AI Detection Explainability for Cybersecurity False Positives
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cybersecurity systems often generate false positive detections, leading to inefficient use of computational, network, and storage resources, as well as requiring manual intervention by administrators lacking expertise in both machine learning and cybersecurity, which complicates the resolution of such false positives.
Innovation Solution
An AI model-based pipeline is employed to generate explanations for false positive detections, automating the handling of these issues by providing clear reasons for false positives and facilitating the improvement of detection mechanisms through corpus growth and model retraining.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual intervention by administrators is used to handle false positive detections, then detailed analysis and resolution of false positives can be performed, but computational resources are wasted and resolution time increases
Solution Approach 1:
The system enables self-service by having the AI model automatically analyze false positive detections, generate explanations, and resolve issues without requiring human administrator intervention. The model processes detections autonomously, reducing both resource consumption and resolution time while maintaining accuracy through its trained capabilities.
Solution Approach 2:
The patent replaces the mechanical manual analysis process with an AI-based automated system. The AI model substitutes human administrators in analyzing false positives, generating explanations, and resolving detections, thereby eliminating the waste of computational resources and time associated with manual intervention.
2Measurement precision
If AI models are used to detect malicious behavior, then detection accuracy improves, but false positive detections increase requiring manual intervention
Solution Approach 1:
The system implements feedback mechanisms where the AI model analyzes false positive detections, generates explanations, and uses this information to refine its future detections. The feedback loop includes monitoring false positive rates and adjusting model parameters accordingly, thereby reducing false positives while maintaining high detection accuracy.
Solution Approach 2:
The patent applies parameter changes by adjusting AI model parameters and thresholds based on analyzed false positive detections. The model modifies its detection criteria and parameter weights to reduce false positive rates while preserving detection accuracy, adapting its behavior through continuous learning from resolved false positive cases.
3Manufacturing precision
If detailed analysis of false positives is performed manually, then resolution quality improves, but computational and network resources are consumed
Solution Approach 1:
The patent replaces manual analysis with an AI-based automated system that performs detailed analysis of false positives. The AI model processes detection data, generates comprehensive explanations, and resolves issues without consuming computational or network resources in the same way manual analysis would, as it operates through efficient algorithmic processing rather than human cognitive resources.
Data Source
AI summary
The present disclosure provides techniques for AI model-based detection explainability. A processing device obtains computer-readable text and an indication of a false positive detection of malicious behavior with respect to the computer-readable text by a cybersecurity system, The processing device obtains, via an artificial intelligence (AI) model trained to generate language, a reason for the false positive detection of the malicious behavior. The processing device provides an indication of the reason for the false positive detection to a destination device.


