Predicting Security Communications via Activity Token Sequences

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data storage systems fail to effectively detect and manage security breaches, particularly those involving complex, time-dependent events or multiple malicious entities, as they lack context and pattern analysis over time, leading to delayed or missed breach detections.

Innovation Solution

The system employs machine learning models, such as vector encoding and contrastive learning models, to translate sequences of user activities into predicted communications, enabling early detection and contextual understanding of security breaches by generating time-ordered sequences of tokens and converting them into natural language predictions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional rule-based detection algorithms are used to evaluate user account history for security breaches, then the system can detect obvious security events, but it fails to account for larger scale patterns in user activity over time and misses complex, time-dependent breach events

Engineering Contradiction:
Improvebreach detection accuracyVSAvoidpattern analysis capability
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent transforms the detection approach by changing parameters from simple rule-based criteria to machine learning models that analyze temporal patterns and sequences of user activities. The system uses contrastive learning models to process activity sequences and predict user communications, enabling detection of complex breach patterns that conventional algorithms miss.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces mechanical rule-based detection systems with machine learning-based predictive systems. Instead of evaluating activities against fixed criteria, the system uses trained models to predict user communications and detect breaches based on learned patterns from historical data, substituting rigid mechanical evaluation with adaptive intelligent analysis.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If the system monitors all user activities in detail to detect security breaches early, then detection accuracy improves, but the computational resources and system complexity increase

Engineering Contradiction:
Improvesecurity breach detection reliabilityVSAvoidcomputational energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the most relevant features and patterns from user activity data for analysis. Instead of processing all raw activity data, the system uses machine learning models to identify and extract meaningful patterns that indicate security breaches, reducing computational overhead while maintaining detection reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs partial analysis by focusing on specific temporal patterns and activity sequences that are most indicative of security breaches. Rather than exhaustively analyzing every possible aspect of user activity, the model concentrates computational resources on the most informative signals for breach detection.

Inventive Principle:
Principle #16Partial or excessive action

3Difficulty of detecting and measuring

If conventional detection systems flag unexpected IP address changes as potential breaches, then some security events are detected, but the system lacks contextual understanding and generates false positives without user perspective

Engineering Contradiction:
Improvesecurity event identificationVSAvoiduser context information
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of information

Solution Approach 1:

The patent implements feedback loops where the system continuously learns from user communications and adjusts its detection patterns. By monitoring actual user responses and communications related to security events, the system refines its understanding of normal versus anomalous behavior, reducing false positives and improving contextual accuracy over time.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system uses machine learning models as intermediaries between raw activity data and security conclusions. These models translate complex activity patterns into meaningful security assessments, bridging the gap between raw data and contextual understanding without requiring direct human interpretation of every event.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Loss of time

If the system uses machine learning models to predict user communications based on activity sequences, then early breach detection is achieved, but the device complexity and implementation difficulty increase

Engineering Contradiction:
Improvebreach detection timeVSAvoidmachine learning system complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by training machine learning models in advance on historical activity data and user communications. The models are pre-trained to recognize breach patterns before actual security events occur, enabling rapid prediction and detection when real-time activities are analyzed, thus reducing detection time without adding runtime complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250021658A1Systems and methods for predicting security communications based on sequences of system activity tokens
Publication Date: 2025.01.16 CAPITAL ONE SERVICES LLC
  • US20250021658A1 patent drawing
  • US20250021658A1 patent drawing
  • US20250021658A1 patent drawing

AI summary

Systems and methods for generating communications based on user account activity data are described herein. For example, the system may receive an input activity log and generate a plurality of tokens. The system may generate a time-ordered sequence of tokens based on the plurality of tokens. The system may generate an output vector encoding based on a machine learning model. The system may generate a predicted communication based on a vector encoding model. The system may transmit the predicted communication to a user device.