Security Risk Prioritization via Normality Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cybersecurity experts face challenges in identifying and prioritizing security risks due to the overwhelming amount of data from diverse sources, lacking a unified platform to analyze and correlate data for user credential and malware threats across large organizations.
Innovation Solution
A method performing normality analysis on security threat events by comparing event data with historical parameters, using machine-executable processes to collect and analyze data from various sources, and applying machine learning to identify and prioritize security risks, including credential and application threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple different tools and processes are used to provide cyber attack prevention and detection, then comprehensive security coverage is achieved, but data complexity and analysis difficulty increase
Solution Approach 1:
The patent combines data from multiple diverse security sources (endpoint protection, network security, cloud security, identity management) into a unified data model with standardized schemas. This allows comprehensive security coverage while reducing data complexity through consistent data representation and correlation rules.
Solution Approach 2:
The patent creates a universal security risk scoring system that can analyze and prioritize risks from multiple different security tools and processes. The unified interface and common data model enable the system to handle diverse security data sources through a single analytical framework.
2Measurement precision
If comprehensive event data is collected from multiple sources, then security risk identification accuracy improves, but processing time and computational resources increase
Solution Approach 1:
The patent pre-defines correlation rules, risk scoring models, and event relationships before security incidents occur. Historical security data is used to establish baseline behaviors and threat patterns in advance, enabling faster real-time analysis when actual security events are detected.
Solution Approach 2:
The patent replaces manual or traditional sequential analysis methods with machine learning models and automated correlation engines. These systems process comprehensive security data in parallel, significantly reducing processing time while maintaining or improving risk identification accuracy.
3Ease of operation
If traditional security analysis methods are used, then implementation simplicity is maintained, but ability to prioritize risks based on organizational context is reduced
Solution Approach 1:
The patent introduces contextual parameters (organizational asset criticality, threat likelihood, impact severity) that can be adjusted based on specific organizational needs. The risk scoring model dynamically weights different factors according to organizational context, providing both ease of operation through automation and adaptability to different security environments.
4Loss of energy
If manual analysis of security events is performed, then resource requirements are reduced, but productivity and speed of risk identification decrease
Solution Approach 1:
The patent implements self-learning machine learning models that automatically improve their risk detection capabilities by analyzing historical security data and identified threats. The system autonomously updates correlation rules and risk scoring parameters without requiring proportional increases in human analytical resources, maintaining low computational overhead while improving productivity.
Data Source
AI summary
A method of identifying security risks in a computer system that includes several computers executing different applications is provided. The method receives event data about threat events associated with a set of applications executing on a set of computers in the computer system. The method, for each event, compares a set of parameters associated with the event with a set of historical parameters maintained for a similar event. The method, based on the comparisons, defines a normality characterization for each event to express a probability of an exploit of the application associated with the event. The method, based on the normality characterization, defines a prioritized display of security risks due to the threat events associated with the set of application.


