Real-Time Risk Assessment Caching for Online Activity Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in detecting and mitigating high-risk online activities in real-time, such as command and control beaconing, lateral movement of assets, and denial of service attacks, which can lead to loss of control of computing devices and digital assets.

Innovation Solution

A computer-implemented method and system that determines risk assessments for online activities using a prediction model applied to data defining the activities, updating in-memory storage with risk scores and categories, and denying access to computing platforms when high-risk activities are detected, employing a risk analysis subsystem and access control module to block malicious access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If real-time risk assessment is performed for all online activities, then system security is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvesystem securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system pre-calculates and stores risk assessments in an in-memory cache before they are needed for actual access decisions. Risk assessments are computed in advance using prediction models and stored for rapid retrieval, eliminating the need to perform full risk calculations in real-time when access requests occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The risk assessment system is divided into distinct components: a prediction model for calculating risk scores, an in-memory cache for storing assessments, and a cache validation mechanism for ensuring data freshness. This segmentation allows each component to operate independently and optimally.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If comprehensive risk assessment data is stored in memory, then detection accuracy is improved, but memory usage and system resources increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidmemory usage
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system stores only the most critical risk assessment data in the in-memory cache rather than maintaining complete historical records. By storing partial risk assessment information that is most relevant for real-time decision-making, the system achieves high detection accuracy while limiting memory consumption to essential data only.

Inventive Principle:
Principle #16Partial or excessive action

3Speed

If risk assessments are cached in memory, then access speed is improved, but data freshness and reliability may deteriorate

Engineering Contradiction:
Improveaccess speedVSAvoiddata freshness
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system implements a cache validation mechanism that continuously monitors and verifies the freshness of cached risk assessments. When accessing cached data, the system validates whether the assessment is still current and reliable, providing feedback to determine whether to use the cached value or recalculate the risk assessment.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12259986B2Detection and mitigation of high-risk online activity in a computing platform
Publication Date: 2025.03.25 QLIK TECH INTERNATIONAL AB
  • US12259986B2 patent drawing
  • US12259986B2 patent drawing
  • US12259986B2 patent drawing

AI summary

Technologies are provided for detection and mitigation of high-risk online activity. The detection and mitigation can be implemented in real-time. In some embodiments, a computing system can determine that a risk assessment for an online activity is unavailable from an in-memory storage. The computing system can obtain the risk assessment for the online activity from a second computing system configured to apply a prediction model to data defining the online activity. The risk assessment can comprise a risk score and a risk category. The computing system can update the in-memory storage to incorporate the data and the risk assessment, and can determine that the risk assessment is indicative of the online activity being high-risk activity. The computing system can then cause denial of access to a computing platform to a user device associated with the online activity.