Cross-Agent Security Alert Prediction for Proactive Remediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems reactively address security issues, allowing attacks to progress and cause damage before effective remediation can be implemented.

Innovation Solution

A proactive security system predicts a collection of alerts using machine learning and signature-based methods, generating preemptive remediation actions based on patterns of alerts detected by diverse security agents.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If reactive security measures are used, then system complexity is reduced, but security effectiveness deteriorates because attacks progress and cause damage before remediation

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by predicting future security alerts before they occur. When a current alert is detected, the system uses machine learning models to predict a collection of future alerts that are likely to occur, and preemptively applies remediation actions for those predicted alerts before the actual security threats materialize. This transforms reactive security into proactive security, preventing attacks before they can cause damage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security system serves itself by automatically predicting future alerts and generating remediation actions without requiring external intervention. The machine learning models continuously learn from alert patterns and automatically adjust predictions, while the system autonomously applies remediation actions based on predicted threats, reducing the need for manual security management while improving effectiveness.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If multiple security agents are deployed, then detection capability is improved, but false alert volume increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidfalse alert volume
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The system merges the outputs of multiple diverse security agents by collecting alerts from various sources including endpoint detection and response agents, network detection and response agents, cloud-based security agents, and host-based agents. Instead of treating each agent's alerts independently, the system combines them into a unified analysis framework where machine learning models evaluate patterns across all alerts, distinguishing true threats from false positives by analyzing correlations and sequences among multiple alert sources.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12381905B2Remediation responsive to a pattern of alerts
Publication Date: 2025.08.05 BLACKBERRY LTD
  • US12381905B2 patent drawing
  • US12381905B2 patent drawing
  • US12381905B2 patent drawing

AI summary

In some examples, a system detects a first alert associated with activities of a first group of entities, the first alert generated by a first type of security agent. The system predicts an alert collection including one or more alerts expected to occur based on occurrence of the first alert, wherein a second alert of the alert collection is from a second type of security agent different from the first type of security agent. The system generates one or more remediation actions to apply in response to a pattern of alerts including the first alert and the one or more alerts of the alert collection. The system provides, in an electronic device to be protected against attacks, information of the one or more remediation actions to be applied by the electronic device responsive to occurrence of the pattern of alerts.