AI Cybersecurity Detection Prioritization Using Historical Timing Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity management systems rely on manual detection prioritization, which is time-consuming, prone to errors, and inefficient in handling numerous and evolving threats, and rule-based approaches fail to adapt to new attack vectors.
Innovation Solution
Transform historical cybersecurity detection data into rank ordered detection datasets and use an AI model trained on these datasets to prioritize detections, considering resolution times and urgency, thereby automating the prioritization process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual detection prioritization is used, then analysts can review and investigate detections, but the process is time-consuming and inefficient in handling numerous threats
Solution Approach 1:
The system enables self-service prioritization by using AI models to automatically assess and rank cybersecurity detections based on historical data patterns, eliminating the need for manual analyst intervention in the prioritization decision-making process
Solution Approach 2:
The patent replaces the mechanical manual review process with an AI-based automated system that uses machine learning models to perform detection prioritization, substituting human cognitive processing with computational algorithms
2Ease of operation
If manual detection prioritization is used, then analysts can make prioritization decisions, but the process is prone to errors and inconsistent
Solution Approach 1:
The system incorporates feedback mechanisms where the AI model continuously learns from historical detection data and analyst resolutions, adjusting its prioritization algorithms to improve accuracy and reduce errors over time
Solution Approach 2:
Manual decision-making is replaced with automated AI-based decision support that provides consistent, objective prioritization rankings based on learned patterns from historical data, eliminating human error and inconsistency
3Extent of automation
If rule-based approaches are used for prioritization, then the system can automatically filter detections, but it fails to adapt to new attack vectors
Solution Approach 1:
The system transitions from static rule-based prioritization to dynamic AI-based prioritization that continuously adapts to new attack vectors by learning from historical detection data and evolving threat patterns
Solution Approach 2:
The patent changes the underlying parameters of prioritization from fixed rules to learned patterns and probabilities, enabling the system to adapt to new threats through continuous training on historical data
4Reliability
If all detections are reviewed manually, then no false positives are missed, but the efficiency of threat response is reduced
Solution Approach 1:
The patent replaces manual review of all detections with AI-based automated prioritization that efficiently ranks detections by severity and urgency, enabling analysts to focus only on high-priority items while maintaining high reliability
Solution Approach 2:
Instead of requiring complete manual review of all detections, the system uses AI to perform partial automated prioritization that is sufficient for efficient threat response, allowing analysts to concentrate resources on the most critical detections
Data Source
AI summary
The present disclosure provides an approach of collecting historical cybersecurity detection data comprising a plurality of cybersecurity detections and a plurality of detection times. The approach transforms the historical cybersecurity detection data into a plurality of rank ordered detection datasets that rank order each one of the plurality of cybersecurity detections based on the plurality of detection times. In turn, the approach trains an artificial intelligence (AI) model using the plurality of rank ordered detection datasets to generate a prioritized output dataset from an input dataset.


