Runtime Risk Detection via Action Sequence Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security programs are ineffective in detecting and preventing advanced persistent threats (APT), which can go undetected and cause significant harm to systems and individuals by compromising proprietary information and leading to identity theft.

Innovation Solution

A system and method for assessing runtime risk that includes a rules database, a policy database, and a processing device to identify specific threats by analyzing action sequences of user, application, and system actions, predicting potential threats, and assigning a behavior score based on identified risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security programs (antivirus, firewalls, IDS/IPS) are used, then basic security protection is provided, but advanced persistent threats remain undetected

Engineering Contradiction:
Improvedetection capabilityVSAvoidthreat coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adjusts security assessment by continuously monitoring action sequences and updating risk scores in real-time. The runtime risk assessment engine dynamically evaluates the correlation between user, application, and system actions to adapt to evolving threats, moving from static signature-based detection to dynamic behavior-based detection that can respond to advanced persistent threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a new dimension of analysis by examining sequences of actions across multiple layers (user actions, application actions, system actions) rather than analyzing individual events in isolation. This multi-dimensional approach to correlating action sequences enables the detection of sophisticated APTs that would evade traditional single-layer security programs.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If action sequence analysis is implemented to detect APTs, then threat detection accuracy improves, but system complexity increases

Engineering Contradiction:
Improvethreat identification accuracyVSAvoidsystem architecture complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the complex task of threat detection into distinct components: a rules database storing action sequence patterns, a policy database containing assessment policies, and a runtime risk assessment engine that correlates actions. This segmentation allows each component to specialize in specific functions, managing overall system complexity while achieving high detection precision through coordinated operation of these modular elements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary databases (rules database and policy database) that mediate between raw action data and threat detection decisions. These intermediary structures store pre-defined patterns and policies, reducing the computational complexity of real-time analysis by filtering and structuring data before final threat assessment, thereby balancing precision with manageable system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If runtime risk assessment is performed continuously, then real-time threat detection is achieved, but processing resources are consumed

Engineering Contradiction:
Improvedetection response timeVSAvoidprocessing resource consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system applies partial action by focusing computational resources on assessing specific action sequences that match patterns in the rules database, rather than analyzing every single system event with equal depth. The runtime risk assessment engine selectively correlates actions based on predefined policies, performing detailed analysis only when relevant patterns are detected, thus achieving real-time detection while optimizing resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8850517B2Runtime risk detection based on user, application, and system action sequence correlation
Publication Date: 2014.09.30 TAASERA LICENSING LLC
  • US8850517B2 patent drawing
  • US8850517B2 patent drawing
  • US8850517B2 patent drawing

AI summary

A method for assessing runtime risk for an application or device includes: storing, in a rules database, a plurality of rules, wherein each rule identifies an action sequence; storing, in a policy database, a plurality of assessment policies, wherein each assessment policy includes at least one rule of the plurality of rules; identifying, using at least one assessment policy, a runtime risk for an application or device, wherein the identified runtime risk identifies and predicts a specific type of threat; and identifying, by a processing device, a behavior score for the application or device based on the identified runtime risk, wherein the action sequence is a sequence of at least two performed actions, and each performed action is at least one of: a user action, an application action, and a system action.