Edge Alert Correlation for Cyber-Physical System Alert Fatigue

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cyber-physical system operators experience alert fatigue due to numerous true and false positive alerts, leading to ignored alerts and increased resource use, which is critical in systems with limited size, weight, and power.

Innovation Solution

Implementing an edge computing system monitor that analyzes data patterns using a domain-specific Happened-Before-Language (HBL) to detect order-dependent properties, suppress alerts exceeding thresholds, and compare against a seen-list of authorized components and relationships to reduce unnecessary alerts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If real-time alerts are generated for all detected incidents including false positives, then operator awareness of potential threats is improved, but alert fatigue increases leading to ignored alerts and increased resource consumption

Engineering Contradiction:
Improveoperator awareness of threatsVSAvoidalert analysis efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary analysis of alert patterns and correlates multiple alerts before generating notifications to operators. By pre-processing and aggregating alert data, the system eliminates false positives and redundant notifications before they reach the operator, ensuring only meaningful threats are communicated.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary alert correlation system between the incident detection mechanisms and the operator interface. This intermediary layer processes, filters, and synthesizes alerts from multiple sources, transforming raw incident data into curated threat notifications that reduce fatigue while maintaining awareness.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple monitoring tools and alert generation mechanisms are deployed to detect all possible threats, then detection coverage is improved, but the volume of redundant and false positive alerts increases

Engineering Contradiction:
Improvethreat detection coverageVSAvoidnumber of alerts
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges data from multiple monitoring tools and alert generation mechanisms into a unified correlation system. By combining inputs from various security tools and analyzing them collectively, the system identifies patterns that indicate genuine threats while filtering out isolated false positives that would otherwise multiply the alert volume.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The alert correlation system serves multiple functions simultaneously: it aggregates alerts from diverse sources, correlates patterns across different tool outputs, filters false positives, and generates consolidated notifications. This multi-functional approach maintains comprehensive detection coverage while reducing the quantity of alerts presented to operators.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If operators respond to each alert individually through bureaucratic processes and permission requests, then security protocols are maintained, but response time increases and resources are consumed

Engineering Contradiction:
Improvesecurity protocol complianceVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary correlation and validation of alerts before presenting them to operators, pre-authorizing responses for confirmed threat patterns. By pre-processing alerts and establishing correlation-based authorization, the system reduces the need for time-consuming bureaucratic processes while maintaining security protocol compliance.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12381773B2Systems and methods for reducing alert fatigue during operation of cyber-physical systems
Publication Date: 2025.08.05 THE MITRE CORPORATION
  • US12381773B2 patent drawing
  • US12381773B2 patent drawing
  • US12381773B2 patent drawing

AI summary

Disclosed herein are systems and methods for reducing or mitigation alert fatigue from real-time alerts in cyber-physical systems or other types of edge computing systems are provided. In one or more examples, the edge computing system monitor can look for one or more patterns within received data that can indicate malicious activity or other conditions that may warrant a real-time or near-real time response from the operator. In one or more examples, a detection of any of the specified patterns in the streaming data can trigger an alert to the operator of the edge computing system. In one or more examples, the alerts can be suppressed until the number of alerts associated with a particular pattern crosses a pre-determined threshold. Additionally or alternatively, alerts can be suppressed based on a duration that the alerts have been generated. The suppression of alerts can be configured to reduce operator alert fatigue.