AI Corroboration of Vendor Cyberthreat Alerts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The complexity of managing cybersecurity vulnerabilities across an enterprise organization, where disparate software tools generate proprietary alerts that are difficult to unify, leading to challenges in filtering false positives and duplicates, is not efficiently addressed by existing technologies.
Innovation Solution
An artificial intelligence (AI) system that applies machine learning techniques to unify and correlate cyberthreat alerts from multiple vendor tools, using APIs to access outputs, and leveraging databases and pattern recognition algorithms to identify overlapping countermeasures and standardize descriptions, thereby filtering out false positives and duplicates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple vendor tools are deployed to detect cyberthreats across diverse computing devices, then detection coverage and reliability are improved, but the complexity of managing and filtering alerts increases significantly
Solution Approach 1:
The patent introduces an AI-powered intermediary system that sits between multiple vendor tools and the security operations team. This intermediary automatically ingests, standardizes, deduplicates, and prioritizes alerts from various vendor tools, reducing the manual filtering burden while maintaining comprehensive detection coverage across diverse computing devices.
Solution Approach 2:
The patent creates a universal alert processing platform that can handle alerts from multiple different vendor tools with proprietary formats. The system performs multiple functions including normalization, deduplication, enrichment, and prioritization within a single system, eliminating the need for separate processing for each vendor tool.
2Measurement precision
If manual filtering of vendor tool outputs is attempted, then false positives and duplicates may be identified, but the process becomes infeasible due to volume and complex interconnections
Solution Approach 1:
The patent replaces manual mechanical filtering processes with an automated AI-based system. The AI model analyzes alert patterns, correlates events across multiple sources, and automatically identifies false positives and duplicates, achieving both high precision in identification and scalability to handle large volumes of alerts that would be impossible to process manually.
Solution Approach 2:
The patent implements feedback loops where the AI system learns from security analyst decisions and alert outcomes. This continuous learning improves the system's ability to identify false positives and duplicates over time, increasing measurement precision while maintaining high processing efficiency through automated decision-making.
3Adaptability or versatility
If proprietary alert formats from different vendor tools are used, then each tool can be optimized for its specific function, but correlation and unification of alerts becomes difficult
Solution Approach 1:
The patent transforms proprietary alert formats from different vendor tools into a standardized internal format through parameter mapping and normalization. The system changes the structure, schema, and representation of alert data while preserving the essential security information, enabling seamless correlation and unification without losing vendor tool specialization capabilities.
4Reliability
If comprehensive cyberthreat detection coverage is achieved across all device components, then security reliability is improved, but the volume of alerts and difficulty of filtering increases
Solution Approach 1:
The patent extracts and removes duplicate alerts and false positives from the comprehensive set of alerts generated by full-coverage detection. The system identifies redundant information across multiple alerts and vendor tools, extracting only the unique and valid security events, thereby reducing alert volume while maintaining comprehensive detection coverage.
Data Source
AI summary
Artificial Intelligence (“AI”) apparatus and method are provided that correlate and consolidate operation of discrete vendor tools for detecting cyberthreats on a network. An AI engine may filter false positives and eliminate duplicates within cyberthreats detected by multiple vendor tools. The AI engine provides machine learning solutions to complexities associated with translating vendor-specific cyberthreats to known cyberthreats. The AI engine may ingest data generated by the multiple vendor tools. The AI engine may classify hardware devices or software applications scanned by each vendor tool. The AI engine may decommission vendor tools that provide redundant cyberthreat detection. The AI engine may display operational results on a dashboard directing cyberthreat defense teams to corroborated cyberthreats and away from false positives.


