Machine Learning Threat Detection for Malicious Entity Ranking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security Operations Center (SOC) analysts face alert fatigue due to the large number of threats, making it difficult to identify which entities are likely to be at risk or pose a risk to other users, as traditional detections do not provide clear indications of malicious entities.

Innovation Solution

A machine learning (ML) threat detector is trained using signal records to predict the threat level of entities, allowing for targeted cybersecurity mitigation actions based on the predicted threat level.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional detection methods are used to monitor all entities, then comprehensive security coverage is achieved, but SOC analysts experience alert fatigue and cannot identify main malicious entities

Engineering Contradiction:
Improvesecurity coverageVSAvoidanalyst workload
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a machine learning model as an intermediary between traditional detection systems and human analysts. The model processes detection signals and entity interactions to generate threat scores, acting as a mediator that filters and prioritizes information before presenting it to analysts, thereby maintaining comprehensive security coverage while reducing analyst workload

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual analysis of detection signals with an automated machine learning system. The mechanical process of analysts reviewing all alerts is substituted with an electronic ML-based threat scoring system that automatically processes and prioritizes entities based on their interaction patterns and signal characteristics

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If cybersecurity mitigation actions are performed on all entities, then maximum security protection is provided, but processing resources are wasted on non-malicious entities

Engineering Contradiction:
Improvesecurity protectionVSAvoidprocessing resources
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies local quality by differentiating threat levels across different entities rather than applying uniform security measures. The ML model generates specific threat scores for each entity based on their individual signal patterns and interactions, enabling targeted mitigation actions that are proportionate to each entity's actual risk level

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by applying cybersecurity mitigation measures only to entities that exceed a certain threat threshold, rather than treating all entities equally. This selective approach focuses resources on the most problematic entities while avoiding unnecessary actions on low-risk entities

Inventive Principle:
Principle #16Partial or excessive action

3Quantity of substance

If traditional detection systems are used, then all suspicious activities are detected, but clear identification of main malicious entities is not provided

Engineering Contradiction:
Improvedetection coverageVSAvoidentity identification accuracy
Core Design Contradiction:
Quantity of substanceVSMeasurement precision

Solution Approach 1:

The patent adds a new dimension of threat scoring to traditional detection outputs. Instead of merely detecting suspicious activities, the ML model incorporates entity interaction graphs and temporal patterns to generate a quantitative threat score that ranks entities by likelihood of being malicious, transforming qualitative detection data into actionable prioritization information

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12432252B2Method and system for predicting malicious entities
Publication Date: 2025.09.30 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12432252B2 patent drawing
  • US12432252B2 patent drawing
  • US12432252B2 patent drawing

AI summary

A computer-implemented method, computer device and computer program are provided for training a Machine Learning model based on a plurality of signal records, each signal record comprising an entity identifier, a signal identifier and a timestamp. Signal records related to an entity can be input into the trained Machine Learning model. The trained Machine Learning model can be used to determine if an entity is malicious.