AI/ML Probabilistic Threat Mitigation for Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity of computer attacks necessitates advanced threat mitigation systems that leverage Artificial Intelligence (AI) and Machine Learning (ML) to effectively process large volumes of unstructured data for detecting security events and improving defense strategies.

Innovation Solution

A computer-implemented threat mitigation system utilizing probabilistic processes, including AI/ML, to analyze unstructured data for security events such as access auditing, anomalies, and attacks, and generate probabilistic models to enhance threat detection and response.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security monitoring methods are used, then device complexity is reduced, but the system cannot effectively detect and respond to increasingly complex computer attacks

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional mechanical security monitoring systems with an AI-based probabilistic system that uses machine learning models to analyze security events. The system substitutes rule-based detection with probabilistic reasoning engines that can handle the increasing complexity of modern attacks while maintaining manageable system complexity through automated learning and adaptation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system changes the fundamental parameters of security analysis by transitioning from deterministic rule-based approaches to probabilistic models with multiple variables. The probabilistic reasoning engine evaluates multiple parameters simultaneously (event probability, threat level, confidence scores) to make security decisions, enabling effective detection of complex attacks through parameter transformation rather than increased system complexity.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If AI/ML is used to process large quantities of security data, then threat detection accuracy is improved, but data processing time and computational resources increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-training probabilistic models on historical security data and pre-calculating probability distributions for common attack patterns. This allows the system to quickly evaluate new security events against pre-computed models, achieving high detection accuracy without processing time penalties during actual threat analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The probabilistic system applies partial action by focusing computational resources on the most probable threats and security events with highest risk scores. Rather than analyzing all data equally, the system uses probability thresholds to prioritize analysis of critical events, achieving effective threat detection with reduced processing time by avoiding excessive analysis of low-risk events.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP4028916B1Threat mitigation system and method
Publication Date: 2025.11.05 RELIAQUEST HOLDINGS LLC
  • EP4028916B1 patent drawingFigure 1
  • EP4028916B1 patent drawingFigure 2
  • EP4028916B1 patent drawingFigure 3

AI summary

A computer-implemented method, computer program product and computing system for: obtaining consolidated platform information to identify current security-relevant capabilities for a computing platform; determining possible security-relevant capabilities for the computing platform; and rendering graphical comparison information that illustrates a difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform.