Cross-Organization Security Alert Scoring Using User Feedback

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security platforms generate overwhelming numbers of alerts, overwhelming security professionals and leading to inefficiencies and potential financial losses due to manual review challenges and human errors.

Innovation Solution

A security platform that adjusts alert properties based on user feedback across organizations, using similarity scores and machine learning to modify alert severity, priority, and confidence levels, thereby improving alert accuracy and reducing false positives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual review of security alerts is performed, then security professionals can investigate and respond to alerts, but the process is time-consuming and overwhelming leading to inefficiency and human errors

Engineering Contradiction:
Improvealert response accuracyVSAvoidtime for manual alert review
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service by having the security platform automatically adjust alert properties based on feedback from security professionals. The platform learns from user interactions and autonomously modifies future alert severity, priority, and confidence levels without requiring continuous manual intervention, thereby reducing time loss while maintaining response accuracy

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms where security professionals provide input on alert accuracy and relevance. This feedback is processed to automatically adjust alert properties for future detections, creating a continuous improvement loop that reduces manual review time while improving the reliability of alert responses

Inventive Principle:
Principle #23Feedback

2Reliability

If security platforms generate comprehensive alerts for all malicious activity, then threat coverage is improved, but the number of alerts becomes overwhelming causing false positives and reducing efficiency

Engineering Contradiction:
Improvethreat coverageVSAvoidnumber of alerts
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system dynamically changes alert parameters including severity, priority, and confidence levels based on learned patterns from security professional feedback. By adjusting these parameters automatically, the system maintains comprehensive threat coverage while filtering out false positives and reducing the overall quantity of alerts that require manual attention

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system applies different alert properties to different alerts based on their specific characteristics and the feedback learned for similar patterns. Instead of uniform treatment, each alert receives customized properties tailored to its context, improving threat coverage for genuine threats while reducing noise from false positives

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250247401A1Security alerts across organizations
Publication Date: 2025.07.31 GOOGLE LLC
  • US20250247401A1 patent drawing
  • US20250247401A1 patent drawing
  • US20250247401A1 patent drawing

AI summary

A method includes obtaining a first set of data pertaining to a first alert generated with respect to first malicious activity relating to a first set of computing devices of a first entity. The first set of data includes the first alert, first metadata for first malicious activity associated with the first alert, and first user feedback relating to the first alert and provided by a first user associated with the first entity. The method further includes identifying second malicious activity relating to a second set of computing devices of a second entity, the second malicious activity having second metadata. The method further includes generating a first similarity score based on a comparison of the first metadata and the second metadata and causing a second alert generated with respect to the second malicious activity to be associated with first alert properties defined based on the first user feedback.