Mapping Unbounded Incident Scores to Fixed Range

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing prevalence of malware and malicious behavior in computer systems makes it challenging to detect and mitigate cyber threats in a timely and resource-efficient manner, as existing security measures often struggle with obfuscated or disguised malicious software.

Innovation Solution

A security service system that monitors host devices for potential malicious incidents by collecting and analyzing event data, using incident scoring and aggregation schemes to identify patterns, and employing a security component that interacts with a cloud-based security system to detect, prevent, and mitigate malware and attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If unbounded incident scores are used to rank malicious incidents, then the system can capture the full range of incident severity, but the scores become difficult to interpret and compare across different time periods and systems

Engineering Contradiction:
Improveincident score interpretabilityVSAvoidincident score range
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent transforms unbounded incident scores into bounded scores using statistical parameters (percentiles, quantiles) to map scores to a standardized range. This allows the system to maintain the full severity differentiation while making scores interpretable through consistent scaling across different time periods and systems.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If comprehensive event data collection is performed to detect obfuscated malware, then detection accuracy improves, but resource consumption and processing time increase significantly

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidthreat detection efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a two-stage detection approach where not all events are fully analyzed. Instead, events are first screened using lightweight filters, and only suspicious events undergo comprehensive analysis. This partial action approach maintains high detection accuracy for malicious incidents while reducing overall resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The detection system is divided into multiple components: event collection, preliminary filtering, incident scoring, and detailed analysis. This segmentation allows the system to process large volumes of events efficiently by applying different levels of scrutiny to different event subsets, improving overall productivity without sacrificing reliability.

Inventive Principle:
Principle #1Segmentation

3Loss of information

If incident scores are aggregated across multiple systems and time periods, then comprehensive threat assessment is achieved, but the complexity of score comparison and threshold determination increases

Engineering Contradiction:
Improvethreat assessment completenessVSAvoidaggregation system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent standardizes incident scores from multiple systems by transforming them to a common scale using percentile-based normalization. This parameter transformation allows aggregation across diverse systems while maintaining comparability, reducing the complexity of threshold determination through consistent scoring distributions.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces statistical intermediaries (percentiles, quantiles, and distribution functions) between raw incident scores and aggregated assessments. These intermediaries serve as mediators that normalize scores from different sources, enabling comprehensive threat assessment while simplifying the aggregation process through standardized intermediate representations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11792210B2Mapping unbounded incident scores to a fixed range
Publication Date: 2023.10.17 CROWDSTRIKE
  • US11792210B2 patent drawing
  • US11792210B2 patent drawing
  • US11792210B2 patent drawing

AI summary

Techniques and systems to provide a more intuitive user overview of events data by mapping unbounded incident scores to a fixed range and aggregating incident scores by different schemes. The system may detect possible malicious incidents associated with events processing on a host device. The events data may be gathered from events detected on the host device. The incident scores for incidents may be determined from the events data. The incident scores may be mapped to bins of a fixed range to highlight the significance of the incident scores. For instance, a first score mapped to a first bin may be insignificant while a second score mapped to a last bin may require urgent review. The incident scores may also be aggregated at different levels (e.g., host device, organization, industry, global, etc.) and at different time intervals to provide insights to the data.