Intelligent Security Event Risk Scoring via User Feedback

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security systems rely on static rules to assess the severity of security-related events, which fail to adapt to changing environments and do not account for the specific implementation and usage of the system, leading to incorrect evaluations and increased costs.

Innovation Solution

An intelligent remediation system that uses a classifier to generate risk scores for security events, incorporating user feedback to learn and adjust its operation, allowing it to prioritize events based on learned riskiness and adapt to changing conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static rules are used to assess security event severity, then the system provides a perceived threat indication, but the system cannot adapt to changing environments and produces incorrect evaluations

Engineering Contradiction:
Improveadaptability to changing environmentVSAvoidaccuracy of risk assessment
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent implements dynamic risk scoring by transitioning from static rules to a machine learning classifier that continuously adapts to changing environments. The classifier learns from historical data and user feedback, dynamically adjusting risk scores based on patterns in the data rather than relying on fixed thresholds. This resolves the contradiction by making the system adaptable while maintaining or improving assessment accuracy through learned patterns.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops where user corrections and outcome data are fed back into the machine learning model to continuously improve risk scoring accuracy. This feedback mechanism allows the system to learn from mistakes and adapt to changing threat landscapes, simultaneously improving adaptability and measurement precision.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If custom fixes are implemented to address static rules limitations, then the system can handle specific cases, but the product cost and complexity increase

Engineering Contradiction:
Improvecustomization capabilityVSAvoidproduct complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the system to automatically adapt to custom environments through machine learning without requiring manual customization. The classifier autonomously learns organization-specific patterns from data and feedback, eliminating the need for expensive custom fixes while maintaining high adaptability. This reduces product complexity while preserving customization capability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes parameters dynamically through machine learning by adjusting risk score weights and thresholds based on learned patterns rather than using fixed parameters. This allows the system to adapt to different environments and requirements without requiring structural modifications or custom code, thereby reducing complexity while maintaining versatility.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If the system processes all reported events, then complete security coverage is achieved, but user resources are overwhelmed due to finite investigation capacity

Engineering Contradiction:
Improvesecurity coverageVSAvoidevent investigation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by differentiating risk assessment across individual events rather than applying uniform thresholds. The machine learning classifier assigns customized risk scores to each event based on its specific characteristics and learned patterns, allowing users to focus resources on high-risk events while maintaining reliable security coverage through prioritized processing.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs partial action by focusing user resources on the most critical events identified through improved risk scoring. Rather than requiring equal investigation of all events, the enhanced classification enables users to address the most significant threats first, improving productivity while maintaining overall security reliability through targeted response.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9548987B1Intelligent remediation of security-related events
Publication Date: 2017.01.17 EMC IP HLDG CO LLC
  • US9548987B1 patent drawing
  • US9548987B1 patent drawing
  • US9548987B1 patent drawing

AI summary

An information processing system implements an intelligent remediation system for security-related events. The intelligent remediation system comprises a classifier configured to process information characterizing the events in order to generate respective risk scores, and a data store coupled to the classifier and configured to store feedback from one or more users regarding the risk scores. The classifier is configured to utilize the feedback regarding the risk scores to learn riskiness of particular events and to adjust its operation based on the learned riskiness, such that the risk score generated by the classifier for a given one of the events is based at least in part on the feedback received regarding risk scores generated for one or more previous ones of the events. A user interface is provided to allow one or more users to supply the feedback regarding the risk scores.