becomes challenging
Solution Approach 1:
The patent replaces traditional rule-based security monitoring with machine learning models that automatically learn and detect anomalous patterns in user behavior, substituting mechanical detection methods with intelligent analysis systems
Solution Approach 2:
The system introduces feature extraction and risk scoring intermediaries between raw event data and security decisions, enabling sophisticated anomaly detection while maintaining a modular architecture that manages complexity
3Measurement precision
If detailed analysis of all user events is performed, then detection accuracy is improved, but processing time and computational resources increase
Solution Approach 1:
The patent extracts only the most relevant features from user events for analysis, filtering out redundant information and focusing computational resources on critical behavior indicators that most strongly correlate with security risks
Solution Approach 2:
The system performs detailed analysis only on events that meet certain criteria or exhibit potential risk indicators, applying full analytical depth selectively rather than uniformly to all events, thus balancing accuracy with processing efficiency
Data Source
AI summary
A method, system and computer-usable medium for performing a feature generation operation. The performing a feature generation operation including: receiving a stream of events, the stream of events comprising a plurality of events; applying labels to applicable events from the plurality of events, the applying labels providing a labeled event; and, processing the labeled event to extract a feature from the labeled event, the processing providing a feature associated with an event.


