Cluster Alert Correlation for Cyber Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed computing systems, security analysts face challenges in distinguishing between valid attack alerts and benign noise, making it difficult to identify and mitigate cyber-attacks due to the high volume of alerts and the need for manual correlation of alerts across multiple systems.

Innovation Solution

A method is implemented in a cluster computing environment to collect and group alerts, identify patterns, and correlate them into clusters based on valid cyber-kill chains, using statistical models and machine learning to notify entities of potential attacks, thereby filtering out noise and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security analysts manually review all security alerts to identify attacks, then detection accuracy may improve, but the time and resources required increase significantly due to the large volume of alerts

Engineering Contradiction:
Improvedetection accuracyVSAvoidtime to analyze alerts
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the large volume of alerts into smaller, manageable groups based on temporal proximity and source-destination relationships. By dividing alerts into discrete analysis units, the system makes manual review feasible while maintaining comprehensive coverage, thus balancing detection accuracy with analyst time investment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary automated grouping and filtering of alerts before presenting them to security analysts. This pre-processing step organizes alerts into meaningful sequences and removes obvious noise, allowing analysts to focus their expertise on already-prepared candidate groups, thereby reducing analysis time while preserving detection accuracy.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If all alerts are analyzed in detail to distinguish valid attacks from benign noise, then false positives may be reduced, but the complexity of the analysis process increases

Engineering Contradiction:
Improvefalse positive rateVSAvoidanalysis process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments alerts into distinct groups based on temporal and contextual relationships, allowing the system to apply different analysis strategies to different segments. This segmentation enables focused examination of only those alert groups that exhibit characteristics of potential attacks, reducing false positives without requiring complex analysis of every individual alert.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies different levels of analysis to different alert groups based on their characteristics. Alert groups that match known attack patterns receive more rigorous scrutiny, while benign-looking groups receive lighter processing. This localized quality approach improves reliability for critical cases without uniformly increasing complexity across all alerts.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If manual correlation of alerts across multiple systems is performed to identify attack patterns, then detection precision improves, but productivity decreases due to the manual effort required

Engineering Contradiction:
Improveattack pattern detection precisionVSAvoidalert analysis throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system performs preliminary automated correlation of alerts across multiple systems, pre-identifying potential attack patterns and organizing them into sequences. This preliminary action creates ready-to-analyze groups that maintain high detection precision while significantly reducing the manual correlation effort required, thereby improving overall productivity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates simplified representations or copies of complex multi-system alert sequences, presenting condensed versions to analysts that retain the essential attack pattern information. This copying approach maintains detection precision by preserving key relationships while improving productivity by reducing the complexity of manual review.

Inventive Principle:
Principle #26Copying

4Speed

If the system processes and correlates all alerts in real-time, then response time to attacks improves, but the computational resources and system complexity increase

Engineering Contradiction:
Improveattack detection speedVSAvoidsystem complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent segments the real-time alert processing workload into manageable chunks based on temporal windows and source-destination pairs. This segmentation allows the system to process alerts in discrete batches with controlled resource requirements, maintaining fast response times while preventing overwhelming system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system processes alert groups in priority order, focusing computational resources on the most suspicious or critical groups first. By applying partial processing to less critical alerts and excessive processing to high-priority alerts, the system achieves effective real-time response for attacks while managing overall system complexity and resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10474966B2Detecting cyber attacks by correlating alerts sequences in a cluster environment
Publication Date: 2019.11.12 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10474966B2 patent drawing
  • US10474966B2 patent drawing
  • US10474966B2 patent drawing

AI summary

Providing network entities with notifications of attacks on the entities. A method includes collecting alerts from a plurality of network entities in a cluster computing environment. Alerts are grouped into heterogeneous groups of alerts. Each group includes a plurality of different types of alerts. Each alert has corresponding properties, including at least one property identifying the type of alert. Each group of alerts corresponds to a timeline of alerts for a particular entity. Groups of alerts that correspond to a valid cyber-kill chain are identified. Different groups of alerts that correspond to a valid cyber-kill chain are correlated into clusters of groups of alerts by correlating the types of alerts and corresponding properties. At least one cluster is identified as having some characteristic of interest. Entities corresponding to groups of alerts in the cluster are notified of the characteristic of interest.