Risk Score Assignment for Network Entity Subsets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern data centers face challenges in processing and indexing large volumes of machine-generated data due to its unstructured nature, making it difficult to apply semantic meaning and perform efficient searching operations.
Innovation Solution
A data aggregation and analysis system that evaluates triggering conditions applied to search results to assign risk scores to entities, optimizing processing by focusing on a subset of entities and creating a baseline behavior for peer groups, and using a graphical user interface to visually present risk scores for real-time monitoring and management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If monitoring and analyzing activity of all entities in a data center, then security coverage and detection capability are improved, but processing complexity and computational resources increase significantly
Solution Approach 1:
The patent divides entities into peer groups based on similar activity patterns and characteristics. Instead of treating all entities uniformly, the system segments them into manageable groups that can be analyzed collectively, reducing processing complexity while maintaining comprehensive security coverage across all entities.
Solution Approach 2:
The system creates baseline behavior profiles that represent typical activity patterns for each peer group. These baselines serve as templates that can be applied to multiple entities within the group, allowing the system to evaluate numerous entities against a single standardized model rather than analyzing each entity individually from scratch.
2Loss of information
If processing large volumes of unstructured machine-generated data, then data analysis completeness is improved, but processing time and computational resources increase
Solution Approach 1:
The system transforms unstructured machine-generated data into structured activity metrics by defining specific parameters and measurement criteria. This parameterization allows the system to process data efficiently by focusing on predetermined metrics rather than analyzing all raw data elements, reducing processing time while maintaining analysis completeness for critical security indicators.
Solution Approach 2:
The system pre-establishes baseline behavior profiles and evaluation criteria before actual security analysis begins. By preparing these reference models in advance, the system can quickly compare current entity activity against known patterns without performing complex analysis in real-time, significantly reducing processing time while maintaining thorough evaluation.
3Measurement precision
If applying comprehensive search operations to all data, then detection accuracy is improved, but processing efficiency decreases
Solution Approach 1:
The patent applies different analysis depths and evaluation strictness levels to different peer groups based on their risk profiles and characteristics. High-risk groups receive more rigorous analysis with stricter thresholds, while low-risk groups undergo lighter evaluation. This localized approach maintains high detection accuracy for critical threats while improving overall processing efficiency by not applying maximum scrutiny uniformly to all entities.
Data Source
AI summary
Systems and methods are disclosed for associating an entity with a risk score that may indicate a security threat associated with the entity's activity. An exemplary method may involve monitoring the activity of a subset of the set of entities (e.g., entities included in a watch list) by executing a search query against events indicating the activity of the subset of entities. The events may be associated with timestamps and may include machine data. Executing the search query may produce search results that pertain to activity of a particular entity from the subset. The search results may be evaluated based on a triggering condition corresponding to the statistical baseline. When the triggering condition is met, a risk score for the particular entity may be updated. The updated risk score may be displayed to a user via a graphical user interface (GUI).


