Hierarchical Security Event Database for Suspicious Pattern Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Identifying suspicious activities in criminal and homeland security investigations is challenging due to the innocuous nature of individual data points, which require both experience and intuition to recognize patterns indicative of potential threats, such as terrorist plots.

Innovation Solution

A computer database system that hierarchically relates triggering security events to additional events based on relationships, including temporal and spatial proximity, and associations between individuals, generating alerts when a predetermined threshold of likelihood is exceeded, with patterns fine-tuned for seasonal, holiday, and climatic norms, and national significance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If individual security events are analyzed separately in a traditional database, then data storage and basic retrieval are simple, but suspicious patterns cannot be identified because each event appears innocuous on its own

Engineering Contradiction:
Improvedifficulty of identifying suspicious patternsVSAvoidcomplexity of data analysis system
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent transitions from analyzing events in isolation (one dimension) to analyzing events across multiple dimensions simultaneously - temporal dimension (time proximity), spatial dimension (location proximity), and relational dimension (connections between individuals). This multi-dimensional analysis enables the system to detect suspicious patterns that are invisible when examining individual events separately, directly resolving the contradiction between detection difficulty and system complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent implements a hierarchical event structure where triggering events are nested with related events, which are themselves nested with additional related events. This nested organization allows the system to manage complexity by breaking down complex pattern recognition into manageable hierarchical levels, where each level focuses on specific aspects of the suspicious activity pattern.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Measurement precision

If experience and intuition are used to recognize suspicious patterns, then pattern recognition accuracy improves, but the process cannot be automated and requires human expertise

Engineering Contradiction:
Improvepattern recognition accuracyVSAvoidautomation of security analysis
Core Design Contradiction:
Measurement precisionVSExtent of automation

Solution Approach 1:

The patent transforms the abstract concepts of experience and intuition into concrete, quantifiable parameters that can be processed by computer algorithms. Specifically, it defines measurable parameters such as time proximity thresholds, location proximity thresholds, and relationship connection criteria. By changing parameters from qualitative (intuition) to quantitative (measurable thresholds), the system achieves both high accuracy and full automation.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system automatically performs pattern recognition without requiring human analysts to manually review each event. The automated analysis engine continuously monitors security events, applies the defined parameters and thresholds, and generates alerts for suspicious patterns autonomously. This self-service capability achieves complete automation while maintaining high accuracy through the structured parameter-based approach.

Inventive Principle:
Principle #25Self-service

3Reliability

If all security events are stored and analyzed together, then comprehensive pattern detection is possible, but the amount of data to be processed becomes overwhelming and analysis efficiency decreases

Engineering Contradiction:
Improvecompleteness of security analysisVSAvoiddata analysis efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the large volume of security event data into manageable units organized around triggering events. Each triggering event becomes the focal point for gathering and analyzing only the relevant related events that meet specific criteria (time proximity, location proximity, relationship connections). This segmentation approach maintains comprehensive analysis reliability by ensuring all relevant events are captured, while improving productivity by avoiding processing of irrelevant data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary filtering and organization of security events before detailed analysis. Events are pre-grouped into hierarchical structures based on triggering events and their relationships, with preliminary assessments of time and location proximity. This preliminary action reduces the data volume requiring intensive analysis while preserving all potentially relevant information, thereby maintaining reliability and improving analysis efficiency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8782780B2Hierarchical organization of data associated with events
Publication Date: 2014.07.15 KYNDRYL INC
  • US8782780B2 patent drawing
  • US8782780B2 patent drawing
  • US8782780B2 patent drawing

AI summary

Methods, data structures, systems and computer program products are provided for organizing security data. A triggering security event is hierarchically related to at least one additional security event based on a possible relationship between the triggering security event and the at least one additional security event in a computer database environment.