Automated Incident Generation for Security Alert Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security alert management systems struggle to accurately detect sophisticated attacks like multi-stage advanced persistent threats (APT) due to their reliance on single data sources and require technical expertise, leading to alert fatigue and inefficient incident analysis.

Innovation Solution

A machine learning-based system that aggregates alerts from heterogeneous sources, normalizes them using semantic similarity parameters, enriches them with security-related data, identifies correlation features, and generates automated incidents, thereby reducing alert fatigue and improving incident analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional SIEM systems use readily available statistical features such as timestamps, then the system is easy to operate, but the system cannot precisely detect sophisticated attacks such as multi-stage APT attacks

Engineering Contradiction:
Improvedetection precisionVSAvoidease of operation
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent introduces an intermediary processing layer that transforms raw alerts into enriched incidents with correlated contextual information. This intermediary layer (incident generation module) bridges the gap between simple alert correlation and complex attack detection, enabling precise APT detection without requiring users to manually analyze raw data from multiple sources.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs self-service by automatically enriching alerts with contextual data, correlating events across multiple sources, and generating structured incidents without user intervention. This automation enables the system to achieve high detection precision while maintaining ease of operation, as the complex analysis is performed autonomously.

Inventive Principle:
Principle #25Self-service

2Reliability

If more data sources are ingested in the XDR platform, then better insights in security posture are provided, but more alerts are generated creating alert fatigue

Engineering Contradiction:
Improvesecurity insight qualityVSAvoidalert fatigue
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent merges multiple alerts from heterogeneous data sources into unified incidents by correlating them based on semantic similarity and contextual relationships. This consolidation reduces the volume of individual alerts that contribute to fatigue while preserving the comprehensive security insights from all ingested data sources.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system extracts only the most relevant and correlated alerts to form meaningful incidents, filtering out redundant or low-value alerts. This extraction process reduces alert fatigue by presenting analysts with a focused set of high-priority incidents rather than the complete raw alert volume from all data sources.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If conventional systems consider only a single data source or homogenous sources, then the system complexity is reduced, but security related data from other data sources may be unnoticed

Engineering Contradiction:
Improveattack detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal incident generation framework that can process and correlate data from heterogeneous sources including endpoints, networks, cloud environments, and identity systems. This multi-functional approach enables comprehensive attack detection across diverse data sources while managing complexity through standardized enrichment and correlation processes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes the parameters of alert processing by introducing semantic similarity metrics, contextual enrichment attributes, and correlated event structures. These parameter transformations enable the system to handle heterogeneous data sources effectively, improving detection accuracy while managing complexity through consistent parameter-based processing.

Inventive Principle:
Principle #35Parameter changes

4Measurement precision

If users manually group together a chain of low-level events, then accurate attack understanding is achieved, but the process requires technical expertise and time

Engineering Contradiction:
Improveattack analysis accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary action by pre-enriching alerts with contextual data and pre-correlating events across multiple sources before presentation to analysts. This advance processing reduces the time required for manual analysis while maintaining accurate attack understanding, as the foundational correlation work is already completed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system performs self-service analysis by automatically grouping low-level events into structured incidents with correlated contextual information. This autonomous event chaining eliminates the need for manual analysis while achieving accurate attack understanding through automated correlation algorithms.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12316662B2System and method for automated incident generation
Publication Date: 2025.05.27 STELLAR CYBER INC
  • US12316662B2 patent drawing
  • US12316662B2 patent drawing
  • US12316662B2 patent drawing

AI summary

The disclosure provides a system, a method and a computer program product for generating an automated incident. The system is configured to retrieve an alert of a plurality of alerts received from a plurality of heterogeneous sources. The alert is associated with a security breach. The system further generates a normalized alert based on normalization of the retrieved alert. The normalization is associated with a semantic similarity parameter. Further, the system generates an enriched alert based on enrichment of the generated normalized alert. The enrichment is based on security related data of the security breach associated with the generated normalized alert. The system further identifies a set of correlation features associated with the generated enriched alert. Furthermore, the system generates the automated incident associated with the alert based on at least the generated enriched alert and the identified set of correlation features associated with the enriched alert.