Intrusion Detection Clustering for False Positive Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Intrusion detection systems face challenges in distinguishing between malicious and legitimate activities, leading to false positives and resource-intensive alerts, which can obscure true attack detection.
Innovation Solution
A method that identifies malicious events by determining entity distances and clustering events that bring organizationally or functionally distant entities closer, using static and dynamic metrics to rank events and generate alerts for suspicious activity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If intrusion detection is too strict, then malicious attacks are detected more accurately, but false positive alerts increase and normal workflow is disturbed
Solution Approach 1:
The patent segments the detection process into multiple stages: initial alert generation, clustering analysis, and ranked alert presentation. Events are grouped into clusters based on similarities, and analysts receive ranked alerts within each cluster. This segmentation allows the system to maintain strict detection criteria while organizing false positives systematically, reducing their disruptive impact on workflow.
Solution Approach 2:
Instead of treating all alerts equally and requiring analysts to filter through them, the patent inverts the approach by automatically ranking alerts within clusters and presenting only the most suspicious ones first. This inversion transforms the problem from manual filtering to automated prioritization, maintaining detection accuracy while reducing false positive burden on analysts.
2Reliability
If intrusion detection is too tolerant, then false positive alerts are reduced, but malicious attacks may be missed
Solution Approach 1:
The patent merges multiple detection events into clusters based on similarities in timing, source, target, and event type. By combining related events, the system maintains tolerant individual event thresholds while achieving accurate attack detection through cluster-level analysis. This merging allows legitimate rare activities to pass individually while coordinated attacks are detected as clustered patterns.
Solution Approach 2:
The patent applies partial action by not requiring every individual event to meet strict detection criteria. Instead, it uses a two-tier approach: tolerant initial detection followed by cluster-level validation. This partial application of strict criteria at the cluster level maintains attack detection accuracy while avoiding false positives from individual tolerant events.
3Measurement precision
If many alerts are generated to ensure attack detection, then attack detection coverage is improved, but resource consumption and cost increase
Solution Approach 1:
The patent extracts and removes low-value alerts from consideration by implementing clustering and ranking mechanisms. Instead of presenting all generated alerts to analysts, the system extracts only the most suspicious ranked alerts within each cluster. This extraction reduces resource consumption for alert processing while maintaining comprehensive attack detection coverage through systematic filtering.
Solution Approach 2:
The patent discards low-priority alerts that are likely false positives after cluster formation and ranking. By discarding these low-value alerts, the system recovers computational resources that would otherwise be spent on processing and analyzing them. This discarding mechanism maintains detection coverage by preserving high-priority alerts while eliminating resource-draining false positives.
4Measurement precision
If checking alerts manually takes significant resources, then detection thoroughness is improved, but organizational cost and time increase
Solution Approach 1:
The patent performs preliminary actions by automatically clustering and ranking alerts before they reach analysts. This preliminary processing organizes alerts in advance, so analysts receive pre-sorted, high-priority alerts rather than unprocessed volumes. The preliminary clustering and ranking actions reduce the time and resources needed for manual verification while maintaining thorough detection through systematic alert organization.
Data Source
AI summary
A method and apparatus for classifying and combining computer attack information identifying as malicious events, events in a network that cause organizationally or functionally distant entities to become closer to each other, the method comprising identifying as malicious events, events in a network that cause organizationally or functionally distant entities to become closer to each other.


