Machine Learning Threat Detection for Malicious Entity Ranking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Security Operations Center (SOC) analysts face alert fatigue due to the large number of threats, making it difficult to identify which entities are likely to be at risk or pose a risk to other users, as traditional detections do not provide clear indications of malicious entities.
Innovation Solution
A machine learning (ML) threat detector is trained using signal records to predict the threat level of entities, allowing for targeted cybersecurity mitigation actions based on the predicted threat level.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional detection methods are used to monitor all entities, then comprehensive security coverage is achieved, but SOC analysts experience alert fatigue and cannot identify main malicious entities
Solution Approach 1:
The patent introduces a machine learning model as an intermediary between traditional detection systems and human analysts. The model processes detection signals and entity interactions to generate threat scores, acting as a mediator that filters and prioritizes information before presenting it to analysts, thereby maintaining comprehensive security coverage while reducing analyst workload
Solution Approach 2:
The patent replaces manual analysis of detection signals with an automated machine learning system. The mechanical process of analysts reviewing all alerts is substituted with an electronic ML-based threat scoring system that automatically processes and prioritizes entities based on their interaction patterns and signal characteristics
2Reliability
If cybersecurity mitigation actions are performed on all entities, then maximum security protection is provided, but processing resources are wasted on non-malicious entities
Solution Approach 1:
The patent applies local quality by differentiating threat levels across different entities rather than applying uniform security measures. The ML model generates specific threat scores for each entity based on their individual signal patterns and interactions, enabling targeted mitigation actions that are proportionate to each entity's actual risk level
Solution Approach 2:
The patent implements partial action by applying cybersecurity mitigation measures only to entities that exceed a certain threat threshold, rather than treating all entities equally. This selective approach focuses resources on the most problematic entities while avoiding unnecessary actions on low-risk entities
3Quantity of substance
If traditional detection systems are used, then all suspicious activities are detected, but clear identification of main malicious entities is not provided
Solution Approach 1:
The patent adds a new dimension of threat scoring to traditional detection outputs. Instead of merely detecting suspicious activities, the ML model incorporates entity interaction graphs and temporal patterns to generate a quantitative threat score that ranks entities by likelihood of being malicious, transforming qualitative detection data into actionable prioritization information
Data Source
AI summary
A computer-implemented method, computer device and computer program are provided for training a Machine Learning model based on a plurality of signal records, each signal record comprising an entity identifier, a signal identifier and a timestamp. Signal records related to an entity can be input into the trained Machine Learning model. The trained Machine Learning model can be used to determine if an entity is malicious.


