Intrusion Detection Clustering for False Positive Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Intrusion detection systems face challenges in distinguishing between malicious and legitimate activities, leading to false positives and resource-intensive alerts, which can obscure true attack detection.

Innovation Solution

A method that identifies malicious events by determining entity distances and clustering events that bring organizationally or functionally distant entities closer, using static and dynamic metrics to rank events and generate alerts for suspicious activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If intrusion detection is too strict, then malicious attacks are detected more accurately, but false positive alerts increase and normal workflow is disturbed

Engineering Contradiction:
Improveattack detection accuracyVSAvoidfalse positive rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent segments the detection process into multiple stages: initial alert generation, clustering analysis, and ranked alert presentation. Events are grouped into clusters based on similarities, and analysts receive ranked alerts within each cluster. This segmentation allows the system to maintain strict detection criteria while organizing false positives systematically, reducing their disruptive impact on workflow.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of treating all alerts equally and requiring analysts to filter through them, the patent inverts the approach by automatically ranking alerts within clusters and presenting only the most suspicious ones first. This inversion transforms the problem from manual filtering to automated prioritization, maintaining detection accuracy while reducing false positive burden on analysts.

Inventive Principle:
Principle #13The other way round (Inversion)

2Reliability

If intrusion detection is too tolerant, then false positive alerts are reduced, but malicious attacks may be missed

Engineering Contradiction:
Improvefalse positive rateVSAvoidattack detection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent merges multiple detection events into clusters based on similarities in timing, source, target, and event type. By combining related events, the system maintains tolerant individual event thresholds while achieving accurate attack detection through cluster-level analysis. This merging allows legitimate rare activities to pass individually while coordinated attacks are detected as clustered patterns.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent applies partial action by not requiring every individual event to meet strict detection criteria. Instead, it uses a two-tier approach: tolerant initial detection followed by cluster-level validation. This partial application of strict criteria at the cluster level maintains attack detection accuracy while avoiding false positives from individual tolerant events.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If many alerts are generated to ensure attack detection, then attack detection coverage is improved, but resource consumption and cost increase

Engineering Contradiction:
Improveattack detection coverageVSAvoidcomputational resources
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The patent extracts and removes low-value alerts from consideration by implementing clustering and ranking mechanisms. Instead of presenting all generated alerts to analysts, the system extracts only the most suspicious ranked alerts within each cluster. This extraction reduces resource consumption for alert processing while maintaining comprehensive attack detection coverage through systematic filtering.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent discards low-priority alerts that are likely false positives after cluster formation and ranking. By discarding these low-value alerts, the system recovers computational resources that would otherwise be spent on processing and analyzing them. This discarding mechanism maintains detection coverage by preserving high-priority alerts while eliminating resource-draining false positives.

Inventive Principle:
Principle #34Discarding and recovering

4Measurement precision

If checking alerts manually takes significant resources, then detection thoroughness is improved, but organizational cost and time increase

Engineering Contradiction:
Improvealert verification thoroughnessVSAvoidalert processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by automatically clustering and ranking alerts before they reach analysts. This preliminary processing organizes alerts in advance, so analysts receive pre-sorted, high-priority alerts rather than unprocessed volumes. The preliminary clustering and ranking actions reduce the time and resources needed for manual verification while maintaining thorough detection through systematic alert organization.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9832214B2Method and apparatus for classifying and combining computer attack information
Publication Date: 2017.11.28 CYBEREASON INC
  • US9832214B2 patent drawing
  • US9832214B2 patent drawing
  • US9832214B2 patent drawing

AI summary

A method and apparatus for classifying and combining computer attack information identifying as malicious events, events in a network that cause organizationally or functionally distant entities to become closer to each other, the method comprising identifying as malicious events, events in a network that cause organizationally or functionally distant entities to become closer to each other.