Machine Learning Classification for Non-Malicious Alert Disposal
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity systems face challenges in efficiently scaling threat detection and response to the increasing volume of security threats in cloud-based environments, leading to inefficiencies that hinder timely detection and resolution of non-malicious electronic communications.
Innovation Solution
A computer-implemented method using a machine learning-based electronic communication classification model to identify and automatically route non-malicious electronic communications to a disposal queue, bypassing unnecessary investigations and closing alerts based on classification thresholds, employing feature extraction and semi-supervised training.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If security operation services scale to handle increasing volume of security threats in cloud-based environments, then the capability to detect and respond to threats improves, but technical inefficiencies arise that slow down detection and response times
Solution Approach 1:
The patent segments the alert queue into multiple specialized queues (e.g., phishing alerts, malware alerts, spam alerts) based on threat type. This segmentation allows different disposal strategies to be applied to different alert types, improving overall processing efficiency while maintaining appropriate detection capabilities for each threat category.
Solution Approach 2:
The patent changes the disposal parameters dynamically based on alert characteristics. By analyzing alert features and adjusting disposal parameters (such as disposal confidence thresholds, queue routing decisions, and investigation priorities), the system optimizes the balance between thorough detection and rapid response for different types of security threats.
2Measurement precision
If manual investigation and analysis of each security alert is performed, then detection accuracy improves, but the workload and time required to process alerts increases significantly
Solution Approach 1:
The patent implements self-service disposal mechanisms where the system automatically disposes of alerts based on analyzed characteristics and configured parameters. The alert disposal service autonomously determines whether to investigate, dismiss, or route alerts without requiring manual analyst intervention for every alert, thereby reducing processing time while maintaining accuracy through intelligent automated decision-making.
Solution Approach 2:
The system incorporates feedback loops where disposal outcomes and alert characteristics are continuously analyzed to refine disposal parameters and improve future disposal decisions. This feedback mechanism enables the system to learn from past decisions and improve both accuracy and efficiency over time without increasing manual workload.
3Reliability
If all security alerts are investigated thoroughly before disposal, then false positives are reduced, but the overall disposal speed and system efficiency decrease
Solution Approach 1:
The patent applies partial investigation action by selectively investigating only those alerts that meet specific criteria or fall into uncertain categories. High-confidence alerts are disposed of automatically without full investigation, while low-confidence or suspicious alerts receive more thorough analysis. This partial action approach maintains reliability for critical alerts while improving overall disposal speed.
Solution Approach 2:
The system dynamically adjusts disposal confidence thresholds and investigation priorities based on alert characteristics, historical data, and current system conditions. By changing these parameters, the system optimizes the balance between thoroughness and speed, ensuring high reliability for critical threats while maintaining high disposal speeds for lower-priority alerts.
Data Source
AI summary
A system and method for accelerating a disposition of non-malicious electronic communications includes extracting one or more corpora of feature vectors from an electronic communication based on providing the electronic communication as input to a feature extractor; computing, by a machine learning-based electronic communication classification model, an electronic communication-type classification inference that includes a probability of the electronic communication being of the target non-malicious electronic communication type in response to the machine learning-based electronic communication classification model receiving the one or more corpora of feature vectors; attributing a classification label of the target non-malicious electronic communication type to the electronic communication based on the probability of the electronic communication-type classification inference satisfying a minimum electronic communication classification threshold; and automatically routing a security alert associated with the electronic communication to an alert disposal queue based on the electronic communication having the classification label of the target non-malicious electronic communication type.


