AI Cyberthreat Alert Correlation System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise organizations face challenges in manually filtering and correlating cyberthreat alerts from disparate vendor tools due to proprietary formats and overlapping detection coverage, leading to difficulties in identifying false positives and duplicates across diverse computing devices and networks.

Innovation Solution

An artificial intelligence (AI) system employing machine learning techniques and APIs to unify and filter cyberthreat alerts from multiple vendor tools, correlating countermeasures to identify overlapping actions, and translating proprietary formats into standardized descriptions to determine duplicate or false alerts, using algorithms like Naïve Bayes Classifier and Support Vector Machine to prioritize remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple vendor tools are deployed to detect cyberthreats across diverse computing devices, then detection coverage is improved, but alert correlation complexity increases

Engineering Contradiction:
Improvedetection coverageVSAvoidalert correlation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an AI-powered intermediary system that sits between multiple vendor tools and the security operations center. This intermediary automatically correlates alerts from different vendors by analyzing alert patterns, identifying false positives, and mapping alerts to specific vulnerabilities using machine learning algorithms. The system translates proprietary alert formats into a standardized framework, eliminating the need for manual correlation while maintaining comprehensive detection coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If manual filtering of vendor tool outputs is attempted, then false positives may be identified, but the process becomes infeasible due to volume and complexity

Engineering Contradiction:
Improvefalse positive identificationVSAvoidfiltering feasibility
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent replaces the manual mechanical process of filtering and analyzing vendor alerts with an automated AI-based system. The AI engine processes thousands of alerts simultaneously, using machine learning models to identify false positives, correlate related alerts, and prioritize genuine threats. This substitution enables precise false positive identification at scale, making the filtering process feasible rather than infeasible.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If proprietary alert formats from different vendors are used, then vendor-specific detection capabilities are maintained, but alert standardization becomes difficult

Engineering Contradiction:
Improvevendor-specific detection capabilityVSAvoidalert standardization
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent creates a universal alert correlation framework that can process and standardize alerts from multiple different vendor formats simultaneously. The AI system learns the proprietary formats of different vendors and automatically translates them into a standardized internal representation, enabling consistent correlation and analysis across all vendors while preserving the ability to handle vendor-specific alert structures and capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11895128B2Artificial intelligence vulnerability collation
Publication Date: 2024.02.06 BANK OF AMERICA CORP
  • US11895128B2 patent drawing
  • US11895128B2 patent drawing
  • US11895128B2 patent drawing

AI summary

Artificial Intelligence (“AI”) apparatus and method are provided that correlate and consolidate operation of discrete vendor tools for detecting cyberthreats on a network. An AI engine may filter false positives and eliminate duplicates within cyberthreats detected by multiple vendor tools. The AI engine provides machine learning solutions to complexities associated with translating vendor-specific cyberthreats to known cyberthreats. The AI engine may ingest data generated by the multiple vendor tools. The AI engine may classify hardware devices or software applications scanned by each vendor tool. The AI engine may decommission vendor tools that provide redundant cyberthreat detection. The AI engine may display operational results on a dashboard directing cyberthreat defense teams to corroborated cyberthreats and away from false positives.