Security Incident Prediction Using ML Classifiers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managed security services (MSS) clients often face difficulties in understanding which security products are necessary for their specific needs, as existing systems fail to clearly demonstrate the value of different security products and may not account for missing or corrupted telemetry data, leading to confusion and inadequate security measures.
Innovation Solution
A computer-implemented method and system that collects telemetry data from security products, identifies missing data, builds a classifier using machine learning to predict security incidents, and performs security actions to secure the client machine, thereby recommending appropriate security products and enhancing security incident detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple security products are deployed to protect against different types of attacks, then security coverage is improved, but client confusion increases due to difficulty in understanding which products are necessary
Solution Approach 1:
The system collects telemetry data from deployed security products and uses machine learning models to generate predictions about security incidents. These predictions are fed back to clients to demonstrate the actual value and effectiveness of each security product, enabling data-driven decisions about product deployment and helping clients understand which products are necessary for their specific needs
Solution Approach 2:
The patent introduces an intermediary system comprising telemetry data collection, machine learning modeling, and prediction generation components. This intermediary processes raw security data and translates it into actionable insights about product effectiveness, bridging the gap between complex security product operations and client understanding
2Measurement precision
If security telemetry data is collected from multiple products to analyze effectiveness, then prediction accuracy is improved, but data completeness deteriorates due to missing or corrupted data
Solution Approach 1:
The system anticipates the problem of missing or corrupted telemetry data by implementing machine learning models specifically trained to handle incomplete data scenarios. These models are prepared in advance to compensate for data gaps, ensuring that prediction accuracy is maintained even when telemetry data is not fully complete
Solution Approach 2:
The patent uses machine learning models to create predictive copies of security incident patterns based on available telemetry data from multiple security products. These predictive models replicate security incident behaviors and can infer missing information, allowing the system to maintain accurate predictions despite incomplete original data
3Adaptability or versatility
If security products are recommended based on comprehensive analysis, then product value demonstration is improved, but system complexity increases due to multiple products and rules
Solution Approach 1:
The system extracts and isolates the core predictive functionality into separate machine learning models that analyze telemetry data from individual security products. By separating the analysis of each product's effectiveness into distinct models, the system manages complexity while maintaining comprehensive analysis capabilities for personalized product recommendations
Data Source
AI summary
A computer-implemented method for predicting security incidents triggered by security software may include (i) collecting, by a computing device, telemetry data from a set of security products deployed by a set of client machines, (ii) identifying, by the computing device, a selected security product within the set of security products that is missing telemetry data for a target client machine, (iii) building a classifier, by the computing device using the telemetry data, that predicts information about security incidents triggered by the selected security product, (iv) determining, by the computing device and based on the classifier, that the selected security product triggers a new security incident on the target client machine, and (v) performing a security action, by the computing device, to secure the target client machine against the new security incident. Various other methods, systems, and computer-readable media are also disclosed.


