Global Correlation Engine Reducing False Positives in Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large and complex organizations, existing network security systems face challenges in distinguishing between genuine security threats and false positives, leading to overwhelming volumes of alerts that hinder effective response to imminent cyber-attacks.

Innovation Solution

A computer-implemented method using a Global Correlation Engine (GCE) that maps security alerts to cyber-attack techniques based on a reference model, determines relationships through a correlation matrix of previous attacks, and issues alerts based on combined confidence scores and threshold analysis, reducing false positives by identifying patterns and connections between alerts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing network security tools are deployed to detect and alert security threats, then the ability to identify security events is improved, but the volume of false positive alerts increases significantly

Engineering Contradiction:
Improvesecurity threat detection capabilityVSAvoidvolume of security alerts
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent combines multiple security detection tools (endpoint detection, network security tools, cloud security tools) into a unified security information and event management (SIEM) platform. This consolidation allows centralized correlation of alerts from various sources, enabling the system to identify patterns and relationships between alerts that would be difficult to detect when analyzing them in isolation, thereby reducing false positives while maintaining comprehensive threat detection.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements feedback mechanisms where alerts are continuously correlated with historical data and patterns from previous security events. The SIEM platform learns from past incidents and adjusts its alerting behavior accordingly, providing feedback loops that help distinguish between genuine threats and false positives by comparing current alerts against established baselines and patterns.

Inventive Principle:
Principle #23Feedback

2Reliability

If security tools issue alerts for all detected security events, then the completeness of threat identification is improved, but the difficulty of separating false alarms from genuine threats increases

Engineering Contradiction:
Improvecompleteness of threat identificationVSAvoiddifficulty of identifying genuine threats
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces correlation rules and analytical processing as intermediary mechanisms between raw security alerts and security analyst review. These intermediaries automatically filter, prioritize, and contextualize alerts by correlating them with known attack patterns, threat intelligence, and historical data, thereby reducing the manual effort required to distinguish genuine threats from false positives while maintaining comprehensive threat identification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system replaces manual analysis of individual alerts with automated correlation engines and machine learning algorithms. These computational systems process and correlate alerts at scales impossible for human analysts, using pattern recognition and statistical analysis to automatically identify genuine threats amidst voluminous alert data, thereby substituting mechanical human analysis with more efficient computational processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If multiple security components are deployed across the network to monitor activity, then the coverage of security monitoring is improved, but the complexity of correlating alerts from different sources increases

Engineering Contradiction:
Improvesecurity monitoring coverageVSAvoidcomplexity of alert correlation system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal SIEM platform that serves multiple functions: collecting alerts from diverse security components, normalizing data from different sources, correlating events across the entire network, generating consolidated reports, and providing response capabilities. This multi-functional system handles the complexity of correlating alerts from endpoint detection tools, network security appliances, and cloud security services through a single unified interface and correlation engine.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system transforms alerts from multiple security components by changing their parameters into a standardized format. The SIEM platform normalizes diverse alert structures, time formats, and data schemas into consistent parameters that enable efficient correlation and analysis, thereby managing the complexity of integrating data from heterogeneous security sources through parameter standardization.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12095784B2Methods and systems for indicating the possibility of a cyber-attack on a computer network
Publication Date: 2024.09.17 LLOYDS BANKING GRP PLC
  • US12095784B2 patent drawing
  • US12095784B2 patent drawing
  • US12095784B2 patent drawing

AI summary

A computer-implemented method for indicating the possibility of a cyber-attack on a computer network, comprising: receiving, from one or more security components installed in a network, an indication of activity within the network associated with a security threat; mapping the indication of activity to one or more cyber-attack techniques; identifying one or more previously received indications of activity within the network associated with a security threat; identifying one or more cyber-attack techniques to which the previously received indication(s) of activity have been mapped; determining whether the indication of activity is associated with one or more of the previously received indication(s) of activity, the determination based at least in part on a strength of a relationship between the one or more cyber-attack techniques to which the indication of activity is mapped and the one or more cyber-attack techniques to which the previously received indication(s) of activity have been mapped; and dependent on the indication of activity being determined to be associated with a previously received indication of activity, issuing a security alert.