Threat Correlation Engine Dynamic Risk Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems rely on binary risk scoring methods that fail to detect real attacks below a set threshold, leading to undetected vulnerabilities and potential losses.
Innovation Solution
A network protection system with monitoring and interdiction agents, utilizing a threat correlation device that updates risk scores based on event types and occurrences, triggering protective actions when scores reach a critical threshold, and includes a risk scoring database to quantify threat levels and minimize false positives.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a high threshold score is set for reporting attacks to avoid false alarms, then false positives are reduced, but real attacks below the threshold go undetected
Solution Approach 1:
The patent transforms the binary pass/fail scoring system into a multi-dimensional risk scoring system that continuously updates risk scores based on event frequency, severity, and patterns. This allows the system to detect subtle attacks that would fall below a fixed threshold while maintaining reliability through dynamic adjustment rather than static parameters.
Solution Approach 2:
The patent adds temporal and contextual dimensions to threat detection by tracking risk scores over time and analyzing event patterns. Instead of a single threshold check, the system evaluates multiple dimensions including event frequency, severity weighting, and temporal patterns, enabling detection of low-scoring attacks that exhibit suspicious patterns across multiple dimensions.
2Ease of operation
If binary pass/fail scoring is used to simplify security assessment, then the system is easier to operate, but it lacks the richness to describe fluid security risk levels
Solution Approach 1:
The patent implements dynamic risk scoring where scores are continuously updated based on new events, event frequencies, and severity weights. The system adapts to changing threat landscapes by automatically adjusting risk levels rather than relying on static classifications, providing both operational simplicity and descriptive richness.
Solution Approach 2:
The patent segments the risk assessment into multiple independent factors including event type, frequency, severity, and temporal patterns. Each factor contributes to the overall risk score, allowing the system to maintain simplicity through modular processing while achieving versatility through the combination of multiple segmented assessments.
3Reliability
If existing security measures are implemented to prevent attacks, then some threats are blocked, but sophisticated attacks can still bypass these measures
Solution Approach 1:
The patent implements continuous feedback loops where risk scores are updated based on incoming events and their outcomes. The system learns from patterns in the data, adjusting risk assessments in real-time based on feedback from monitoring agents and interdiction results, enabling it to adapt to sophisticated attacks that evolve over time.
Solution Approach 2:
The patent performs preliminary risk assessment and scoring before attacks fully execute, allowing the system to identify and mitigate threats in advance. By continuously monitoring and scoring potential attacks based on their characteristics and patterns, the system can take preventive action before sophisticated attacks cause harm.
Data Source
AI summary
A network protection system and method for processing of network traffic between one or more networked devices. The network protection system may include the networked devices and a threat correlation device. The networked devices may operate as a monitoring agent and/or an interdiction agent. The threat correlation device may execute computer code for receiving information from the monitoring agent regarding an event recognized by the monitoring agent, retrieving an event score for the event from a risk scoring database based on an event type, a destination of the event, and a number of occurrences of the event, and updating a risk score by adding the event score to the risk score. When the risk score reaches a critical threshold, the threat correlation device may send instructions to the interdiction agent to take protective or defensive action against data traffic of that event type and from that aggressor.


