Context-Aware Malicious Activity Warning System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in distinguishing between benign and malicious activity on computer networks, as granting access rights for benign activities can inadvertently allow malicious activities, and current methods require manual effort to review indicators, leading to inefficiencies in detecting and evaluating potential malicious behavior.
Innovation Solution
A context-aware warning system that automatically collects and analyzes indicators, generates alerts, and provides an interactive user interface for auditors, allowing for efficient evaluation and prioritization of alerts through automated scoring and dynamic re-grouping, filtering, and updating based on past findings and auditor feedback.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If access rights are granted for benign activity, then benign activity can be performed, but malicious activity becomes possible
Solution Approach 1:
The system dynamically changes parameters (risk scores, alert thresholds) based on contextual analysis of entity behavior, allowing access rights to be adjusted in real-time without completely restricting benign activity
Solution Approach 2:
The system implements feedback loops where auditor responses to alerts refine future risk assessments, allowing the system to learn from past decisions and improve differentiation between benign and malicious activity over time
2Measurement precision
If manual review of indicators is performed, then accurate detection of malicious activity is achieved, but time and effort requirements increase
Solution Approach 1:
The system introduces an automated scoring mechanism as an intermediary that pre-evaluates indicators and generates prioritized alerts, reducing the manual review burden while maintaining detection accuracy through contextual analysis
Solution Approach 2:
The system applies partial automation by focusing manual review efforts only on high-priority alerts that exceed dynamically adjusted thresholds, rather than requiring review of all indicators
3Measurement precision
If comprehensive indicators are collected for analysis, then detection accuracy improves, but system complexity increases
Solution Approach 1:
The system segments the complex analysis task into distinct components: automated collection of indicators, contextual analysis, scoring mechanisms, and alert generation, allowing each component to be optimized independently
4Productivity
If automated scoring and filtering are implemented, then productivity increases, but false positives may increase
Solution Approach 1:
The system implements dynamic threshold adjustment where alert thresholds adapt based on auditor feedback and historical data, allowing the system to maintain high productivity while reducing false positives over time through continuous learning
Data Source
AI summary
A computer system is configured to generate alerts related to malicious activity on an audited computing system. The computing system is provided with instructions to receive activity information associated with activity of an entity performed in an audited computing network, access contextual information associated with the entity, determine, based on the contextual information, a set of weights associated with the activity information and combine the weight and the entity activity information to generate a risk score. In response to the risk score satisfying a threshold value, the computer system may generate an alert, and, in response to receiving a user input associated with the alert, update the set of weights. In certain embodiments, the updated weights may be used for determining the risk score of future alerts.


