Network Security Alerting With Adaptive ARO Risk Reporting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer networks face challenges in maintaining security due to distributed architectures, limited resources for threat management, and the difficulty in processing vast amounts of event data to adapt to changing risks and threats.

Innovation Solution

A system and method for network security monitoring that includes generating alerts from network events, processing them with triggering definitions to create Action, Recommendation, or Observation (ARO) reports, and adjusting these definitions based on feedback from a remote server, allowing for efficient and secure network management across distributed environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network administrators manually monitor and process event data to detect threats, then security monitoring capability is improved, but resource consumption and time requirements increase significantly

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidtime for processing event data
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables automated self-monitoring of network security through machine learning models that automatically analyze event data, detect threats, and generate alerts without requiring continuous manual intervention from administrators

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Manual monitoring and analysis processes are replaced with automated machine learning-based systems that process event data, identify patterns, and detect security threats algorithmically, substituting human effort with computational automation

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If comprehensive event data is retained for analysis, then threat detection accuracy is improved, but bandwidth usage and data storage requirements increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidbandwidth usage
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The system extracts only the most relevant and critical event data elements needed for threat detection, filtering out redundant information to reduce data transmission and storage requirements while maintaining detection accuracy

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Different levels of data retention and processing are applied to different types of events based on their security relevance, with high-priority events receiving full analysis and lower-priority events receiving summarized processing

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If distributed network architecture is implemented to improve scalability, then network capacity is improved, but security management complexity increases

Engineering Contradiction:
Improvenetwork scalabilityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

A centralized machine learning model serves multiple distributed network locations simultaneously, providing universal threat detection capabilities across the entire distributed architecture through a single coordinated system

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The machine learning model acts as an intermediary layer between distributed network components and security administrators, translating complex distributed security events into unified, interpretable insights that simplify management

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20260032157A1Systems and methods for network monitoring, reporting, and risk mitigation
Publication Date: 2026.01.29 FIELD EFFECT SOFTWARE INC
  • US20260032157A1 patent drawing
  • US20260032157A1 patent drawing
  • US20260032157A1 patent drawing

AI summary

A network monitoring, reporting and risk mitigation system collects events at a computing device within the local network to provide improved network security. The events are aggregated into alerts, which may be processed according to triggering definitions in order to create ARO (action, recommendations and observations) reports providing required or recommended actions to take or observations to a network administrator. The ARO reports may be processed by a remote server in order to generate contextual feedback for updating the triggering definitions.