Cybersecurity Analytics False Positive Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial network systems face challenges in accurately distinguishing between cyber-security threats and false positive alerts, leading to unnecessary disruptions due to the high rate of false positives generated by behavioral pattern-based analytics engines.
Innovation Solution
A collaborative infrastructure that enables communication between cyber-security analytics engines and asset analytics engines, allowing for the sharing of domain-specific knowledge to correlate anomalies with state changes, thereby reducing false positive alerts by determining if detected anomalies are correlated with rationalized changes in the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If behavioral pattern-based analytics engines are used to detect cyber-security threats, then the system can detect unknown vulnerabilities and zero-day attacks, but the false positive rate increases significantly
Solution Approach 1:
The system segments the detection process into two independent engines: a behavioral pattern-based analytics engine for detecting unknown threats and a targeted analytics engine for verifying specific threats. This segmentation allows each engine to specialize in its strength while the combination reduces false positives through cross-validation.
Solution Approach 2:
A collaboration interface module acts as an intermediary between the two analytics engines, enabling them to share information and coordinate their operations. The module receives anomaly data from the behavioral engine, queries the targeted engine for verification, and integrates their findings to produce final detection results with reduced false positives.
2Measurement precision
If targeted approach is used for cyber-security detection, then false positive rate is reduced, but the system cannot detect newly invented zero-day attacks
Solution Approach 1:
The detection system is divided into two specialized components: a behavioral pattern-based analytics engine that handles adaptability for zero-day attacks, and a targeted analytics engine that handles precision for known threats. Each segment focuses on its strength while the system as a whole achieves both adaptability and precision.
Solution Approach 2:
The collaboration interface module provides universal functionality by enabling both analytics engines to work together. It allows the behavioral engine's adaptive detections to be verified by the targeted engine's precise analysis, creating a multi-functional system that handles both novel and known threats effectively.
3Reliability
If behavioral analysis is used to mitigate zero-day attack risk, then detection capability is improved, but unnecessary automated or human operated action items are triggered
Solution Approach 1:
The system implements a feedback mechanism where the targeted analytics engine validates anomalies detected by the behavioral engine before triggering action items. This feedback loop ensures that only verified threats result in operational disruptions, maintaining security detection capability while preventing unnecessary actions that would reduce productivity.
Solution Approach 2:
The collaboration interface module serves as an intermediary that filters and validates detections before they trigger automated or human operations. By positioning this intermediary between detection and action, the system maintains reliable security detection while preventing productivity losses from false positive disruptions.
Data Source
AI summary
A system comprising a computer-readable storage medium storing at least one program, and a method for reducing cyber-security related false positive alerts is presented. In example embodiments the method may include identifying an indication of a cyber-security threat based on an operational anomaly in a network system. The method may further include determining that the operational anomaly is a false positive indicator with respect to the cyber-security threat based on the operational anomaly being correlated with a malfunction or reconfiguration event.


