Intrusion Detection Event Risk Rating Calculation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network intrusion detection systems face challenges in accurately assessing the risk of potential attacks due to false positives and lack of precision in severity ratings, which hinders effective resource allocation and response policies.
Innovation Solution
A method that calculates an event risk rating by considering factors such as signature fidelity, attack relevance, and target value, allowing for more precise assessment and prioritization of attacks, and enabling tailored response policies based on the calculated risk rating.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network intrusion detection systems monitor all network activity in real-time to detect suspicious or malicious activity, then the system can detect attacks quickly and provide timely warnings, but the system generates false positives when known signatures are detected but have no potential impact on the computer system
Solution Approach 1:
The patent changes the parameters for risk assessment from simple signature detection to a multi-factor evaluation model. This includes calculating risk ratings based on multiple parameters such as attack severity, system vulnerability, attack frequency, and business impact, thereby reducing false positives while maintaining detection accuracy
Solution Approach 2:
The system implements feedback mechanisms by continuously monitoring network activity, assessing risk ratings, and adjusting detection policies based on historical data and actual system behavior. This feedback loop enables the system to learn from past false positives and refine its detection accuracy over time
2Object-affected harmful factors
If the system blocks all potential attacks based on signature detection, then attack prevention is improved, but the system cannot distinguish between actual threats and benign activity, leading to over-blocking
Solution Approach 1:
The patent introduces a risk rating calculation that evaluates multiple parameters including attack severity, system vulnerability level, attack frequency, and business impact. This multi-parameter approach enables the system to prioritize blocking actions based on actual risk rather than simply blocking all detected signatures, thereby improving resource allocation efficiency
Solution Approach 2:
Instead of blocking all potential attacks uniformly, the system applies partial blocking based on calculated risk ratings. High-risk attacks are blocked automatically, while low-risk or false-positive detections are allowed to pass, avoiding excessive blocking and maintaining normal business operations
3Ease of operation
If the system responds to all detected attacks with the same blocking policy, then the response mechanism is simple, but the system cannot prioritize resource allocation based on attack severity and impact
Solution Approach 1:
The patent transforms the response mechanism from a uniform blocking policy to a differentiated response strategy based on calculated risk ratings. The system evaluates multiple parameters including attack severity, system criticality, and business impact to determine appropriate response actions, enabling efficient resource allocation to high-priority threats
Solution Approach 2:
The system implements dynamic response policies that adapt based on the calculated risk rating. The response mechanism transitions from static uniform blocking to dynamic conditional responses, where the system automatically adjusts blocking, alerting, and resource allocation based on the severity and impact assessment of each detected attack
Data Source
AI summary
According to one embodiment of the invention, a computerized method for addressing intrusion attacks directed at a computer includes receiving a data stream corresponding to a potential attack on the computer and calculating an event risk rating for the data stream. Calculating the event risk rating includes determining at least one component risk rating. In one embodiment, the component risk ratings are: a signature fidelity rating indicative of the likelihood the potential attack will affect the computer in the absence of knowledge regarding the computer, an attack relevance rating indicative of the relevance of the potential attack to the computer, and a target value rating indicative of the perceived value of the computer. The method also includes responding to the potential attack based on the calculated risk rating.


