Cybersecurity Analytics False Positive Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial network systems face challenges in accurately distinguishing between cyber-security threats and false positive alerts, leading to unnecessary disruptions due to the high rate of false positives generated by behavioral pattern-based analytics engines.

Innovation Solution

A collaborative infrastructure that enables communication between cyber-security analytics engines and asset analytics engines, allowing for the sharing of domain-specific knowledge to correlate anomalies with state changes, thereby reducing false positive alerts by determining if detected anomalies are correlated with rationalized changes in the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If behavioral pattern-based analytics engines are used to detect cyber-security threats, then the system can detect unknown vulnerabilities and zero-day attacks, but the false positive rate increases significantly

Engineering Contradiction:
Improvedetection capabilityVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The system segments the detection process into two independent engines: a behavioral pattern-based analytics engine for detecting unknown threats and a targeted analytics engine for verifying specific threats. This segmentation allows each engine to specialize in its strength while the combination reduces false positives through cross-validation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A collaboration interface module acts as an intermediary between the two analytics engines, enabling them to share information and coordinate their operations. The module receives anomaly data from the behavioral engine, queries the targeted engine for verification, and integrates their findings to produce final detection results with reduced false positives.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If targeted approach is used for cyber-security detection, then false positive rate is reduced, but the system cannot detect newly invented zero-day attacks

Engineering Contradiction:
Improvefalse positive rateVSAvoiddetection coverage
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The detection system is divided into two specialized components: a behavioral pattern-based analytics engine that handles adaptability for zero-day attacks, and a targeted analytics engine that handles precision for known threats. Each segment focuses on its strength while the system as a whole achieves both adaptability and precision.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The collaboration interface module provides universal functionality by enabling both analytics engines to work together. It allows the behavioral engine's adaptive detections to be verified by the targeted engine's precise analysis, creating a multi-functional system that handles both novel and known threats effectively.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If behavioral analysis is used to mitigate zero-day attack risk, then detection capability is improved, but unnecessary automated or human operated action items are triggered

Engineering Contradiction:
Improvesecurity detectionVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements a feedback mechanism where the targeted analytics engine validates anomalies detected by the behavioral engine before triggering action items. This feedback loop ensures that only verified threats result in operational disruptions, maintaining security detection capability while preventing unnecessary actions that would reduce productivity.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The collaboration interface module serves as an intermediary that filters and validates detections before they trigger automated or human operations. By positioning this intermediary between detection and action, the system maintains reliable security detection while preventing productivity losses from false positive disruptions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10063580B2Collaborative infrastructure supporting cyber-security analytics in industrial networks
Publication Date: 2018.08.28 GE DIGITAL HLDG LLC
  • US10063580B2 patent drawing
  • US10063580B2 patent drawing
  • US10063580B2 patent drawing

AI summary

A system comprising a computer-readable storage medium storing at least one program, and a method for reducing cyber-security related false positive alerts is presented. In example embodiments the method may include identifying an indication of a cyber-security threat based on an operational anomaly in a network system. The method may further include determining that the operational anomaly is a false positive indicator with respect to the cyber-security threat based on the operational anomaly being correlated with a malfunction or reconfiguration event.