Threat Correlation Engine Dynamic Risk Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems rely on binary risk scoring methods that fail to detect real attacks below a set threshold, leading to undetected vulnerabilities and potential losses.

Innovation Solution

A network protection system with monitoring and interdiction agents, utilizing a threat correlation device that updates risk scores based on event types and occurrences, triggering protective actions when scores reach a critical threshold, and includes a risk scoring database to quantify threat levels and minimize false positives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a high threshold score is set for reporting attacks to avoid false alarms, then false positives are reduced, but real attacks below the threshold go undetected

Engineering Contradiction:
Improvefalse positive rateVSAvoidattack detection capability
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent transforms the binary pass/fail scoring system into a multi-dimensional risk scoring system that continuously updates risk scores based on event frequency, severity, and patterns. This allows the system to detect subtle attacks that would fall below a fixed threshold while maintaining reliability through dynamic adjustment rather than static parameters.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent adds temporal and contextual dimensions to threat detection by tracking risk scores over time and analyzing event patterns. Instead of a single threshold check, the system evaluates multiple dimensions including event frequency, severity weighting, and temporal patterns, enabling detection of low-scoring attacks that exhibit suspicious patterns across multiple dimensions.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of operation

If binary pass/fail scoring is used to simplify security assessment, then the system is easier to operate, but it lacks the richness to describe fluid security risk levels

Engineering Contradiction:
Improvescoring system simplicityVSAvoidrisk description granularity
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic risk scoring where scores are continuously updated based on new events, event frequencies, and severity weights. The system adapts to changing threat landscapes by automatically adjusting risk levels rather than relying on static classifications, providing both operational simplicity and descriptive richness.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments the risk assessment into multiple independent factors including event type, frequency, severity, and temporal patterns. Each factor contributes to the overall risk score, allowing the system to maintain simplicity through modular processing while achieving versatility through the combination of multiple segmented assessments.

Inventive Principle:
Principle #1Segmentation

3Reliability

If existing security measures are implemented to prevent attacks, then some threats are blocked, but sophisticated attacks can still bypass these measures

Engineering Contradiction:
Improvethreat blocking effectivenessVSAvoidundetected attack impact
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements continuous feedback loops where risk scores are updated based on incoming events and their outcomes. The system learns from patterns in the data, adjusting risk assessments in real-time based on feedback from monitoring agents and interdiction results, enabling it to adapt to sophisticated attacks that evolve over time.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary risk assessment and scoring before attacks fully execute, allowing the system to identify and mitigate threats in advance. By continuously monitoring and scoring potential attacks based on their characteristics and patterns, the system can take preventive action before sophisticated attacks cause harm.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10122748B1Network protection system and threat correlation engine
Publication Date: 2018.11.06 INSCYT LLC
  • US10122748B1 patent drawing
  • US10122748B1 patent drawing
  • US10122748B1 patent drawing

AI summary

A network protection system and method for processing of network traffic between one or more networked devices. The network protection system may include the networked devices and a threat correlation device. The networked devices may operate as a monitoring agent and/or an interdiction agent. The threat correlation device may execute computer code for receiving information from the monitoring agent regarding an event recognized by the monitoring agent, retrieving an event score for the event from a risk scoring database based on an event type, a destination of the event, and a number of occurrences of the event, and updating a risk score by adding the event score to the risk score. When the risk score reaches a critical threshold, the threat correlation device may send instructions to the interdiction agent to take protective or defensive action against data traffic of that event type and from that aggressor.