AI Security Control Decision-Making for Threat Event Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security control systems struggle to efficiently prioritize and quickly process large numbers of security threat events, leading to increased workload and inconsistent response times due to manual analysis, which can result in delayed responses to high-risk events.

Innovation Solution

A method utilizing artificial intelligence to determine priority processing orders for security threat events and playbooks by considering event risk, playbook execution time, and risk occurrence frequency, using supervised and reinforcement learning models to automate decision-making.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If manual analysis by control personnel is used to process security threat events, then flexibility in handling different types of events is maintained, but the workload increases excessively and response time becomes inconsistent

Engineering Contradiction:
Improveflexibility in handling eventsVSAvoidresponse efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent segments security threat events into different priority levels (high, medium, low) based on risk assessment criteria. High-priority events requiring manual analysis are separated from routine events that can be handled automatically through playbook execution, reducing the workload on control personnel while maintaining flexibility for critical incidents.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements self-service through automated playbook execution for routine security events. The playbook automatically responds to threats without human intervention, handling common attack patterns and reducing the need for manual analysis of low-complexity events.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If all security threat events are processed manually, then accurate analysis can be performed, but the time required increases significantly and high-risk events may be delayed

Engineering Contradiction:
Improveanalysis accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies local quality by providing differentiated processing: high-priority events receive thorough manual analysis for accuracy, while low-priority events receive automated processing for speed. The AI model and playbook provide sufficient analysis accuracy for routine events, reserving human expertise for complex cases.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs preliminary action through automated playbook execution and AI-based priority assessment before human analysts review events. This preliminary filtering and classification prepares events for appropriate handling, ensuring high-priority events are identified and processed promptly.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If security controllers rely on individual know-how and experience, then personalized judgment can be applied, but consistent response across different controllers becomes difficult to achieve

Engineering Contradiction:
Improvepersonalized judgmentVSAvoidresponse consistency
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The patent implements universality through the playbook, which provides a standardized response framework applicable to all security events of a given type. All controllers follow the same playbook procedures for consistent handling, while the system maintains adaptability through AI-based priority assessment and selective playbook selection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system incorporates feedback mechanisms where playbook execution results and threat analysis outcomes are fed back into the AI model to continuously improve priority assessment accuracy. This feedback loop ensures that the system learns from actual responses while maintaining consistent processing standards.

Inventive Principle:
Principle #23Feedback

4Speed

If high-risk events are identified and preferentially processed among many security threats, then critical incidents can be responded to quickly, but the complexity of prioritization increases

Engineering Contradiction:
Improveprocessing speed for high-risk eventsVSAvoidprioritization system complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent changes parameters by assessing and assigning priority levels (high, medium, low) to security events based on multiple criteria including threat type, source, and potential impact. This parameter-based prioritization enables systematic identification of high-risk events without requiring complex manual evaluation for each incident.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The AI model serves as an intermediary between raw security events and human analysts. It automatically assesses event priority and routes high-priority events to human reviewers, while routing lower-priority events to automated playbook execution, thereby simplifying the overall prioritization process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12393683B2Method for supporting decision-making in security control environment based on artificial intelligence
Publication Date: 2025.08.19 KOREA INTERNET & SECURITY AGENCY
  • US12393683B2 patent drawing
  • US12393683B2 patent drawing
  • US12393683B2 patent drawing

AI summary

A method of supporting decision-making of security control includes: (a) when an system for automatically analyzing a security threat receives a security warning from a security device, collecting security threat events generating the security warning from the security device; (b) when the collected security threat events exceed a preset event processing threshold, generating, by the system for automatically analyzing a security threat, a first request message for preferentially processing a security event; (c) when receiving the first request message generated from the system, determining, by the system for supporting priority of security control, a priority processing order of the security threat events, and notifying the system; and (d) when receiving the second request message generated from the system, determining, by the system for supporting priority of security control, a priority processing order and notifying the system for automatically analyzing a security threat of the determined priority processing order.