Automated Security Incident Analysis Using Machine Learning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems generate numerous anomalies that can indicate either legitimate or malicious activities, requiring manual investigation by incident response teams, which is time-consuming and often results in delayed incident remediation due to incompatibility issues between different security products.

Innovation Solution

Implementing a system that uses machine-learning approaches, such as neural networks or Bayesian networks, to analyze security signals and predict the likely response of incident response teams, allowing for automated or notified remedial actions to be taken based on compliance policies and confidence scores.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual investigation by incident response team is used to analyze security anomalies, then accuracy in determining legitimate vs malicious activities is improved, but time consumption and response delay increase

Engineering Contradiction:
Improveaccuracy in determining security threatVSAvoidtime to identify and remediate security incidents
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent introduces an intermediary system that sits between security products and incident response teams. This system automatically collects security signals from multiple incompatible security products, analyzes them using machine learning, and presents consolidated findings to the incident response team, reducing their manual analysis burden while maintaining accuracy

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical manual investigation process with an automated machine learning system. The system uses trained models to automatically classify security anomalies as legitimate or malicious, substituting human manual analysis with automated computational analysis that operates faster and at scale

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If multiple security products from different vendors are deployed to detect security threats, then detection capability and coverage are improved, but system complexity and compatibility issues increase

Engineering Contradiction:
Improvesecurity threat detection capabilityVSAvoidcomplexity of integrating multiple security products
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal system that can ingest and process security signals from multiple different security product vendors. The system uses standardized data collection and machine learning models that work across different security product types, providing multi-functional analysis capability without requiring separate analysis pipelines for each vendor

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system acts as an intermediary layer that standardizes communication between incompatible security products. It collects signals from various vendors through unified interfaces, normalizes the data, and processes it through consistent machine learning models, eliminating direct compatibility requirements between security products

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If incident response team manually cross-references anomalies from different security products, then ability to identify related anomalies is improved, but productivity and response speed decrease

Engineering Contradiction:
Improveability to identify related anomaliesVSAvoidspeed of security incident identification
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent replaces the manual cross-referencing process with automated machine learning analysis. The system automatically correlates security signals from multiple sources, identifies patterns and relationships between anomalies, and presents consolidated findings, performing the cross-referencing function computationally rather than manually

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs continuous automated analysis of security signals, constantly cross-referencing and correlating anomalies in real-time. This continuous automated process replaces the intermittent manual cross-referencing that occurs only when the incident response team reviews anomalies, maintaining persistent correlation capability

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11418543B2Automated identification of security issues
Publication Date: 2022.08.16 OMNISSA LLC
  • US11418543B2 patent drawing
  • US11418543B2 patent drawing
  • US11418543B2 patent drawing

AI summary

Disclosed are various approaches for automating the detection and identification of security issues. A plurality of signals received from a plurality of security devices are analyzed to identify a predicted security incident, each of the plurality of signals indicating a potential security issue. A confidence score is then calculated for the predicted security incident. At least one compliance policy is then evaluated to determine whether to perform a remedial action specified in the compliance policy, wherein a determination to perform the remedial action is based at least in part on the confidence score. Finally, the remedial action is performed in response to an evaluation of the at least one compliance policy.