Security Intelligence Automation Platform Using Visual Flow Interfaces
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional information security frameworks face challenges in accurately detecting threats due to high false negatives and false positives, leading to resource-intensive and ineffective threat detection processes.
Innovation Solution
A security intelligence automation platform that automates threat detection and alert triaging by segmenting and scoring event data along multiple dimensions, using techniques like clustering, correlation, and mapping, to prioritize true threats and de-prioritize false alarms, utilizing a graphical user interface for visual flow representation and machine learning for improved scoring.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional monitoring techniques are used for threat detection, then the system can detect potential threats, but the detection accuracy is low with high false negatives and false positives
Solution Approach 1:
The patent segments event data into multiple dimensions (e.g., source, destination, protocol, time) and applies separate scoring rules to each dimension. This segmentation allows for more precise threat detection by evaluating different aspects of events independently and combining their scores, thereby reducing both false negatives and false positives while improving overall detection accuracy.
2Productivity
If conventional threat detection processes are used, then threats can be detected, but the process is resource-intensive and inefficient
Solution Approach 1:
The patent applies local quality by assigning different scoring weights and rules to different dimensions of event data based on their specific threat indicators. Instead of uniformly processing all events with the same computational intensity, the system selectively applies scoring rules to relevant dimensions, reducing unnecessary computational overhead while maintaining high detection efficiency.
3Measurement precision
If security analysts manually review all alerts, then true threats can be identified, but the process is time-consuming and delays threat response
Solution Approach 1:
The patent transforms the threat detection process by changing parameters from manual review to automated multi-dimensional scoring. The system calculates composite scores based on multiple dimensions and scoring rules, automatically prioritizing true threats and filtering false positives. This parameter change dramatically reduces the mean time to identify threats while maintaining high accuracy through the structured scoring framework.
4Reliability
If comprehensive event data analysis is performed, then more threats can be detected, but the complexity of the detection system increases
Solution Approach 1:
The patent addresses system complexity by organizing comprehensive event data analysis into multiple independent dimensions (source, destination, protocol, time, etc.), each with its own scoring rules. This dimensional organization allows the system to handle complex analysis tasks in a structured, modular way, improving threat detection coverage while managing system complexity through clear separation of analysis dimensions and their corresponding rules.
Data Source
AI summary
A system for security intelligence automation using flows is disclosed. In various embodiments, a system includes a processor configured to provide a graphical user interface for at least one visual flow for threat ranking. The processor is further configured to render, in the graphical user interface, a visual flow interface for at least one of generating and configuring the at least one visual flow. The processor is further configured to provide, via the visual flow interface, a drag and drop ranking automation flow.


