Anomaly Grouping and Prioritization for Security Alert Overload

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security analytics products generate a high volume of alerts that overwhelm security response teams, leading to alert fatigue and increased security risks due to the inability to effectively process and prioritize relevant threats.

Innovation Solution

Implementing a system that utilizes neural network-based processors to enhance anomaly data, perform multi-stage grouping and prioritization, and generate analyst work units with summaries, leveraging threat intelligence and active learning to streamline threat analysis and response.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security products generate comprehensive alerts, then security coverage is improved, but alert volume increases overwhelming security teams

Engineering Contradiction:
Improvesecurity coverageVSAvoidsecurity team capacity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the overwhelming stream of security alerts into distinct groups based on multiple dimensions including threat type, affected assets, time windows, and correlation patterns. This segmentation transforms a single overwhelming alert stream into multiple manageable groups that security analysts can process systematically, resolving the contradiction between comprehensive security coverage and team capacity by organizing alerts into digestible units.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary alert management system that sits between security products and security teams. This intermediary automatically correlates, deduplicates, prioritizes, and groups alerts using machine learning models and predefined policies, acting as a mediator that translates raw alert volumes into manageable security incidents, thereby preserving comprehensive security coverage while protecting team capacity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If alert filtering and suppression policies are applied, then alert volume is reduced, but important alerts may be missed

Engineering Contradiction:
Improvealert processing efficiencyVSAvoidalert accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements dynamic alert filtering and suppression policies that adapt based on contextual factors such as threat intelligence feeds, historical incident patterns, asset criticality levels, and real-time security posture. Rather than static filtering rules, the system dynamically adjusts what alerts are suppressed versus escalated, ensuring that important alerts are not missed while still reducing volume through context-aware filtering.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent incorporates feedback loops where security analyst actions on grouped alerts (such as false positive markings, investigation outcomes, and prioritization adjustments) are fed back into the alert grouping and prioritization models. This continuous learning mechanism improves the accuracy of alert filtering over time, reducing false suppressions while maintaining efficient alert processing through refined prioritization based on actual security outcomes.

Inventive Principle:
Principle #23Feedback

3Loss of information

If all anomaly details are presented to analysts, then complete information is provided, but analyst workload increases

Engineering Contradiction:
Improveanomaly information completenessVSAvoidanalyst response time
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The patent applies local quality by presenting different levels of information detail to different analysts based on their expertise, role, and the specific alert context. Critical alerts receive comprehensive detailed information, while lower-priority alerts receive summarized views. This localized information quality ensures that analysts receive complete information where necessary while reducing workload through selective summarization elsewhere, resolving the contradiction between information completeness and response efficiency.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments anomaly information into hierarchical layers: executive summaries for quick assessment, detailed technical information for deep analysis, and contextual metadata for correlation. Analysts can navigate between these segmented information layers based on their immediate needs, receiving complete information when necessary while avoiding overwhelming detail during initial triage, thus balancing information completeness with manageable workload.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12621312B2Incident descriptions for extended detection and response to security anomalies
Publication Date: 2026.05.05 CISCO TECHNOLOGY INC
  • US12621312B2 patent drawing
  • US12621312B2 patent drawing
  • US12621312B2 patent drawing

AI summary

Techniques described herein for extended detection and response to security anomalies in computing networks can perform automated analysis of anomalies occurring in different telemetry sources in a computer network, in order to synthesize the anomalies into analyst work units that are surfaced for further analysis by security response teams. Anomalies can initially be processed in order to identify and collect extended anomaly data. The extended anomaly data can then be used to group the anomalies according to a multi-stage grouping process which produces analyst work units. The analyst work units can be processed to produce analyst summaries that assist with analysis and response. Furthermore, the analyst work units can be prioritized for further analysis, and analyst interactions with the prioritized analyst work units can be used to influence subsequent anomaly grouping operations.