AI Priority Decision Model for Cybersecurity Event Triage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In AI-based security control environments, the increasing frequency and sophistication of cyberattacks lead to a high workload for analysts in processing and prioritizing security events, with existing methods being inefficient in quickly identifying and responding to high-risk events due to variability in human analysis and response times.

Innovation Solution

An event processing method and system that measures risk levels and determines processing priorities for security control events using a computing device, employing a priority decision model to assign scores based on damage potential, reproducibility, exploitability, affected users, and discoverability, and verifies these priorities through feedback to reinforce the training of the decision model.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual analysis of security events is performed by human analysts, then detailed threat assessment can be achieved, but processing time increases significantly and workload becomes excessive

Engineering Contradiction:
Improvethreat assessment accuracyVSAvoidevent processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

An AI-based priority decision model is introduced as an intermediary between security event collection and human analyst review. The model automatically processes events, assigns priorities based on multiple factors (risk level, detection equipment importance, attack frequency), and filters events before human analysis, reducing both processing time and workload while maintaining assessment quality

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service processing where the priority decision model autonomously evaluates and prioritizes security events without continuous human intervention. The model uses reinforced learning to continuously improve its prioritization accuracy, making the system progressively more autonomous in handling security event triage

Inventive Principle:
Principle #25Self-service

2Reliability

If all collected security events are processed, then comprehensive security monitoring is achieved, but system overload occurs during high-frequency attack periods

Engineering Contradiction:
Improvesecurity monitoring coverageVSAvoidevent processing throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies partial action by processing only the most critical events that exceed the event processing threshold. The priority decision model identifies and prioritizes high-risk events for immediate processing while deprioritizing or deferring lower-risk events, enabling the system to maintain reliable monitoring of critical threats without being overwhelmed by the total volume of all events

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The event processing system is segmented into multiple priority levels. Events are divided into high-priority (requiring immediate processing), medium-priority (processed during normal capacity), and low-priority (deferred or batch-processed) categories. This segmentation allows the system to maintain comprehensive monitoring coverage while managing processing throughput by handling only necessary events at any given time

Inventive Principle:
Principle #1Segmentation

3Productivity

If priority decision models are used to automatically determine event processing order, then processing efficiency increases, but accuracy of priority determination may decrease compared to expert human judgment

Engineering Contradiction:
Improveevent processing efficiencyVSAvoidpriority determination accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The priority decision model incorporates feedback mechanisms where the prioritization results are continuously evaluated against actual threat outcomes and expert analyst corrections. This feedback loop enables the model to learn from both successful prioritizations and errors, progressively improving its accuracy while maintaining high processing efficiency

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system replaces the mechanical human judgment process with an AI-based decision model that uses multiple scoring factors (risk level, detection equipment importance, attack frequency) and weighted calculations. This substitution enables consistent, scalable priority determination that matches or exceeds expert human judgment while processing far more events efficiently

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12124573B1Event processing method and system
Publication Date: 2024.10.22 KOREA INTERNET & SECURITY AGENCY
  • US12124573B1 patent drawing
  • US12124573B1 patent drawing
  • US12124573B1 patent drawing

AI summary

An event processing method performed by a computing device is provided. The method may comprise receiving a plurality of events and generating a first event sequence in which the received events are sequentially arranged, determining first priorities for the events included in the first event sequence, using data output from a previously trained priority decision model, verifying the first priorities by comparing the first priorities with second priorities for the events included in the first event sequence, determining a feedback score for the first priorities based on results of the verification; and reinforcing the training of the priority decision model using the feedback score.