Cybersecurity Analytics Feedback Control for False Positive Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cybersecurity analytics in cloud-based systems often generate numerous false positives and noise due to frequent IT environment changes, making it difficult for providers to maintain accuracy and reliability of threat detection.

Innovation Solution

Implement a cloud-based cybersecurity application that evaluates the performance of analytics using machine learning and applies corrective actions, such as throttling or disabling, to reduce false positives and noise in the outputs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cybersecurity analytics are applied to detect threats in cloud-based systems, then threat detection capability is improved, but the number of false positives and noise increases due to frequent IT environment changes

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidfalse positives and noise
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The system continuously monitors analytics performance by evaluating detected threats against predefined criteria and feeds this information back to adjust analytics behavior. This feedback loop enables the system to learn from past performance and reduce false positives dynamically, resolving the contradiction between detection capability and false positive rate

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The analytics system dynamically adjusts its detection parameters and thresholds based on changing IT environment conditions and historical performance data. This dynamic adaptation allows the system to maintain high detection accuracy while minimizing false positives in evolving cloud environments

Inventive Principle:
Principle #15Dynamics

2Reliability

If analytics performance is continuously monitored and adjusted to reduce false positives, then threat detection reliability is improved, but system complexity increases

Engineering Contradiction:
Improveanalytics output reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically monitors its own performance and applies corrective actions without requiring external intervention. The self-service mechanism simplifies operational complexity while maintaining high reliability through automated performance evaluation and adaptive adjustments

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system manages complexity by focusing on key performance parameters (such as false positive rate and detection accuracy) rather than attempting to control all system variables. This parameter-driven approach simplifies monitoring and adjustment processes while improving analytics reliability

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250379881A1Systems And Methods For Reducing False Positives In Cybersecurity Analytics Results
Publication Date: 2025.12.11 CISCO TECHNOLOGY INC
  • US20250379881A1 patent drawing
  • US20250379881A1 patent drawing
  • US20250379881A1 patent drawing

AI summary

In a computer-implemented method for managing analytic results in a cybersecurity system, data representing a plurality of events are accessed, where the plurality of events include machine data generated by entities that are part of or that interact with a computer network. A cybersecurity analytic of a cybersecurity application is applied to the data to produce analytic results, wherein the cybersecurity analytic is to detect a cybersecurity-related anomaly or threat. A performance of the cybersecurity analytic is then evaluated by applying the analytic results to a specified performance criterion. A corrective action for the cybersecurity analytic is then determined, based on a result of evaluating the performance of the cybersecurity analytic. Zero or more anomaly or threat detections by the cybersecurity analytic are then incorporated into an output of the cybersecurity application, based on the determined corrective action.