Cybersecurity Alert Bucketing for Attack Graph Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing complexity of cybersecurity attacks leads to a surge in data collection, resulting in higher rates of false-positive cybersecurity alerts, which can cause analyst fatigue.
Innovation Solution
An apparatus and method that utilize a processor to receive cybersecurity alerts, identify associated buckets in a hash table, update sets of alerts, generate attack graphs, and determine maliciousness scores to automatically trigger remedial actions when scores exceed a predetermined range.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data collection is increased to monitor complex cybersecurity attacks, then detection capability is improved, but the number of false-positive alerts increases
Solution Approach 1:
The patent segments cybersecurity alerts into different buckets based on their attributes (e.g., IP address, port number, protocol). This segmentation allows the system to process and analyze alerts in organized groups rather than as a monolithic stream, enabling more precise correlation and reducing false positives while maintaining comprehensive monitoring capability.
Solution Approach 2:
The patent introduces an intermediary correlation analysis layer that processes alerts through multiple stages: initial alert generation, bucket assignment, correlation analysis, and final attack graph construction. This intermediary processing layer filters and refines alerts before final detection, reducing false positives while preserving true threats.
2Adaptability or versatility
If the number of cybersecurity alerts is increased to monitor complex attacks, then monitoring coverage is improved, but analyst fatigue increases
Solution Approach 1:
The patent implements self-service through automated correlation analysis and attack graph generation. The system automatically processes alerts, identifies patterns, constructs attack graphs, and prioritizes threats without requiring manual analyst intervention for each alert. This automation reduces analyst fatigue while maintaining comprehensive monitoring coverage.
Solution Approach 2:
The patent incorporates feedback mechanisms where the system continuously learns from alert patterns and adjusts its correlation analysis. The attack graph construction provides feedback about the severity and context of alerts, allowing the system to prioritize truly malicious activities while filtering benign noise, thereby reducing analyst workload.
3Measurement precision
If correlation analysis is performed on all cybersecurity alerts, then attack detection accuracy is improved, but processing time increases
Solution Approach 1:
The patent segments alerts into buckets based on their attributes before performing correlation analysis. This segmentation reduces the correlation analysis from processing all alerts against each other to processing only relevant alerts within each bucket, significantly reducing processing time while maintaining detection accuracy.
Solution Approach 2:
The patent applies partial correlation analysis by focusing correlation efforts on alerts that share common attributes or are located in the same bucket, rather than performing exhaustive correlation on all alerts. This partial action approach maintains sufficient detection accuracy while dramatically reducing processing time.
Data Source
AI summary
A stream of cybersecurity alerts is received. Each cybersecurity alert from the stream of cybersecurity alerts is associated with a set of attributes. Each cybersecurity alert from the stream of cybersecurity alerts is associated, based on the set of attributes and as that cybersecurity alert is received, to a bucket from a set of buckets. Each bucket from the set of buckets is associated with (1) an attribute from the set of attributes different than remaining buckets from the set of buckets and (2) a set cybersecurity alerts from the stream of cybersecurity alerts having the attribute. For each bucket from the set of buckets, a set of correlations between cybersecurity alerts included in the set of cybersecurity alerts for that bucket are determined, based on the set of cybersecurity alerts for that bucket, to generate an attack graph associated with that bucket.


