Threat Detection Model GUI for Cybersecurity Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data science models for cybersecurity are challenging to build and maintain due to heterogeneity in data formats, poor data quality, and the need for specialized skills, making it difficult for organizations to detect anomalous behavior effectively.

Innovation Solution

A graphical user interface (GUI) based tool that allows users to create and maintain data science models through a step-by-step process, including data selection, algorithm selection, risk scoring, and automation, which is vendor and data format agnostic, enabling users of various skill levels to build and reuse models across different platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If machine learning and artificial intelligence algorithms are adopted to detect anomalous behavior, then threat detection capability is improved, but device complexity and difficulty of operation increase due to specialized skills required

Engineering Contradiction:
Improvethreat detection capabilityVSAvoiddifficulty of building and maintaining models
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a graphical user interface (GUI) as an intermediary layer between the user and the complex machine learning algorithms. The GUI provides a step-by-step wizard that guides users through data selection, algorithm selection, risk scoring, and automation setup without requiring them to understand the underlying complex algorithms, thus resolving the contradiction between improved detection capability and ease of operation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables users to independently build and maintain their own threat detection models through the intuitive GUI without requiring specialized data science expertise. The automated reapplication of models and scheduled execution further reduce manual intervention, allowing users to self-serve the complex task of model creation and maintenance

Inventive Principle:
Principle #25Self-service

2Measurement precision

If data science models are built using specialized algorithms and processes, then measurement precision of anomalous behavior is improved, but device complexity increases due to heterogeneity in data formats and poor data quality

Engineering Contradiction:
Improvedetection precision of anomalous behaviorVSAvoidcomplexity of data processing system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent transforms heterogeneous data from various sources into a standardized format through the GUI's data selection process. By changing the parameter representation of diverse data sources into a common structure, the system maintains detection precision while reducing the complexity associated with handling heterogeneous data formats

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The GUI tool is designed to be vendor and data format agnostic, providing universal functionality that works with multiple data sources and formats. This multi-functionality allows the same interface and process to handle diverse data types, reducing system complexity while maintaining precise anomaly detection capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If step-by-step wizard process is implemented for model creation, then ease of operation is improved, but productivity decreases due to time-consuming manual configuration

Engineering Contradiction:
Improveuser friendliness of model creationVSAvoidspeed of model creation and deployment
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system performs preliminary actions by automatically applying the selected algorithm to the selected data and generating the model configuration. The GUI's step-by-step wizard pre-configures necessary parameters and automatically executes the model creation process, reducing both the perceived complexity for users and the actual time required for model deployment

Inventive Principle:
Principle #10Preliminary action

4Productivity

If automated reapplication of model is scheduled, then productivity is improved, but device complexity increases due to automation infrastructure requirements

Engineering Contradiction:
Improveefficiency of threat detectionVSAvoidcomplexity of automation system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges the model reapplication functionality with the existing GUI interface and data processing pipeline. The automated reapplication is integrated into the same system that handles data selection and model creation, combining multiple functions into a unified platform rather than adding separate automation infrastructure, thus improving productivity without proportionally increasing device complexity

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11765189B2Building and maintaining cyber security threat detection models
Publication Date: 2023.09.19 GURUCUL SOLUTIONS LLC
  • US11765189B2 patent drawing
  • US11765189B2 patent drawing
  • US11765189B2 patent drawing

AI summary

Techniques for building and maintaining cyber security threat detection models are described. The techniques include data selection, algorithm selection, risk score algorithm selection, model outcome selection, and model automation. During data selection, data is received from various sources and in various formats. The data is then tokenized into vector form and compared to preexisting vectors. If the vectors are equal, the tokenized vector is saved in the database. If the vectors are not equal, a new vector, in key value pair format, is formed. After which, algorithms can be selected to detect anomalies within the data and assign a risk score to the data. Subsequently, a matrix is formed with the vector, selected algorithm, and parameters of the data that were analyzed. The matrix is then stored for application with future data based on a predetermined rule. The output can be modeled in various user-friendly methods.