Threat Mitigation Data Enrichment for Adaptive Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing threat mitigation systems struggle to effectively address the increasing complexity of computer attacks due to their reliance on predefined rules and signature-based detection, which are limited in identifying new, evolving, or sophisticated threats.
Innovation Solution
Implementing an AI/ML process that learns from data to detect and adapt to unusual patterns and behaviors, combining raw data with supplemental data using ciphers and analysis trees to form enriched data repositories for comprehensive threat analysis across multiple computing systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If predefined rules and signature-based detection are used, then the system is simple to implement, but it cannot effectively identify new, evolving, or sophisticated threats
Solution Approach 1:
The patent replaces traditional mechanical rule-based detection systems with AI/ML-based cognitive systems. The AI/ML process automatically learns from data patterns, substitutes manual rule creation and updates, and adapts to new threats without requiring explicit programming for each threat scenario.
Solution Approach 2:
The system performs preliminary actions by continuously learning from historical and real-time data before threats materialize. The AI/ML models are trained in advance on diverse attack patterns, enabling the system to recognize and respond to new threats faster than traditional signature-based systems that require post-attack updates.
2Adaptability or versatility
If AI/ML processes are implemented to detect evolving threats, then the system can identify new and sophisticated attacks, but the computational complexity and data processing requirements increase
Solution Approach 1:
The patent segments the threat detection system into multiple specialized AI/ML models, each trained to detect specific threat types or patterns. This modular approach divides the complex task of identifying all possible threats into manageable segments, reducing the computational burden on any single model while maintaining comprehensive coverage.
Solution Approach 2:
The system adds analytical dimensions by processing data through multiple AI/ML models simultaneously, each examining different aspects of threat patterns. This multi-dimensional analysis approach enables the system to detect sophisticated threats by combining insights from various analytical perspectives rather than relying on a single complex model.
3Reliability
If comprehensive data enrichment is performed across multiple technology types, then the system provides holistic threat monitoring, but the time and computational resources required increase
Solution Approach 1:
The patent implements preliminary action by pre-processing and enriching data from multiple technology types in advance, before threat analysis is required. This upfront data preparation includes normalizing formats, extracting relevant features, and organizing information across different security subsystems, so that when threats are detected, the AI/ML models can immediately analyze pre-enriched data without time-consuming processing delays.
Solution Approach 2:
The system creates standardized data copies and representations across different technology types, allowing the same AI/ML analysis pipelines to process data from diverse sources uniformly. This copying approach enables comprehensive multi-source monitoring while reducing processing time by reusing validated data transformation templates rather than creating custom processing logic for each data source.
Data Source
AI summary
A computer-implemented method, computer program product and computing system for receiving a message concerning an event within a computer platform, wherein the message concerns a technology type and includes raw data; defining a cipher for the technology type, thus defining an associated cipher; processing the raw data included within the message using the associated cipher to define supplemental data for the technology type; and forming enriched data for the technology type based, at least in part, upon the raw data and the supplemental data.


