Iterative Security List for Real-Time Threat Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data networks face challenges in efficiently identifying and blocking malicious communications in real-time, due to the complexity and vastness of data sets involved.
Innovation Solution
The implementation of an iterative security list generated by an access control mechanism, which uses Weight of Evidence (WoE) and Information Value (IV) calculations to create a set of access control rules applied by a filtering mechanism to determine if communications are erroneous and should be blocked.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional filtering mechanisms are used to identify malicious communications, then comprehensive analysis can be performed, but the processing speed and real-time capability deteriorate
Solution Approach 1:
The patent segments the threat detection process into multiple iterative stages, where each stage applies a subset of filtering rules. The iterative rule list divides comprehensive analysis into sequential steps, allowing the system to process communications in phases rather than requiring all rules to be applied simultaneously, thus improving processing speed while maintaining detection accuracy.
Solution Approach 2:
The patent implements dynamic rule application where the filtering mechanism adaptively selects and applies rules based on the communication being analyzed. The iterative approach allows the system to dynamically adjust which rules are applied at each stage, optimizing the balance between processing speed and detection accuracy by applying more stringent rules only when necessary.
2Reliability
If comprehensive filtering rules are applied to all communications, then threat detection accuracy improves, but computational resource consumption increases
Solution Approach 1:
The patent applies partial action by implementing an iterative rule list where not all filtering rules are applied to every communication. Instead, the system applies a sequence of rules iteratively, stopping when a decision is reached or when a predetermined number of iterations is completed. This reduces computational resource usage while maintaining security by applying comprehensive rules only when necessary.
Solution Approach 2:
The patent implements local quality by applying different filtering rule sets to different communications based on their characteristics. The iterative approach allows the system to apply more stringent local filtering rules to suspicious communications while using lighter rules for normal traffic, optimizing computational resource allocation across the network.
3Productivity
If simple filtering rules are used, then processing speed improves, but threat detection accuracy deteriorates
Solution Approach 1:
The patent implements periodic action through its iterative rule list mechanism, where filtering rules are applied in repeated cycles. Each iteration applies a set of rules and evaluates results, allowing the system to maintain high processing throughput by using simple rules in each iteration while achieving high detection accuracy through multiple periodic applications of the rule set.
Data Source
AI summary
Embodiments described herein relate generally to network-based threat detection mechanisms. Specifically, embodiments described herein describe a communication mechanism that filters (e.g., allows or blocks) received communications according to an iterative security list.


