Cyber Security Alert Triage via Metadata Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems generate excessive false alarms in cyber security threat monitoring, requiring human operators to spend resources investigating non-negligible false alarms, which is time-consuming and prone to human error.
Innovation Solution
The system employs metadata correlation to differentiate between true and false alerts, utilizing machine learning models to provide a confidence score and recommended actions, along with visualizations in a Case Management tool to expedite the triage process, and maps activities to tactics and techniques to identify the end goal of malicious attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hundreds of rules/detectors are used to identify threats, then threat detection capability is improved, but false alarm rate increases
Solution Approach 1:
The patent introduces an intermediary machine learning classification system between the threat detection rules and human analysts. This intermediary layer automatically processes alerts generated by hundreds of rules/detectors, filtering out false alarms and prioritizing genuine threats before they reach human operators, thus resolving the contradiction between comprehensive detection and false alarm reduction
Solution Approach 2:
The patent replaces manual mechanical review of alerts by human operators with an automated machine learning-based classification system. This substitution enables the system to process large volumes of alerts generated by multiple rules without human intervention, maintaining high detection capability while significantly reducing false alarms that would otherwise require manual investigation
2Measurement precision
If human operators manually review alerts and log files, then accuracy of threat identification is improved, but time consumption increases
Solution Approach 1:
The patent applies preliminary action by having the machine learning system pre-classify alerts and log files before human operators review them. The system automatically analyzes alert data, correlates it with contextual information, and pre-determines threat likelihood, so that when human operators do review items, they only need to verify pre-identified threats rather than conducting comprehensive manual analysis from scratch
Solution Approach 2:
The patent creates a digital copy of the alert triage process through machine learning models that replicate and enhance human analyst capabilities. The ML system copies the analytical functions of human operators but executes them at scale and speed, providing accurate threat identification without the time consumption inherent in manual review of hundreds of alerts and distributed log files
3Measurement precision
If comprehensive data review across many systems is performed, then accuracy of threat assessment is improved, but operational complexity increases
Solution Approach 1:
The patent merges the complexity of reviewing data across many distributed systems into a single unified machine learning processing layer. Instead of requiring operators to manually navigate multiple systems and log files, the ML system consolidates data from all sources, correlates it with contextual information, and presents a simplified threat assessment, thus maintaining high accuracy while reducing operational complexity
Solution Approach 2:
The patent implements a universal machine learning platform that handles multiple functions: alert classification, contextual data correlation, threat assessment, and priority ranking. This multi-functional system replaces the need for operators to manually query and review data across many different systems, maintaining comprehensive accuracy while simplifying the operational interface to a single integrated tool
Data Source
AI summary
The present disclosure is directed to systems, apparatuses and methods for mitigating cyber-attacks. For example, the method includes receiving, from one or more network devices tracking activity on a network, one or more data streams associated with a respective one of the one or more network devices, identifying a security alert from the one or more data streams, the security alert including metadata context describing the network device from the one or more network devices that originated the security alert, analyzing the metadata context to generate a metadata context score. When the security alert is determined to be a security threat event, classifying a type of the security threat event based on the related activity score and the metadata context, and outputting a recommended mitigation course of action based on the classified type of the security threat event.


