Anomaly Grouping and Prioritization for Security Alert Overload
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Security analytics products generate a high volume of alerts that overwhelm security response teams, leading to alert fatigue and increased security risks due to the inability to effectively process and prioritize relevant threats.
Innovation Solution
Implementing a system that utilizes neural network-based processors to enhance anomaly data, perform multi-stage grouping and prioritization, and generate analyst work units with summaries, leveraging threat intelligence and active learning to streamline threat analysis and response.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple security products generate comprehensive alerts, then security coverage is improved, but alert volume increases overwhelming security teams
Solution Approach 1:
The patent segments the overwhelming stream of security alerts into distinct groups based on multiple dimensions including threat type, affected assets, time windows, and correlation patterns. This segmentation transforms a single overwhelming alert stream into multiple manageable groups that security analysts can process systematically, resolving the contradiction between comprehensive security coverage and team capacity by organizing alerts into digestible units.
Solution Approach 2:
The patent introduces an intermediary alert management system that sits between security products and security teams. This intermediary automatically correlates, deduplicates, prioritizes, and groups alerts using machine learning models and predefined policies, acting as a mediator that translates raw alert volumes into manageable security incidents, thereby preserving comprehensive security coverage while protecting team capacity.
2Productivity
If alert filtering and suppression policies are applied, then alert volume is reduced, but important alerts may be missed
Solution Approach 1:
The patent implements dynamic alert filtering and suppression policies that adapt based on contextual factors such as threat intelligence feeds, historical incident patterns, asset criticality levels, and real-time security posture. Rather than static filtering rules, the system dynamically adjusts what alerts are suppressed versus escalated, ensuring that important alerts are not missed while still reducing volume through context-aware filtering.
Solution Approach 2:
The patent incorporates feedback loops where security analyst actions on grouped alerts (such as false positive markings, investigation outcomes, and prioritization adjustments) are fed back into the alert grouping and prioritization models. This continuous learning mechanism improves the accuracy of alert filtering over time, reducing false suppressions while maintaining efficient alert processing through refined prioritization based on actual security outcomes.
3Loss of information
If all anomaly details are presented to analysts, then complete information is provided, but analyst workload increases
Solution Approach 1:
The patent applies local quality by presenting different levels of information detail to different analysts based on their expertise, role, and the specific alert context. Critical alerts receive comprehensive detailed information, while lower-priority alerts receive summarized views. This localized information quality ensures that analysts receive complete information where necessary while reducing workload through selective summarization elsewhere, resolving the contradiction between information completeness and response efficiency.
Solution Approach 2:
The patent segments anomaly information into hierarchical layers: executive summaries for quick assessment, detailed technical information for deep analysis, and contextual metadata for correlation. Analysts can navigate between these segmented information layers based on their immediate needs, receiving complete information when necessary while avoiding overwhelming detail during initial triage, thus balancing information completeness with manageable workload.
Data Source
AI summary
Techniques described herein for extended detection and response to security anomalies in computing networks can perform automated analysis of anomalies occurring in different telemetry sources in a computer network, in order to synthesize the anomalies into analyst work units that are surfaced for further analysis by security response teams. Anomalies can initially be processed in order to identify and collect extended anomaly data. The extended anomaly data can then be used to group the anomalies according to a multi-stage grouping process which produces analyst work units. The analyst work units can be processed to produce analyst summaries that assist with analysis and response. Furthermore, the analyst work units can be prioritized for further analysis, and analyst interactions with the prioritized analyst work units can be used to influence subsequent anomaly grouping operations.


