Network Flow Risk Assessment via Composite Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for identifying cybersecurity threats based on single network flows or detection engines are insufficient, as they often lack sufficient evidence to confirm malware events or threats accurately.
Innovation Solution
A system that aggregates network flows between entities and uses multiple risk assessment tools to score communications, creating a composite risk score for clusters of network flows, enabling more accurate threat detection and remedial actions when thresholds are met.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a single network flow or single detection engine is used to identify threats, then the system complexity is low, but the detection accuracy is insufficient
Solution Approach 1:
The patent combines multiple network flows and multiple detection engines into a unified risk assessment system. Individual risk scores from different detection engines are aggregated and combined to form a composite risk score, enabling more accurate threat detection through the collective power of multiple sources rather than relying on a single engine.
Solution Approach 2:
The patent creates a composite risk assessment by combining multiple individual risk scores into a unified evaluation. Each detection engine contributes its own risk score, and these are synthesized into a composite score that provides a more comprehensive and accurate threat assessment, analogous to how composite materials combine different properties to achieve superior characteristics.
2Measurement precision
If multiple risk assessment tools are used to score network flows, then the detection accuracy improves, but the processing time increases
Solution Approach 1:
The patent performs preliminary scoring of individual network flows using multiple detection engines before aggregation. By pre-calculating individual risk scores and organizing them into a structured format, the system reduces the computational burden during the final risk assessment phase, enabling faster processing despite using multiple tools.
Solution Approach 2:
The patent divides the risk assessment process into separate scoring stages for different detection engines, with each engine independently evaluating specific aspects of network flows. This segmentation allows parallel processing of multiple engines and facilitates efficient aggregation of results, reducing overall processing time while maintaining comprehensive evaluation.
3Reliability
If individual network flows are scored separately, then the detailed analysis is thorough, but the overall risk assessment is less accurate
Solution Approach 1:
The patent implements a feedback mechanism where individual risk scores from multiple detection engines are aggregated and fed back into a unified risk assessment model. This feedback loop allows the system to adjust and refine the overall risk assessment based on the collective input from individual evaluations, improving reliability through iterative refinement.
Solution Approach 2:
The patent creates a universal aggregation framework that can handle risk scores from multiple different detection engines and types of network flows. This multi-functional aggregation system processes diverse inputs through a standardized method, enabling consistent and reliable overall risk assessment across different scenarios and data types.
Data Source
AI summary
A cluster of network flows is formed on the basis of a particular entity-to-entity relationship, and individual network flows within the cluster are further identified on an application-by-application basis to better characterize communications between two compute instances connected through a data network. By individually scoring network flows for each application with a variety of tools, and aggregating these individual scores into a composite score for the cluster of network flows, more accurate threat detections can be supported based on an increase in relevant threat data and a more complete view of risk factors.


