Risk-Based Data Priority Scoring for Unknown Host Identifiers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network monitoring and information management systems inaccurately assign risk-based priority scores, leading to alarm fatigue and missed threats due to assigning lower scores when identifiers lack known risk levels, resulting in inefficient and ineffective threat prioritization.
Innovation Solution
A processing platform that parses host identifiers from data, retrieves relative risk or threat levels from known host records, and generates RBP scores by combining or substituting levels when identifiers are unknown, ensuring accurate prioritization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing products assign higher RBP scores to reduce false negatives, then fewer important events are missed, but alarm fatigue increases and personnel cannot adequately address all alarms
Solution Approach 1:
The system dynamically adjusts RBP score parameters based on multiple factors including event characteristics, host risk levels, and contextual information. By changing the scoring parameters adaptively rather than using fixed thresholds, the system optimizes the balance between detecting all important events and maintaining manageable alarm volumes for personnel.
Solution Approach 2:
The patent replaces manual risk assessment with an automated computational system that uses algorithms to calculate RBP scores. This substitution of mechanical human judgment with an automated system enables consistent, scalable scoring that can handle high volumes of events without contributing to alarm fatigue.
2Ease of manufacture
If existing products assign a value of zero for unknown identifiers, then the calculation is simplified, but the RBP scores become artificially lower and dangerous threats may go unnoticed
Solution Approach 1:
The system performs preliminary actions by maintaining a database of known host identifiers with pre-assigned risk levels before processing new events. When an identifier is encountered, the system first checks this database to retrieve established risk levels, avoiding the need to calculate from scratch and ensuring accurate scores are used immediately.
Solution Approach 2:
The patent introduces an intermediary mechanism—a database of known host risk levels—that bridges the gap between unknown identifiers and accurate risk scoring. Instead of directly assigning zero to unknown identifiers, the system uses this intermediary database to retrieve or infer appropriate risk levels, thereby maintaining measurement precision while managing calculation complexity.
3Reliability
If existing products assign higher RBP scores to unknown identifiers to compensate for lack of information, then fewer threats are missed, but the scores may be overly conservative and reduce prioritization accuracy
Solution Approach 1:
The system applies partial action by assigning default risk levels only when necessary (when identifiers are truly unknown), rather than always using conservative defaults. When information is available in the known hosts database, the system uses that precise information. This partial application of conservative scoring maintains detection coverage without sacrificing prioritization accuracy for well-known identifiers.
Data Source
AI summary
Utilities (e.g., methods, systems, apparatuses, etc.) for use in generating and making use of priority scores for data generated by one or more data systems that more accurately prioritize those events and other pieces of data to be addressed by analysts and troubleshooters before others (e.g., collectively taking into account threats posed by origin host components and risks to impacted host components) to work the highest risk events and alarms first and to effectively and efficiently spend their alarm monitoring time.


