Cyber Security Alert Triage via Metadata Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems generate excessive false alarms in cyber security threat monitoring, requiring human operators to spend resources investigating non-negligible false alarms, which is time-consuming and prone to human error.

Innovation Solution

The system employs metadata correlation to differentiate between true and false alerts, utilizing machine learning models to provide a confidence score and recommended actions, along with visualizations in a Case Management tool to expedite the triage process, and maps activities to tactics and techniques to identify the end goal of malicious attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hundreds of rules/detectors are used to identify threats, then threat detection capability is improved, but false alarm rate increases

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidfalse alarm rate
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent introduces an intermediary machine learning classification system between the threat detection rules and human analysts. This intermediary layer automatically processes alerts generated by hundreds of rules/detectors, filtering out false alarms and prioritizing genuine threats before they reach human operators, thus resolving the contradiction between comprehensive detection and false alarm reduction

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual mechanical review of alerts by human operators with an automated machine learning-based classification system. This substitution enables the system to process large volumes of alerts generated by multiple rules without human intervention, maintaining high detection capability while significantly reducing false alarms that would otherwise require manual investigation

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If human operators manually review alerts and log files, then accuracy of threat identification is improved, but time consumption increases

Engineering Contradiction:
Improveaccuracy of threat identificationVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by having the machine learning system pre-classify alerts and log files before human operators review them. The system automatically analyzes alert data, correlates it with contextual information, and pre-determines threat likelihood, so that when human operators do review items, they only need to verify pre-identified threats rather than conducting comprehensive manual analysis from scratch

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a digital copy of the alert triage process through machine learning models that replicate and enhance human analyst capabilities. The ML system copies the analytical functions of human operators but executes them at scale and speed, providing accurate threat identification without the time consumption inherent in manual review of hundreds of alerts and distributed log files

Inventive Principle:
Principle #26Copying

3Measurement precision

If comprehensive data review across many systems is performed, then accuracy of threat assessment is improved, but operational complexity increases

Engineering Contradiction:
Improveaccuracy of threat assessmentVSAvoidoperational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges the complexity of reviewing data across many distributed systems into a single unified machine learning processing layer. Instead of requiring operators to manually navigate multiple systems and log files, the ML system consolidates data from all sources, correlates it with contextual information, and presents a simplified threat assessment, thus maintaining high accuracy while reducing operational complexity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements a universal machine learning platform that handles multiple functions: alert classification, contextual data correlation, threat assessment, and priority ranking. This multi-functional system replaces the need for operators to manually query and review data across many different systems, maintaining comprehensive accuracy while simplifying the operational interface to a single integrated tool

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11785040B2Systems and methods for cyber security alert triage
Publication Date: 2023.10.10 CAPITAL ONE SERVICES LLC
  • US11785040B2 patent drawing
  • US11785040B2 patent drawing
  • US11785040B2 patent drawing

AI summary

The present disclosure is directed to systems, apparatuses and methods for mitigating cyber-attacks. For example, the method includes receiving, from one or more network devices tracking activity on a network, one or more data streams associated with a respective one of the one or more network devices, identifying a security alert from the one or more data streams, the security alert including metadata context describing the network device from the one or more network devices that originated the security alert, analyzing the metadata context to generate a metadata context score. When the security alert is determined to be a security threat event, classifying a type of the security threat event based on the related activity score and the metadata context, and outputting a recommended mitigation course of action based on the classified type of the security threat event.