SIOM-Based Intrusion Detection for Enterprise Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise systems face ongoing challenges in maintaining security due to hackers consistently finding new ways to breach systems, particularly in financial transactions, where consumer identity and credit card details are at risk, and existing security measures are often ineffective against network-based attacks.

Innovation Solution

An automated intrusion detection and remediation system that uses a Secure Input/Output Module (SIOM) to monitor and securely communicate with peripheral devices, employing heuristic algorithms to identify patterns and trigger real-time actions for security threats, with a broader focus on network and terminal host information, and secure session integrity to prevent data alteration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures are deployed to protect enterprise systems, then security coverage is improved, but hackers can quickly figure out new ways to breach systems

Engineering Contradiction:
Improvesecurity coverageVSAvoidadaptability to new attack methods
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security system dynamically adapts its behavior based on real-time analysis of system events and patterns. The heuristic algorithms continuously learn from new attack patterns and adjust security policies automatically, allowing the system to evolve its defense strategies without manual intervention and stay ahead of emerging threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements continuous feedback loops where security events are monitored, analyzed, and used to automatically adjust security policies. The heuristic algorithms analyze patterns in security events and feed this information back into the system to improve detection and response capabilities, creating a self-improving security mechanism.

Inventive Principle:
Principle #23Feedback

2Difficulty of detecting and measuring

If more security monitoring and detection mechanisms are implemented, then detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The security system performs self-analysis and self-adjustment through automated heuristic algorithms that independently evaluate security events and modify security policies without requiring complex external management infrastructure. The system serves itself by automatically learning from patterns and adapting its own configuration.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The heuristic algorithms serve multiple functions simultaneously: they detect anomalies, analyze patterns, generate security policies, and adjust system configuration. This multi-functionality consolidates what would otherwise require multiple separate complex systems into a single integrated security platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Speed

If automated response actions are triggered based on detected patterns, then response speed is improved, but false positive risk increases

Engineering Contradiction:
Improveresponse speedVSAvoidfalse positive rate
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system performs preliminary analysis of security events against established patterns and heuristics before triggering automated responses. By pre-configuring heuristic rules and patterns that represent known attack behaviors, the system can quickly match incoming events against these pre-analyzed criteria, enabling fast response while maintaining accuracy through pre-validated detection logic.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9967270B2Enterprise intrusion detection and remediation
Publication Date: 2018.05.08 NCR VOYIX CORP
  • US9967270B2 patent drawing
  • US9967270B2 patent drawing
  • US9967270B2 patent drawing

AI summary

Events are securely packaged and transmitted from peripherals of terminals and from secure input/out modules (SIOMs) of terminals. The events are collected and mined in real time for security risk patterns and dynamic remedial actions are pushed back down to the terminals, peripherals, and SIOMs.