AI Priority Decision Model for Cybersecurity Event Triage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In AI-based security control environments, the increasing frequency and sophistication of cyberattacks lead to a high workload for analysts in processing and prioritizing security events, with existing methods being inefficient in quickly identifying and responding to high-risk events due to variability in human analysis and response times.
Innovation Solution
An event processing method and system that measures risk levels and determines processing priorities for security control events using a computing device, employing a priority decision model to assign scores based on damage potential, reproducibility, exploitability, affected users, and discoverability, and verifies these priorities through feedback to reinforce the training of the decision model.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual analysis of security events is performed by human analysts, then detailed threat assessment can be achieved, but processing time increases significantly and workload becomes excessive
Solution Approach 1:
An AI-based priority decision model is introduced as an intermediary between security event collection and human analyst review. The model automatically processes events, assigns priorities based on multiple factors (risk level, detection equipment importance, attack frequency), and filters events before human analysis, reducing both processing time and workload while maintaining assessment quality
Solution Approach 2:
The system enables self-service processing where the priority decision model autonomously evaluates and prioritizes security events without continuous human intervention. The model uses reinforced learning to continuously improve its prioritization accuracy, making the system progressively more autonomous in handling security event triage
2Reliability
If all collected security events are processed, then comprehensive security monitoring is achieved, but system overload occurs during high-frequency attack periods
Solution Approach 1:
The system applies partial action by processing only the most critical events that exceed the event processing threshold. The priority decision model identifies and prioritizes high-risk events for immediate processing while deprioritizing or deferring lower-risk events, enabling the system to maintain reliable monitoring of critical threats without being overwhelmed by the total volume of all events
Solution Approach 2:
The event processing system is segmented into multiple priority levels. Events are divided into high-priority (requiring immediate processing), medium-priority (processed during normal capacity), and low-priority (deferred or batch-processed) categories. This segmentation allows the system to maintain comprehensive monitoring coverage while managing processing throughput by handling only necessary events at any given time
3Productivity
If priority decision models are used to automatically determine event processing order, then processing efficiency increases, but accuracy of priority determination may decrease compared to expert human judgment
Solution Approach 1:
The priority decision model incorporates feedback mechanisms where the prioritization results are continuously evaluated against actual threat outcomes and expert analyst corrections. This feedback loop enables the model to learn from both successful prioritizations and errors, progressively improving its accuracy while maintaining high processing efficiency
Solution Approach 2:
The system replaces the mechanical human judgment process with an AI-based decision model that uses multiple scoring factors (risk level, detection equipment importance, attack frequency) and weighted calculations. This substitution enables consistent, scalable priority determination that matches or exceeds expert human judgment while processing far more events efficiently
Data Source
AI summary
An event processing method performed by a computing device is provided. The method may comprise receiving a plurality of events and generating a first event sequence in which the received events are sequentially arranged, determining first priorities for the events included in the first event sequence, using data output from a previously trained priority decision model, verifying the first priorities by comparing the first priorities with second priorities for the events included in the first event sequence, determining a feedback score for the first priorities based on results of the verification; and reinforcing the training of the priority decision model using the feedback score.


