Machine Learning Correlator for Network Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems face challenges in detecting security threats in a timely manner across networked environments, relying on a combination of human resources and partially automated systems, which often fail to identify risks before they spread significantly.

Innovation Solution

A computing system and method that maintains data sets for assets, users, and security threats, correlating them using classifiers and correlators to identify threats and perform security actions, such as locking assets or suspending operations, in response to queries about assets, users, or security threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If conventional systems use human resources and partially automated systems for security management, then operational flexibility is maintained, but detection speed and timeliness deteriorate

Engineering Contradiction:
Improvedetection speedVSAvoidsystem complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The system segments security monitoring into specialized components: data collection module, machine learning correlator, threat identification module, and automated response module. Each component handles specific tasks, enabling parallel processing and faster detection without overwhelming system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The machine learning correlator acts as an intermediary between raw security data and threat identification. It automatically correlates data from multiple sources, reducing the need for complex human analysis while accelerating detection speed through automated pattern recognition.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If more data sources are correlated to improve threat detection accuracy, then measurement precision improves, but device complexity increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoiddata correlation complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The machine learning correlator is designed as a universal component that handles multiple data sources (network traffic, system logs, threat intelligence feeds) through a single correlated data structure. This multi-functional approach enables comprehensive threat detection without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system transforms raw data from various sources into standardized parameters within a correlated data structure. By changing the parameter representation and using machine learning to identify relationships between parameters, the system achieves high detection accuracy while managing complexity through consistent data transformation.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If automated systems are implemented to improve response time, then productivity increases, but ease of operation decreases

Engineering Contradiction:
Improveresponse productivityVSAvoidsystem operation ease
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by pre-configuring response protocols and pre-training machine learning models on historical security data. When threats are detected, pre-defined automated responses are immediately executed, increasing productivity while maintaining operational simplicity through pre-planned action sequences.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback loops where automated responses are monitored and evaluated. This feedback mechanism allows the system to self-adjust and improve while maintaining automated operation, reducing the need for complex manual intervention and preserving ease of operation despite high automation levels.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11856017B2Machine learning correlator to infer network properties
Publication Date: 2023.12.26 RAPID7 INC
  • US11856017B2 patent drawing
  • US11856017B2 patent drawing
  • US11856017B2 patent drawing

AI summary

Approaches provide for securing an electronic environment. A threat analysis service can obtain data for devices, users, and threats from disparate sources and can correlate users to devices and threats to build an understanding of an electronic environment's operational, organizational, and security concerns in order to provide customized security strategies and remediations. Additionally, the threat analysis service can develop a model of an electronic environment's behavior by monitoring and analyzing various the data from the data sources. The model can be updated such that the threat analysis service can tailor its orchestration to complement existing operational processes.