Security Intelligence Automation Platform for Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional information security frameworks are resource-intensive and ineffective in accurately detecting threats due to high false positives and false negatives, overwhelming analysts and potentially missing security breaches.

Innovation Solution

A security intelligence automation platform that automates threat detection and triage using a visual flow interface, enabling efficient segmentation, scoring, and prioritization of event data to identify true threats and de-prioritize false alarms, leveraging techniques like threat hunting, clustering, correlation, and mapping.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional monitoring techniques are used to detect threats, then security coverage is provided, but detection accuracy is low and false positives/negatives are high

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidfalse positive rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent segments event data into multiple dimensions (entity, action, target, etc.) and creates separate scoring rules for each dimension. This segmentation allows the system to evaluate different aspects of security events independently and combine them for comprehensive threat assessment, improving detection accuracy while reducing false positives through multi-faceted analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameters of threat detection by introducing dimensional scoring where events are evaluated across multiple parameters (entity type, action type, target type, source reputation, etc.) rather than using single-threshold rules. This parameter-based approach enables more nuanced threat detection and reduces both false positives and false negatives.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If conventional security monitoring is implemented, then basic threat detection is achieved, but resource consumption is high and analyst workload is overwhelming

Engineering Contradiction:
Improvesecurity analysis efficiencyVSAvoidcomputational resource consumption
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent applies partial action by not requiring complete analysis of all security events. Instead, it scores events across multiple dimensions and prioritizes those with higher overall scores or specific critical dimension scores. This allows the system to focus computational resources on the most suspicious events rather than analyzing every event in detail, reducing resource consumption while maintaining detection effectiveness.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs self-service through automated dimensional scoring and event prioritization. The scoring rules automatically evaluate events across multiple dimensions and generate priority rankings without requiring manual analyst intervention for each event. This automation reduces both computational overhead and analyst workload.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If comprehensive event monitoring is performed, then all security events are captured, but noise and false alarms increase

Engineering Contradiction:
Improvethreat identification accuracyVSAvoidsignal-to-noise ratio
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent introduces dimensional scoring as an intermediary layer between raw event data and threat identification. Instead of directly analyzing all events, the system first scores events across multiple dimensions (entity, action, target, source, etc.) and uses these scores as intermediaries to prioritize and filter events. This intermediary scoring mechanism separates signal from noise by highlighting events with suspicious patterns across multiple dimensions while suppressing benign events.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10666666B1Security intelligence automation platform using flows
Publication Date: 2020.05.26 LOGICHUB INC
  • US10666666B1 patent drawing
  • US10666666B1 patent drawing
  • US10666666B1 patent drawing

AI summary

A system for security intelligence automation using flows is disclosed. In various embodiments, a system includes a communications interface configured to receive events. The system includes a processor configured to select event data associated with the events, where the event data is associated with a computer network environment. The processor may be further configured to segment the event data along a plurality of dimensions, score the event data along the plurality of dimensions, and generate a ranking of each of the events based at least in part on the scoring of the event data.