Asset Anomaly Detection Retraining for Structured False Positives
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing anomaly detection systems in computing environments suffer from structured false positives, misidentifying assets as anomalies due to unexpected but intentional events, leading to inaccurate anomaly risk scores and increased detection rates.
Innovation Solution
Retraining the anomaly detection machine learning model to refine associations between behavioral attributes and asset types, using classification algorithms to account for structured false positives, and calculating a structured false positive score to adjust anomaly risk scores.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the anomaly detection machine learning model is applied to detect asset anomalies, then the detection rate of anomalies is improved, but the number of false positives increases due to structured false positives from unexpected but intentional events
Solution Approach 1:
The patent introduces a structured false positive score as an intermediary metric to mediate between the anomaly detection model's raw output and the final anomaly risk assessment. This intermediary score specifically measures the likelihood that an anomaly detection is a false positive caused by structured intentional events, allowing the system to differentiate between true anomalies and false positives without reducing the overall detection rate
Solution Approach 2:
The patent changes the parameter space by adding a new dimension to anomaly assessment - the structured false positive score. Instead of relying solely on the model anomaly risk score, the system now evaluates assets using multiple parameters including the structured false positive score, which is calculated based on the frequency and patterns of intentional events. This parameter change enables more nuanced anomaly risk calculation that accounts for false positives
2Quantity of substance
If the model anomaly risk score is used to identify anomaly assets, then the detection coverage is improved, but the reliability of detected anomalies deteriorates due to structured false positives
Solution Approach 1:
The patent implements a feedback mechanism where the structured false positive score is calculated for each detected anomaly asset and fed back into the anomaly risk assessment process. This feedback loop allows the system to continuously refine its anomaly detection by comparing the structured false positive score against thresholds and adjusting the final anomaly risk score accordingly, thereby improving the reliability of detected anomalies while maintaining detection coverage
Solution Approach 2:
The patent applies partial action by selectively adjusting the anomaly risk score based on the structured false positive score. Rather than discarding all anomaly detections or applying a uniform adjustment, the system selectively reduces the anomaly risk score only for assets where the structured false positive score indicates a high likelihood of false positive, thereby maintaining detection coverage for true anomalies while improving reliability
Data Source
AI summary
Techniques are described with regard to addressing structured false positives in the context of detecting asset anomalies in a computing environment. An associated computer-implemented method includes applying an anomaly detection machine learning model to each of a plurality of assets in order to determine a plurality of anomaly assets among the plurality of assets. The plurality of anomaly assets are determined based upon a model anomaly risk score calculated for each of the plurality of assets consequent to asset event data analysis. The method further includes calculating a structured false positive score for each of the plurality of anomaly assets during a current structured false positive time window. The method further includes retraining the anomaly detection machine learning model responsive to determining that a threshold value of anomaly assets among the plurality of anomaly assets have a structured false positive score exceeding a structured false positive threshold value.


