Entity-Centric Alert Consolidation in Enterprise Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise threat detection systems generate a high number of false positive alerts due to similar events triggering alerts for the same user, leading to increased total cost of ownership as each alert requires similar effort to close, even if it's a false positive.
Innovation Solution
The system shifts focus from individual alerts to entities, accumulating pattern results into entity data records, allowing for holistic decision-making on entities such as users, systems, or IP addresses, and automatically closing alerts once all related entities' actions are completed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional alert-based processing is used in ETD systems, then comprehensive monitoring of security events is achieved, but the number of false positive alerts increases significantly
Solution Approach 1:
The patent merges multiple alerts related to the same entity into a single consolidated alert. Instead of treating each security event independently, the system groups events by entity (user, system, IP address) and consolidates them into one alert with aggregated information, thereby reducing the total number of alerts while maintaining comprehensive monitoring coverage.
Solution Approach 2:
The patent creates a universal entity-centric alerting framework that handles multiple types of security events through a common consolidation mechanism. The entity data record serves as a multi-functional container that accumulates various event types and patterns, allowing the system to process diverse security events uniformly and reduce false positives across different event categories.
2Measurement precision
If each alert is processed individually, then detailed analysis of each security event is possible, but the total cost of ownership increases due to repetitive effort
Solution Approach 1:
The patent combines multiple individual alert processing tasks into a single entity-level processing operation. By consolidating alerts that share the same entity, the system performs analysis and mitigation actions once at the entity level rather than repeatedly for each individual alert, significantly reducing processing effort while maintaining detailed analysis capabilities through the accumulated entity data.
Solution Approach 2:
The patent performs preliminary accumulation of event data in entity data records before final alert generation and processing. This preliminary action organizes and aggregates raw events into structured entity profiles, enabling more efficient subsequent analysis and reducing the computational effort required during actual alert processing by having data pre-organized and ready.
3Reliability
If similar events trigger separate alerts for the same user, then each security incident is captured, but the same root cause generates multiple redundant alerts
Solution Approach 1:
The patent merges multiple alerts arising from similar events involving the same entity into a single consolidated alert. The entity data record accumulates all related events and patterns, allowing the system to detect the same root cause once and represent it through one alert rather than generating multiple redundant alerts for the same underlying issue.
Solution Approach 2:
The patent uses entity data records as templates that capture the essential characteristics of security events. Instead of creating separate alert structures for each event, the system copies and accumulates event data into the entity record template, which then serves as the basis for a single comprehensive alert, eliminating redundancy while preserving incident detection capability.
Data Source
AI summary
An enterprise threat detection (ETD) pattern is executed against received log event data from one or more computing systems. Using the ETD pattern, an event threshold is determined to have been exceeded. Entities associated with an alert created based on the exceeded threshold are determined and, at runtime, a severity value is calculated for each determined entity associated with the alert. A selection is received of a determined entity on which to perform mitigation action activities. Mitigation action activities associated with the determined entity are written into an activity record data record. A mitigation action activity is closed on the determined entity and a determination performed that all mitigation action activities associated with all entities related to the created alert have been closed. The created alert is closed.


