Probabilistic Event Processing for Missing-Event Risk Metrics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Complex Event Processing (CEP) systems assume uniformity of input data sources and lack handling of missing events, leading to inefficiencies in threat detection and response.
Innovation Solution
Implementing a probabilistic model using Bayesian Networks or Markov Chains to compute a risk metric on a network of processing nodes, handling both concrete and probabilistic events, including event pattern matching and machine learning to account for missing information and propagate risk assessments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If current CEP systems assume uniformity of input data sources and concrete events without missing inputs, then the system operation is simplified, but the reliability of threat detection deteriorates due to inability to handle real-world uncertainties
Solution Approach 1:
The patent transforms the nature of event representation by introducing probabilistic parameters. Events are no longer represented as simple concrete occurrences but as probabilistic events with associated confidence values and uncertainty measurements. This parameter change allows the system to handle missing data and source variability while maintaining automated processing through mathematical probability frameworks.
Solution Approach 2:
The patent introduces probabilistic modeling and uncertainty quantification as intermediary layers between raw event data and threat detection conclusions. These intermediaries bridge the gap between simplified system operation and reliable threat detection by providing a mathematical framework to handle uncertainties without requiring complex manual intervention.
2Device complexity
If CEP systems process only concrete events from similar data sources, then the device complexity is reduced, but the adaptability to handle diverse real-world data sources deteriorates
Solution Approach 1:
The patent creates a universal probabilistic event processing framework that can handle multiple types of data sources and event types through a unified approach. The system uses general probabilistic models and uncertainty measurements that apply across different data sources (social media, transaction systems, web activity, etc.), making the system adaptable to diverse inputs without requiring source-specific processing logic.
Solution Approach 2:
By changing the representation of events to include probabilistic parameters and uncertainty measurements, the system gains the ability to process diverse data sources uniformly. The parameter enrichment allows the same processing framework to handle concrete events, missing events, and events from various sources with different reliability characteristics.
3Productivity
If CEP systems do not account for missing events or uncertain data, then the productivity of event processing is maintained, but the measurement precision of threat detection deteriorates
Solution Approach 1:
The patent replaces traditional mechanical event matching logic with probabilistic mathematical models. Instead of requiring exact matches and complete data, the system uses probability theory and statistical methods to assess threats. This substitution maintains processing throughput by using efficient computational probability frameworks while dramatically improving measurement precision through uncertainty quantification and confidence measurements.
Solution Approach 2:
The introduction of probabilistic parameters and uncertainty measurements transforms the event processing approach. The system can now process events with partial information by computing probability-based threat assessments, maintaining productivity through automated probabilistic reasoning while improving detection accuracy through quantitative uncertainty analysis.
Data Source
Figure 1A
Figure 1B
Figure 2
AI summary
Methods and systems for computing a risk metric on a network of processing nodes are disclosed. The method includes receiving a plurality of events at a plurality of processing nodes. The method further includes at a first processing node, processing on a first event and a known instance of a second event to determine whether the first event matches the known instance of the second event. The method further includes in response to determining that the first event does not match the known instance of the second event, terminating the processing without generating an output, and generating a first output event having a resulting probability computed based on a confidence value of the first event and a first probabilistic value of a first missing event, or in response to determining that the first event matches the known instance of the second event, generating the first output event having the resulting probability computed based on the confidence value of the first event.