Sensor-Based Rules for Malicious Activity Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems for computer networks lack effective mechanisms to dynamically respond to and manage malicious activity, as they often require manual intervention and are not optimized for real-time detection and mitigation of threats.

Innovation Solution

The system employs sensor-based rules that can be created and managed to detect and mitigate malicious activity by extracting indicators from evidence of suspicious activity, linking them to actors, and tasking sensors to take appropriate actions, ensuring compliance with vendor-specific syntax and best practices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual review of malicious activity evidence is used, then security analysis accuracy is improved, but response time and productivity deteriorate

Engineering Contradiction:
Improvesecurity analysis accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent introduces sensor-based rules as an intermediary mechanism between malicious activity detection and manual analysis. These rules automatically process indicators (IP addresses, domains, file hashes) extracted from evidence, performing initial filtering, classification, and response actions. This intermediary layer handles routine tasks, allowing human analysts to focus on complex cases while maintaining high-speed automated response for standard threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service through automated rule execution. When indicators are extracted from evidence, the sensor-based rules automatically trigger appropriate responses (blocking, alerting, investigation) without requiring manual intervention for each incident. The rules serve themselves by continuously monitoring and reacting to new indicators, reducing the burden on security personnel while maintaining consistent response quality.

Inventive Principle:
Principle #25Self-service

2Reliability

If comprehensive security monitoring is implemented, then detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security monitoring system into distinct modular components: evidence collection modules, indicator extraction modules, sensor-based rule modules, and response execution modules. Each component has a specific function and can be independently configured and managed. This segmentation allows comprehensive monitoring capabilities to be built from simple, well-defined units, reducing overall system complexity while maintaining high detection capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The sensor-based rules serve multiple functions simultaneously: they detect malicious indicators, classify threats by type and severity, trigger appropriate responses, and generate reports. This multi-functionality reduces the need for separate specialized systems for each security task, simplifying the overall architecture while maintaining comprehensive detection and response capabilities across multiple threat vectors.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If automated response actions are implemented, then response speed is improved, but risk of false positives increases

Engineering Contradiction:
Improveresponse speedVSAvoidfalse positive rate
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The sensor-based rules are designed to be dynamic and configurable, allowing response thresholds, sensitivity levels, and action criteria to be adjusted based on organizational risk tolerance and threat landscape. The rules can be enabled or disabled, modified, or tuned without system reconfiguration, allowing the automated response system to adapt to reducing false positives while maintaining rapid response capability for confirmed threats.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10505986B1Sensor based rules for responding to malicious activity
Publication Date: 2019.12.10 ANALYST PLATFORM LLC
  • US10505986B1 patent drawing
  • US10505986B1 patent drawing
  • US10505986B1 patent drawing

AI summary

Systems and techniques are provided for creating sensor based rules for detecting and responding to malicious activity. Evidence corresponding to a malicious activity is received. The evidence corresponding to malicious activity is analyzed. Indicators are identified from the evidence. The indicators are extracted from the evidence. It is determined that an action to mitigate or detect a threat needs to be taken based on the indicators and evidence. A sensor to employ the prescribed action is identified. Whether a sensor based rule meets a threshold requirement is validated. A configuration file used to task the sensor based rule to the identified sensor is created. The number of sensor based rule triggers is tracked.