Sandbox-Based Cybersecurity Event Detector Modification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity event detection systems struggle to detect new types of events and may miss specific instances of known events, leading to inadequate reaction to cybersecurity threats due to limitations in their detection capabilities.

Innovation Solution

A method and apparatus for modifying cybersecurity event detectors in a sandbox environment to improve their effectiveness, involving the receipt of desired modifications, testing, and analysis of system events to determine true positives, false positives, and false negatives, with statistics being sent to client devices for display and potential implementation in production environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the cybersecurity event detector is modified to detect new types of events, then the detection capability is improved, but the false positive rate increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidfalse positive rate
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by testing modifications in a sandbox environment before deploying them to production. The system receives desired modifications, tests them against historical event data to evaluate performance metrics (including false positive rates), and only implements modifications that meet performance thresholds. This advance testing prevents harmful modifications from reaching the production detector.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by calculating performance metrics (true positives, false positives, false negatives) after testing modifications and using this feedback to determine whether to implement the modifications. The system continuously monitors detection effectiveness and adjusts the modification implementation decision based on measured performance, creating a closed-loop control system that balances detection capability with reliability.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If the cybersecurity event detector is continuously improved to detect specific instances of known events, then the detection precision is improved, but the system complexity increases

Engineering Contradiction:
Improvedetection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the system into distinct components: the production cybersecurity event detector, the sandbox environment for testing, and the modification management system. This segmentation allows continuous improvement of detection precision through controlled modifications in the sandbox without increasing the complexity of the production detector itself. The complex testing and evaluation logic is isolated in the sandbox environment.

Inventive Principle:
Principle #1Segmentation

3Reliability

If the sandbox environment is used to test modifications before production deployment, then the reliability of detection improvements is improved, but the time required for implementation increases

Engineering Contradiction:
Improvereliability of detection improvementsVSAvoidimplementation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by implementing a selective testing approach where not all modifications require full sandbox testing before deployment. The system can implement modifications with lower risk or those that meet predefined performance thresholds more quickly, while subjecting high-risk or high-impact modifications to more rigorous testing. This differentiated approach reduces overall implementation time while maintaining reliability for critical modifications.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20240311471A1Cybersecurity event detection system and method
Publication Date: 2024.09.19 PALANTIR TECHNOLOGIES INC
  • US20240311471A1 patent drawing
  • US20240311471A1 patent drawing
  • US20240311471A1 patent drawing

AI summary

A method, performed by one or more processors, includes: receiving an indication of a desired modification to a cybersecurity event detector that is being contemporaneously used for the detection of potential cybersecurity events in a production environment; modifying, in a sandbox environment, the cybersecurity event detector based on the indication of the desired modification to the cybersecurity event detector; and for each system event in a set of system events, determining, in the sandbox environment, whether the respective system event is indicative of a potential cybersecurity event using the modified cybersecurity event detector. Related apparatus are also disclosed.