Automated Incident Generation for Security Alert Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security alert management systems struggle to accurately detect sophisticated attacks like multi-stage advanced persistent threats (APT) due to their reliance on single data sources and require technical expertise, leading to alert fatigue and inefficient incident analysis.
Innovation Solution
A machine learning-based system that aggregates alerts from heterogeneous sources, normalizes them using semantic similarity parameters, enriches them with security-related data, identifies correlation features, and generates automated incidents, thereby reducing alert fatigue and improving incident analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional SIEM systems use readily available statistical features such as timestamps, then the system is easy to operate, but the system cannot precisely detect sophisticated attacks such as multi-stage APT attacks
Solution Approach 1:
The patent introduces an intermediary processing layer that transforms raw alerts into enriched incidents with correlated contextual information. This intermediary layer (incident generation module) bridges the gap between simple alert correlation and complex attack detection, enabling precise APT detection without requiring users to manually analyze raw data from multiple sources.
Solution Approach 2:
The system performs self-service by automatically enriching alerts with contextual data, correlating events across multiple sources, and generating structured incidents without user intervention. This automation enables the system to achieve high detection precision while maintaining ease of operation, as the complex analysis is performed autonomously.
2Reliability
If more data sources are ingested in the XDR platform, then better insights in security posture are provided, but more alerts are generated creating alert fatigue
Solution Approach 1:
The patent merges multiple alerts from heterogeneous data sources into unified incidents by correlating them based on semantic similarity and contextual relationships. This consolidation reduces the volume of individual alerts that contribute to fatigue while preserving the comprehensive security insights from all ingested data sources.
Solution Approach 2:
The system extracts only the most relevant and correlated alerts to form meaningful incidents, filtering out redundant or low-value alerts. This extraction process reduces alert fatigue by presenting analysts with a focused set of high-priority incidents rather than the complete raw alert volume from all data sources.
3Reliability
If conventional systems consider only a single data source or homogenous sources, then the system complexity is reduced, but security related data from other data sources may be unnoticed
Solution Approach 1:
The patent implements a universal incident generation framework that can process and correlate data from heterogeneous sources including endpoints, networks, cloud environments, and identity systems. This multi-functional approach enables comprehensive attack detection across diverse data sources while managing complexity through standardized enrichment and correlation processes.
Solution Approach 2:
The system changes the parameters of alert processing by introducing semantic similarity metrics, contextual enrichment attributes, and correlated event structures. These parameter transformations enable the system to handle heterogeneous data sources effectively, improving detection accuracy while managing complexity through consistent parameter-based processing.
4Measurement precision
If users manually group together a chain of low-level events, then accurate attack understanding is achieved, but the process requires technical expertise and time
Solution Approach 1:
The patent performs preliminary action by pre-enriching alerts with contextual data and pre-correlating events across multiple sources before presentation to analysts. This advance processing reduces the time required for manual analysis while maintaining accurate attack understanding, as the foundational correlation work is already completed.
Solution Approach 2:
The system performs self-service analysis by automatically grouping low-level events into structured incidents with correlated contextual information. This autonomous event chaining eliminates the need for manual analysis while achieving accurate attack understanding through automated correlation algorithms.
Data Source
AI summary
The disclosure provides a system, a method and a computer program product for generating an automated incident. The system is configured to retrieve an alert of a plurality of alerts received from a plurality of heterogeneous sources. The alert is associated with a security breach. The system further generates a normalized alert based on normalization of the retrieved alert. The normalization is associated with a semantic similarity parameter. Further, the system generates an enriched alert based on enrichment of the generated normalized alert. The enrichment is based on security related data of the security breach associated with the generated normalized alert. The system further identifies a set of correlation features associated with the generated enriched alert. Furthermore, the system generates the automated incident associated with the alert based on at least the generated enriched alert and the identified set of correlation features associated with the enriched alert.


