AI Cyberthreat Alert Correlation and Deduplication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of managing cybersecurity threats across an enterprise organization, where disparate software tools generate alerts in proprietary formats, making it difficult to distinguish between false positives and duplicates, and requiring manual filtering which is not feasible due to volume and interconnections.

Innovation Solution

An artificial intelligence (AI) system that applies machine learning techniques to unify and filter cyberthreat alerts from multiple vendor tools by identifying overlapping countermeasures, correlating them with known cyberthreats, and prioritizing remediation, using APIs and a database to translate vendor-specific descriptions into standardized formats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple vendor tools are deployed to detect cyberthreats across diverse computing devices, then detection coverage and reliability are improved, but the complexity of managing and filtering alerts from these tools increases significantly

Engineering Contradiction:
Improvecyberthreat detection coverageVSAvoidalert filtering complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an artificial intelligence system as an intermediary component that sits between multiple vendor tools and the cybersecurity team. This AI system receives alerts from various vendor tools in different proprietary formats, processes them through machine learning models, and outputs standardized, deduplicated threat information. The intermediary handles the complexity of format translation, duplicate detection, and prioritization, allowing vendor tools to maintain their specialized detection capabilities while eliminating the management burden.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If manual filtering of vendor tool outputs is attempted, then accuracy in identifying false positives and duplicates may be improved, but the time and resource requirements become prohibitive due to volume and interconnections

Engineering Contradiction:
Improvefalse positive identification accuracyVSAvoidmanual filtering time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces the manual mechanical process of filtering and analyzing alerts with an automated artificial intelligence system. The AI uses machine learning algorithms to automatically detect false positives, identify duplicate alerts, and prioritize threats based on learned patterns from historical data. This substitution maintains or improves accuracy while reducing the time and human resources required from hours or days of manual work to near-real-time automated processing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If vendor-specific proprietary formats are maintained for cyberthreat alerts, then each vendor tool can optimize its detection capabilities, but the difficulty of correlating and consolidating alerts from different tools increases

Engineering Contradiction:
Improvevendor tool detection capabilityVSAvoidalert correlation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal interface layer through the AI system that can process multiple proprietary formats from different vendors. The AI is trained to recognize and parse various vendor-specific alert formats, extracting relevant threat information from each. It then translates these diverse inputs into a standardized universal output format, enabling correlation and consolidation of alerts while preserving the specialized detection capabilities of each vendor tool through their native formats.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11757904B2Artificial intelligence reverse vendor collation
Publication Date: 2023.09.12 BANK OF AMERICA CORP
  • US11757904B2 patent drawing
  • US11757904B2 patent drawing
  • US11757904B2 patent drawing

AI summary

Artificial Intelligence (“AI”) apparatus and method are provided that correlate and consolidate operation of discrete vendor tools for detecting cyberthreats on a network. An AI engine may filter false positives and eliminate duplicates within cyberthreats detected by multiple vendor tools. The AI engine provides machine learning solutions to complexities associated with translating vendor-specific cyberthreats to known cyberthreats. The AI engine may ingest data generated by the multiple vendor tools. The AI engine may classify hardware devices or software applications scanned by each vendor tool. The AI engine may decommission vendor tools that provide redundant cyberthreat detection. The AI engine may display operational results on a dashboard directing cyberthreat defense teams to corroborated cyberthreats and away from false positives.