Security Violation Assessment Tool Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional systems fail to accurately assess the threat posed by new system violations in light of existing violations, leading to potential security compromises and false positives, which can hinder authorized access and enhance unauthorized access.

Innovation Solution

A security violation assessment tool comprising a memory to store system violations, an identification engine to classify new violations, and an evaluation engine to compare new violations with existing ones, determining the threat level based on classifications and indications of previous deviations from user baselines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional systems assess new system violations in isolation without considering existing violations, then the assessment process is simple and fast, but the accuracy of threat detection is low leading to false positives and missed threats

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidassessment system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system pre-processes and stores classifications of existing system violations in a structured format before new violations occur. This preliminary organization of historical violation data enables the evaluation engine to efficiently retrieve and compare violations without performing complex real-time analysis, thus improving detection accuracy while maintaining operational simplicity

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The assessment system is divided into distinct functional components: an identification engine that classifies violations, a storage mechanism that organizes historical violations by classification, and an evaluation engine that compares new violations against stored patterns. This segmentation allows each component to specialize in specific tasks, improving overall accuracy without proportionally increasing complexity

Inventive Principle:
Principle #1Segmentation

2Reliability

If the system blocks all detected violations without accurate threat assessment, then system security is enhanced, but authorized access is hindered due to false positives

Engineering Contradiction:
Improvesystem securityVSAvoidauthorized access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system uses historical violation data as feedback to improve future threat assessments. By comparing new violations against a stored record of existing violations and their outcomes, the system learns to distinguish between genuine threats and false positives, thereby maintaining security while reducing unnecessary blocks on authorized access

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The evaluation engine dynamically adjusts assessment parameters based on the combination of violation classifications detected. Rather than applying fixed blocking rules, the system modifies its threat evaluation criteria according to the specific pattern of violations observed, allowing nuanced decisions that protect system security while permitting legitimate operations

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10122744B2Security violation assessment tool to compare new violation with existing violation
Publication Date: 2018.11.06 BANK OF AMERICA CORP
  • US10122744B2 patent drawing
  • US10122744B2 patent drawing
  • US10122744B2 patent drawing

AI summary

A method comprises receiving a notification of a new system violation and classifying, based on characteristics of the new system violation, the new system violation as one or more of: an access violation; a configurational violation; an unauthorized modification; a usage violation; and an unsecured surface violation. The method also comprises comparing the new system violation in combination with one or more of a plurality of existing system violations to a plurality of entries and determining, based on the comparison of the new system violation and the one or more plurality of existing system violations to the plurality of entries, whether the new system violation threatens the system.