Automated Alert Bundling for Security Operations Centers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security operations centers face inefficiencies and resource wastage due to manual investigations of numerous security alerts, with similar alerts requiring duplicate efforts and potential missed connections to underlying causes, leading to increased stress and resource consumption.

Innovation Solution

An automated alert bundling system that groups similar alerts based on various criteria such as event similarity, behavioral profiles, criticality of assets, and indicators of compromise, allowing for bundled alerts to be processed more efficiently and reducing the workload on analysts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual investigation of each security alert is performed, then thorough analysis of individual alerts is achieved, but resource consumption increases and productivity decreases

Engineering Contradiction:
Improvealert analysis thoroughnessVSAvoidalert processing efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent groups multiple similar security alerts into bundles based on similarity criteria (event type, source, target, severity). Analysts investigate one representative alert per bundle, and the investigation results are automatically applied to all bundled alerts. This merging approach maintains thorough analysis quality while dramatically improving productivity by eliminating duplicate investigation work across similar alerts.

Inventive Principle:
Principle #5Merging (Combining)

2Loss of information

If similar alerts are investigated separately, then individual alert details are captured, but duplicate efforts waste resources and time

Engineering Contradiction:
Improvealert detail captureVSAvoidduplicate investigation time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system identifies and groups alerts with similar characteristics (event type, source IP, target system, severity level) into bundles. Instead of investigating each alert separately, analysts investigate one representative alert per bundle, capturing all necessary details. The system then automatically applies these investigation findings to all bundled alerts, eliminating duplicate time consumption while preserving complete alert detail capture through the bundling metadata.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary grouping and identification of similar alerts before the analyst begins investigation. By pre-bundling alerts based on objective similarity criteria, the system prepares the work in advance, allowing analysts to immediately focus on unique investigation tasks rather than first identifying duplicates. This preliminary action reduces the time analysts would otherwise spend on duplicate investigations.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If all security alerts are processed individually, then comprehensive monitoring is maintained, but analyst workload and stress increase

Engineering Contradiction:
Improvesecurity monitoring completenessVSAvoidanalyst workload
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system maintains comprehensive security monitoring by grouping alerts into bundles while preserving all original alert data and characteristics. Analysts review one representative alert per bundle, ensuring complete monitoring coverage, while the system automatically tracks and applies findings across all bundled alerts. This approach significantly reduces analyst workload and stress by eliminating redundant review of identical or similar alerts, while maintaining thorough security oversight.

Inventive Principle:
Principle #5Merging (Combining)

4Productivity

If alert bundling is implemented, then processing efficiency improves and resource utilization increases, but system complexity increases

Engineering Contradiction:
Improvealert processing efficiencyVSAvoidbundling system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The alert bundling system is implemented as a modular component that segments the alert processing workflow into distinct phases: alert collection, similarity evaluation, bundling, representative selection, investigation, and result propagation. Each module performs a specific function with well-defined interfaces, making the overall system manageable despite its complexity. The segmentation allows the system to achieve high productivity through automated bundling while keeping each individual component relatively simple and maintainable.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11240256B2Grouping alerts into bundles of alerts
Publication Date: 2022.02.01 MICRO FOCUS LLC
  • US11240256B2 patent drawing
  • US11240256B2 patent drawing
  • US11240256B2 patent drawing

AI summary

In some examples, a plurality of alerts relating to issues in a computing arrangement are received, where the plurality of alerts generated based on events in the computing arrangement. A subset of the plurality of alerts is grouped into a bundle of alerts, the grouping being based on a criterion. The bundle of alerts is communicated to cause processing of the alerts in the bundle of alerts together.