Statistical Security Model for Cross-Client Threat Propagation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information handling systems lack an efficient mechanism for automatically propagating supplementary intelligence across different client systems to enhance security event detection and response, particularly in identifying and mitigating malicious activities that may not be immediately recognized by individual IDS systems.

Innovation Solution

An information handling system with a processor that analyzes security alerts from one client system to build a statistical security model, which is then applied to logs from another client system to identify potential security events and classify malicious activity, leveraging supplementary indicators such as IP addresses and network activity patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual IDS systems use traditional signature-based detection, then they can identify known threats, but they fail to detect novel malicious activities without specific signatures

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary analysis of security alerts from multiple client systems to build statistical security models before actual threat detection. By pre-processing and pre-analyzing security data from diverse sources, the system prepares predictive models that can identify novel threats without requiring specific signatures, thus resolving the contradiction between reliable known-threat detection and versatile unknown-threat detection

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces statistical security models as an intermediary between raw security alerts and threat detection. These models act as mediators that transform and propagate supplementary intelligence across client systems, enabling the detection of malicious activities that individual IDS systems cannot identify alone, thereby enhancing both detection accuracy and coverage

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security intelligence is propagated across multiple client systems, then detection capability improves, but system complexity increases

Engineering Contradiction:
Improvesecurity event detectionVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements a universal statistical security model that serves multiple client systems simultaneously. This multi-functional approach allows the same model to analyze security alerts from different client systems and propagate supplementary intelligence across the network, improving security detection without requiring separate complex systems for each client

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges security intelligence from multiple client systems into a unified statistical security model. By combining security alerts and logs from diverse sources into a single analytical framework, the system achieves enhanced detection capability while avoiding the complexity of maintaining separate analysis systems for each client

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If the system analyzes security alerts from multiple client systems, then malicious activity identification improves, but processing time increases

Engineering Contradiction:
Improvethreat identification accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary analysis and builds statistical security models in advance, before actual threat detection is needed. By pre-processing security alerts and pre-computing statistical models from multiple client systems, the system reduces the time required for real-time threat identification while maintaining high accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by propagating supplementary intelligence and statistical models across client systems. Instead of each system performing complete independent analysis, the system copies and shares pre-processed security intelligence and statistical models, reducing redundant processing time while maintaining accurate threat identification

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10489720B2System and method for vendor agnostic automatic supplementary intelligence propagation
Publication Date: 2019.11.26 SECUREWORKS CORP
  • US10489720B2 patent drawing
  • US10489720B2 patent drawing
  • US10489720B2 patent drawing

AI summary

An information handling system includes a storage and a processor. The storage is configured to store network activity logs from a first client system and a second client system. The processor is configured to receive a security alert from the first client system, analyze the security alert to obtain a plurality of indicators, utilize the supplementary indicators to build a statistical security model, and analyze activity on the second client system using the statistical security model to identify an additional security events.