Security Intelligence Automation Platform Using Visual Flow Interfaces

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional information security frameworks face challenges in accurately detecting threats due to high false negatives and false positives, leading to resource-intensive and ineffective threat detection processes.

Innovation Solution

A security intelligence automation platform that automates threat detection and alert triaging by segmenting and scoring event data along multiple dimensions, using techniques like clustering, correlation, and mapping, to prioritize true threats and de-prioritize false alarms, utilizing a graphical user interface for visual flow representation and machine learning for improved scoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional monitoring techniques are used for threat detection, then the system can detect potential threats, but the detection accuracy is low with high false negatives and false positives

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidfalse positive rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent segments event data into multiple dimensions (e.g., source, destination, protocol, time) and applies separate scoring rules to each dimension. This segmentation allows for more precise threat detection by evaluating different aspects of events independently and combining their scores, thereby reducing both false negatives and false positives while improving overall detection accuracy.

Inventive Principle:
Principle #1Segmentation

2Productivity

If conventional threat detection processes are used, then threats can be detected, but the process is resource-intensive and inefficient

Engineering Contradiction:
Improvethreat detection efficiencyVSAvoidcomputational resources
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent applies local quality by assigning different scoring weights and rules to different dimensions of event data based on their specific threat indicators. Instead of uniformly processing all events with the same computational intensity, the system selectively applies scoring rules to relevant dimensions, reducing unnecessary computational overhead while maintaining high detection efficiency.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If security analysts manually review all alerts, then true threats can be identified, but the process is time-consuming and delays threat response

Engineering Contradiction:
Improvethreat identification accuracyVSAvoidmean time to identify threats
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent transforms the threat detection process by changing parameters from manual review to automated multi-dimensional scoring. The system calculates composite scores based on multiple dimensions and scoring rules, automatically prioritizing true threats and filtering false positives. This parameter change dramatically reduces the mean time to identify threats while maintaining high accuracy through the structured scoring framework.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If comprehensive event data analysis is performed, then more threats can be detected, but the complexity of the detection system increases

Engineering Contradiction:
Improvethreat detection coverageVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent addresses system complexity by organizing comprehensive event data analysis into multiple independent dimensions (source, destination, protocol, time, etc.), each with its own scoring rules. This dimensional organization allows the system to handle complex analysis tasks in a structured, modular way, improving threat detection coverage while managing system complexity through clear separation of analysis dimensions and their corresponding rules.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10735272B1Graphical user interface for security intelligence automation platform using flows
Publication Date: 2020.08.04 LOGICHUB INC
  • US10735272B1 patent drawing
  • US10735272B1 patent drawing
  • US10735272B1 patent drawing

AI summary

A system for security intelligence automation using flows is disclosed. In various embodiments, a system includes a processor configured to provide a graphical user interface for at least one visual flow for threat ranking. The processor is further configured to render, in the graphical user interface, a visual flow interface for at least one of generating and configuring the at least one visual flow. The processor is further configured to provide, via the visual flow interface, a drag and drop ranking automation flow.