Intelligent Security Event Risk Scoring via User Feedback
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security systems rely on static rules to assess the severity of security-related events, which fail to adapt to changing environments and do not account for the specific implementation and usage of the system, leading to incorrect evaluations and increased costs.
Innovation Solution
An intelligent remediation system that uses a classifier to generate risk scores for security events, incorporating user feedback to learn and adjust its operation, allowing it to prioritize events based on learned riskiness and adapt to changing conditions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If static rules are used to assess security event severity, then the system provides a perceived threat indication, but the system cannot adapt to changing environments and produces incorrect evaluations
Solution Approach 1:
The patent implements dynamic risk scoring by transitioning from static rules to a machine learning classifier that continuously adapts to changing environments. The classifier learns from historical data and user feedback, dynamically adjusting risk scores based on patterns in the data rather than relying on fixed thresholds. This resolves the contradiction by making the system adaptable while maintaining or improving assessment accuracy through learned patterns.
Solution Approach 2:
The system incorporates feedback loops where user corrections and outcome data are fed back into the machine learning model to continuously improve risk scoring accuracy. This feedback mechanism allows the system to learn from mistakes and adapt to changing threat landscapes, simultaneously improving adaptability and measurement precision.
2Adaptability or versatility
If custom fixes are implemented to address static rules limitations, then the system can handle specific cases, but the product cost and complexity increase
Solution Approach 1:
The patent implements self-service by enabling the system to automatically adapt to custom environments through machine learning without requiring manual customization. The classifier autonomously learns organization-specific patterns from data and feedback, eliminating the need for expensive custom fixes while maintaining high adaptability. This reduces product complexity while preserving customization capability.
Solution Approach 2:
The system changes parameters dynamically through machine learning by adjusting risk score weights and thresholds based on learned patterns rather than using fixed parameters. This allows the system to adapt to different environments and requirements without requiring structural modifications or custom code, thereby reducing complexity while maintaining versatility.
3Reliability
If the system processes all reported events, then complete security coverage is achieved, but user resources are overwhelmed due to finite investigation capacity
Solution Approach 1:
The patent applies local quality by differentiating risk assessment across individual events rather than applying uniform thresholds. The machine learning classifier assigns customized risk scores to each event based on its specific characteristics and learned patterns, allowing users to focus resources on high-risk events while maintaining reliable security coverage through prioritized processing.
Solution Approach 2:
The system performs partial action by focusing user resources on the most critical events identified through improved risk scoring. Rather than requiring equal investigation of all events, the enhanced classification enables users to address the most significant threats first, improving productivity while maintaining overall security reliability through targeted response.
Data Source
AI summary
An information processing system implements an intelligent remediation system for security-related events. The intelligent remediation system comprises a classifier configured to process information characterizing the events in order to generate respective risk scores, and a data store coupled to the classifier and configured to store feedback from one or more users regarding the risk scores. The classifier is configured to utilize the feedback regarding the risk scores to learn riskiness of particular events and to adjust its operation based on the learned riskiness, such that the risk score generated by the classifier for a given one of the events is based at least in part on the feedback received regarding risk scores generated for one or more previous ones of the events. A user interface is provided to allow one or more users to supply the feedback regarding the risk scores.


