Automated Contextual Information Building for Security Alert Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Security analysts in a computing arrangement face time-consuming and labor-intensive manual investigations to determine the validity and cause of security alerts, often dealing with sparse information and high false positives, which can lead to inefficient response times.
Innovation Solution
An automated contextual information building system that utilizes a SIEM system to collect event data, generate alerts, and provide richer contextual information to analysts or automated remediation engines, leveraging historical data and past investigations to determine alert similarity, statistics, and correlation, thereby reducing the need for manual hypothesis testing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual investigation is performed by security analysts to determine alert validity, then accurate security issue identification is achieved, but time consumption and labor intensity increase significantly
Solution Approach 1:
The system performs preliminary actions by automatically collecting contextual information, generating hypotheses, and preparing investigation data before human analysts intervene. This pre-processing reduces the time analysts need to spend on each alert while maintaining accuracy.
Solution Approach 2:
An automated investigation generation system acts as an intermediary between alert generation and human analysis. This mediator collects event data, generates contextual information, and prioritizes alerts, thereby reducing the time burden on analysts without compromising validation accuracy.
2Measurement precision
If comprehensive contextual information is collected for each alert, then analysis accuracy improves, but system complexity and data processing requirements increase
Solution Approach 1:
The investigation generation process is segmented into distinct components: event data collection, contextual information generation, hypothesis generation, and alert prioritization. Each component handles specific tasks independently, making the overall complex system manageable and maintainable.
Solution Approach 2:
The automated investigation generation system performs multiple functions within a single unified platform: collecting event data from multiple sources, generating contextual information, creating hypotheses, and prioritizing alerts. This multi-functionality reduces the need for separate systems while maintaining comprehensive analysis capabilities.
3Productivity
If automated systems are used to process alerts, then response speed increases, but ability to handle complex security issues may be reduced
Solution Approach 1:
The system incorporates feedback mechanisms where investigation results and analyst decisions are fed back into the system to improve future automated investigations. This continuous learning enhances the system's ability to handle complex issues while maintaining high processing speed.
Solution Approach 2:
The automated investigation generation system performs self-service by automatically collecting data, generating hypotheses, and prioritizing alerts without requiring constant human intervention. This autonomy maintains high processing speed while the system's sophisticated algorithms ensure complex issues are adequately handled.
Data Source
AI summary
In some examples, an alert relating to an issue in a computing arrangement is received. Contextual information is determined for the alert, the determined contextual information comprising spatial and temporal distributions of previous instances of the alert or similar alerts. The contextual information is communicated for use in addressing the issue in the computing arrangement.


