Runtime Risk Detection via Action Sequence Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional security programs are ineffective in detecting and preventing advanced persistent threats (APT), which can go undetected and cause significant harm to systems and individuals by compromising proprietary information and leading to identity theft.
Innovation Solution
A system and method for assessing runtime risk that includes a rules database, a policy database, and a processing device to identify specific threats by analyzing action sequences of user, application, and system actions, predicting potential threats, and assigning a behavior score based on identified risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security programs (antivirus, firewalls, IDS/IPS) are used, then basic security protection is provided, but advanced persistent threats remain undetected
Solution Approach 1:
The system dynamically adjusts security assessment by continuously monitoring action sequences and updating risk scores in real-time. The runtime risk assessment engine dynamically evaluates the correlation between user, application, and system actions to adapt to evolving threats, moving from static signature-based detection to dynamic behavior-based detection that can respond to advanced persistent threats.
Solution Approach 2:
The patent introduces a new dimension of analysis by examining sequences of actions across multiple layers (user actions, application actions, system actions) rather than analyzing individual events in isolation. This multi-dimensional approach to correlating action sequences enables the detection of sophisticated APTs that would evade traditional single-layer security programs.
2Measurement precision
If action sequence analysis is implemented to detect APTs, then threat detection accuracy improves, but system complexity increases
Solution Approach 1:
The system segments the complex task of threat detection into distinct components: a rules database storing action sequence patterns, a policy database containing assessment policies, and a runtime risk assessment engine that correlates actions. This segmentation allows each component to specialize in specific functions, managing overall system complexity while achieving high detection precision through coordinated operation of these modular elements.
Solution Approach 2:
The patent introduces intermediary databases (rules database and policy database) that mediate between raw action data and threat detection decisions. These intermediary structures store pre-defined patterns and policies, reducing the computational complexity of real-time analysis by filtering and structuring data before final threat assessment, thereby balancing precision with manageable system complexity.
3Speed
If runtime risk assessment is performed continuously, then real-time threat detection is achieved, but processing resources are consumed
Solution Approach 1:
The system applies partial action by focusing computational resources on assessing specific action sequences that match patterns in the rules database, rather than analyzing every single system event with equal depth. The runtime risk assessment engine selectively correlates actions based on predefined policies, performing detailed analysis only when relevant patterns are detected, thus achieving real-time detection while optimizing resource consumption.
Data Source
AI summary
A method for assessing runtime risk for an application or device includes: storing, in a rules database, a plurality of rules, wherein each rule identifies an action sequence; storing, in a policy database, a plurality of assessment policies, wherein each assessment policy includes at least one rule of the plurality of rules; identifying, using at least one assessment policy, a runtime risk for an application or device, wherein the identified runtime risk identifies and predicts a specific type of threat; and identifying, by a processing device, a behavior score for the application or device based on the identified runtime risk, wherein the action sequence is a sequence of at least two performed actions, and each performed action is at least one of: a user action, an application action, and a system action.


