Intrusion Detection GUI Alert Snooze and Severity Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing large enterprise networks is costly and inefficient due to the need for manual, ad-hoc decision-making on network topology and security, with existing systems lacking effective tools for early detection and mitigation of security violations.

Innovation Solution

A graphical user interface for an intrusion detection system that includes features for summarizing anomalies, allowing users to snooze alerts, and displaying event details, along with a method for providing operators with lists of events and enabling them to clear alerts, facilitating better network management and security monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If intrusion detection systems generate detailed alerts for all detected anomalies, then detection precision is improved, but operator workload and false assertion impact increase

Engineering Contradiction:
Improvedetection precisionVSAvoidoperator workload
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system segments alerts by severity level (critical, high, medium, low) and groups related anomalies into unified event summaries. This segmentation allows operators to focus on critical issues while filtering out less significant false assertions, reducing workload without sacrificing detection precision for important events.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system incorporates feedback mechanisms where operators can mark alerts as false positives, and this feedback is used to refine future detection algorithms. The interface allows operators to provide feedback on alert accuracy, which feeds back into the intrusion detection system to reduce false assertions over time while maintaining high detection precision for real threats.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If the system provides detailed anomaly information for each event, then measurement precision is improved, but the time required for operator analysis increases

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidoperator analysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary action by automatically correlating and grouping related anomalies into unified event summaries before presenting them to operators. Detailed anomaly information is pre-organized and contextualized, allowing operators to quickly understand the full picture without manually analyzing each individual anomaly, thus reducing analysis time while maintaining precision.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The interface presents anomaly data across multiple dimensions including severity levels, event types, source/destination hosts, and temporal patterns. This dimensional organization allows operators to quickly filter and prioritize information based on multiple criteria simultaneously, reducing the time needed to analyze detailed anomaly information while maintaining comprehensive understanding.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Speed

If the system alerts on all detected security violations immediately, then response time to attacks is improved, but the number of false assertions increases

Engineering Contradiction:
Improveresponse speedVSAvoidfalse assertions
Core Design Contradiction:
SpeedVSObject-generated harmful factors

Solution Approach 1:

The system applies asymmetric alerting where critical and high severity events trigger immediate alerts, while medium and low severity events undergo additional verification or are grouped into summaries. This asymmetric approach ensures fast response to genuine threats while filtering out false assertions from less severe but potentially spurious anomalies.

Inventive Principle:
Principle #4Asymmetry

Solution Approach 2:

The alerting system is dynamic, adjusting its sensitivity and verification requirements based on contextual factors such as time of day, network conditions, and historical data. The system can temporarily increase alerting sensitivity during critical periods while reducing it during low-risk periods, balancing response speed with false assertion reduction adaptively.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS7774839B2Feedback mechanism to minimize false assertions of a network intrusion
Publication Date: 2010.08.10 RIVERBED TECH LLC
  • US7774839B2 patent drawing
  • US7774839B2 patent drawing
  • US7774839B2 patent drawing

AI summary

A graphical user interface for an intrusion detection system is described. The graphical user interface includes a field that depicts a summary of anomalies identified as part of a event that is detected in a network, the summary indicating event severity details of the event and an alert action region including a control to permit a user to snooze future alerts related to the event in the summary for a period of time.