Heuristic Analytics for Real-Time Security Event Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for analyzing information security events are inefficient and time-consuming, particularly in mission-critical systems, as they rely on post-crime forensic data analytics that struggle with the vast volume and diversity of unstructured data, hindering rapid discovery and response to security threats.

Innovation Solution

A heuristic data analytics method that analyzes Binary Large Objects (BLOBs) of structured and unstructured information security events in real-time using large-scale computing systems, identifying potential security breaches by buffering data streams, determining statistical parameters, and generating behavioral patterns to detect variations from expected or predefined patterns, enabling early threat identification and defensive countermeasures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If post-crime forensic data analytics is used to analyze information security events, then analysis thoroughness is improved, but analysis speed and responsiveness deteriorate

Engineering Contradiction:
Improveanalysis thoroughnessVSAvoidanalysis speed
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously analyzing information security events in real-time as they occur, rather than waiting for post-crime forensic analysis. The heuristic analytics engine proactively processes events, identifies patterns, and detects anomalies before security breaches can cause significant damage, thereby resolving the contradiction between thoroughness and speed by shifting the analysis timeline forward

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system segments the analysis process into distinct functional components: event collection from multiple sources, heuristic pattern matching, statistical anomaly detection, and threat classification. This segmentation allows parallel processing of different event types using specialized algorithms, enabling both comprehensive analysis coverage and high-speed processing simultaneously

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If traditional forensic data analytics software is used to handle large volumes of unstructured information security events, then data accuracy is improved, but processing capability deteriorates

Engineering Contradiction:
Improvedata accuracyVSAvoidprocessing capability
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system changes the parameters of data processing by transforming unstructured security events into standardized structured formats with defined schemas. Events are normalized into consistent data models with standardized fields for timestamp, source, destination, event type, and severity. This parameter standardization enables efficient indexing, querying, and analysis while maintaining full data accuracy, resolving the contradiction between handling unstructured data comprehensively and processing it at high speed

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system introduces an intermediary layer consisting of heuristic analytics engines and pattern recognition algorithms that act as mediators between raw security events and forensic analysis. These intermediaries pre-process and enrich events with contextual information, threat intelligence, and behavioral patterns, thereby reducing the computational burden on downstream forensic systems while improving overall processing capability

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of time

If real-time heuristic analytics is implemented to identify security threats early, then response time is improved, but system complexity increases

Engineering Contradiction:
Improveresponse timeVSAvoidsystem complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system implements universal multi-functional heuristic analytics engines that can analyze multiple types of security events (network intrusions, malware detections, authentication failures, data access anomalies) using a single unified platform. The same core engine adapts to different data sources and event types through configurable parameters rather than requiring separate specialized systems, thereby reducing overall system complexity while maintaining real-time response capabilities across diverse security domains

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Measurement precision

If comprehensive data collection from multiple sources is performed to improve threat detection accuracy, then detection precision is improved, but data processing burden increases

Engineering Contradiction:
Improvedetection precisionVSAvoiddata processing burden
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system extracts and isolates only the most critical and relevant features from comprehensive security event data for analysis. Instead of processing all raw event attributes equally, the heuristic engines identify and extract key indicators of compromise (IOCs), behavioral anomalies, and threat patterns that are most predictive of security breaches. This selective extraction reduces processing burden while maintaining high detection precision by focusing computational resources on the most informative data elements

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10740458B2System and method for high frequency heuristic data acquisition and analytics of information security events
Publication Date: 2020.08.11 CERTIS CISCO
  • US10740458B2 patent drawing
  • US10740458B2 patent drawing
  • US10740458B2 patent drawing

AI summary

This document discloses a heuristic data analytics method and system for analysing potential information security threats in information security events. In particular, the heuristic data analytics method and system analyses Binary Large Objects (BLOBs) of structured and unstructured information security events at high speed and in real-time to anticipate potential security breaches that will occur in the near future using algorithms and large scale computing systems.