Machine Learning Classification for Non-Malicious Alert Disposal

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity systems face challenges in efficiently scaling threat detection and response to the increasing volume of security threats in cloud-based environments, leading to inefficiencies that hinder timely detection and resolution of non-malicious electronic communications.

Innovation Solution

A computer-implemented method using a machine learning-based electronic communication classification model to identify and automatically route non-malicious electronic communications to a disposal queue, bypassing unnecessary investigations and closing alerts based on classification thresholds, employing feature extraction and semi-supervised training.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If security operation services scale to handle increasing volume of security threats in cloud-based environments, then the capability to detect and respond to threats improves, but technical inefficiencies arise that slow down detection and response times

Engineering Contradiction:
Improvethreat detection capabilityVSAvoiddetection and response time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent segments the alert queue into multiple specialized queues (e.g., phishing alerts, malware alerts, spam alerts) based on threat type. This segmentation allows different disposal strategies to be applied to different alert types, improving overall processing efficiency while maintaining appropriate detection capabilities for each threat category.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the disposal parameters dynamically based on alert characteristics. By analyzing alert features and adjusting disposal parameters (such as disposal confidence thresholds, queue routing decisions, and investigation priorities), the system optimizes the balance between thorough detection and rapid response for different types of security threats.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If manual investigation and analysis of each security alert is performed, then detection accuracy improves, but the workload and time required to process alerts increases significantly

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidalert processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements self-service disposal mechanisms where the system automatically disposes of alerts based on analyzed characteristics and configured parameters. The alert disposal service autonomously determines whether to investigate, dismiss, or route alerts without requiring manual analyst intervention for every alert, thereby reducing processing time while maintaining accuracy through intelligent automated decision-making.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback loops where disposal outcomes and alert characteristics are continuously analyzed to refine disposal parameters and improve future disposal decisions. This feedback mechanism enables the system to learn from past decisions and improve both accuracy and efficiency over time without increasing manual workload.

Inventive Principle:
Principle #23Feedback

3Reliability

If all security alerts are investigated thoroughly before disposal, then false positives are reduced, but the overall disposal speed and system efficiency decrease

Engineering Contradiction:
Improvealert disposal accuracyVSAvoidalert disposal speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial investigation action by selectively investigating only those alerts that meet specific criteria or fall into uncertain categories. High-confidence alerts are disposed of automatically without full investigation, while low-confidence or suspicious alerts receive more thorough analysis. This partial action approach maintains reliability for critical alerts while improving overall disposal speed.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system dynamically adjusts disposal confidence thresholds and investigation priorities based on alert characteristics, historical data, and current system conditions. By changing these parameters, the system optimizes the balance between thoroughness and speed, ensuring high reliability for critical threats while maintaining high disposal speeds for lower-priority alerts.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12388870B2Systems and methods for intelligent identification and automated disposal of non-malicious electronic communications
Publication Date: 2025.08.12 EXPEL INC
  • US12388870B2 patent drawing
  • US12388870B2 patent drawing
  • US12388870B2 patent drawing

AI summary

A system and method for accelerating a disposition of non-malicious electronic communications includes extracting one or more corpora of feature vectors from an electronic communication based on providing the electronic communication as input to a feature extractor; computing, by a machine learning-based electronic communication classification model, an electronic communication-type classification inference that includes a probability of the electronic communication being of the target non-malicious electronic communication type in response to the machine learning-based electronic communication classification model receiving the one or more corpora of feature vectors; attributing a classification label of the target non-malicious electronic communication type to the electronic communication based on the probability of the electronic communication-type classification inference satisfying a minimum electronic communication classification threshold; and automatically routing a security alert associated with the electronic communication to an alert disposal queue based on the electronic communication having the classification label of the target non-malicious electronic communication type.