Automated Threat Mitigation via Classification Model

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing systems face challenges in efficiently addressing unknown threat scenarios due to the lack of established remediation protocols, leading to inefficient and costly manual processes for IT specialists, who often struggle to identify and implement appropriate mitigation strategies.

Innovation Solution

A computing system generates a mitigation file with predictive remediation processes by analyzing threat vectors and applying a classification model to identify relevant processes from a network of client systems, creating a composite remediation file that includes both non-executable and executable instructions for immediate action.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual monitoring and updating of antivirus software is performed by IT specialists, then threat mitigation capability is maintained, but cost and time consumption increase significantly

Engineering Contradiction:
Improvethreat mitigation capabilityVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service by allowing the computing system to automatically detect unknown threat scenarios and generate its own mitigation processes without requiring human intervention. The classification model autonomously analyzes threat vectors and produces tailored mitigation strategies, freeing IT specialists from manual monitoring tasks while maintaining reliable threat mitigation capability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual process of IT specialists monitoring and updating antivirus software with an automated electronic system. The classification model and mitigation generation process substitute human expertise with algorithmic analysis, dramatically reducing time consumption while preserving threat mitigation effectiveness through systematic evaluation of threat scenarios.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If IT specialists manually search for remediation protocols online, then response to unknown threats is attempted, but efficiency decreases and best remediation processes cannot be identified

Engineering Contradiction:
Improveresponse to unknown threatsVSAvoidefficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system replaces the inefficient manual online search process with an automated classification model that systematically analyzes threat scenarios. The model evaluates threat vectors against known patterns and generates optimized mitigation processes, dramatically improving productivity while maintaining adaptability to unknown threats through continuous learning and pattern recognition.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system incorporates feedback mechanisms where the classification model continuously learns from analyzed threat scenarios and refines its mitigation generation capabilities. This feedback loop enables the system to improve its response efficiency to unknown threats over time, adapting to new threat patterns while maintaining high productivity through automated decision-making.

Inventive Principle:
Principle #23Feedback

3Reliability

If comprehensive monitoring software is deployed to detect all threats, then threat detection capability improves, but system complexity and cost increase

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the essential threat detection and mitigation functions from complex comprehensive monitoring software. By isolating the core classification model and mitigation generation processes, the system achieves reliable threat detection capability while reducing overall system complexity. The extracted functions operate independently as a focused solution rather than part of a庞大的 monitoring infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10911479B2Real-time mitigations for unfamiliar threat scenarios
Publication Date: 2021.02.02 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10911479B2 patent drawing
  • US10911479B2 patent drawing
  • US10911479B2 patent drawing

AI summary

A computing system performs real-time mitigations for unfamiliar threat scenarios by identifying a particular threat scenario for a client system that has not previously experienced the threat scenario and for which a remediation process is unknown. The computing system responds to the unknown threat scenario by generating and providing the client system a mitigation file that includes a predictive set of mitigation processes for responding to the threat scenario. The mitigation file is generated by first generating a threat vector that identifies a plurality of different threat scenario characteristics for the particular threat scenario. Then, a classification model is applied to the threat vector to identify a predictive set of mitigation processes that are determined to be a best fit for the threat vector and that are included in the mitigation file.