Meta-Alert Generation for Enterprise Security Risk Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computer systems face challenges in efficiently analyzing and identifying trends in operational and security alert volumes across entities within an enterprise, leading to difficulties in identifying risky behaviors and necessitating manual review, which is time-consuming and resource-intensive.
Innovation Solution
A central device generates meta-alerts by comparing alert volumes of entities against baseline thresholds, segmenting entities into peer groups, and determining alert volumes relative to historical and peer group averages, thereby flagging spikes or increases in alert activity for management attention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual review of alert volumes is performed, then analysis accuracy is maintained, but time consumption and resource usage increase
Solution Approach 1:
The system performs self-service by automatically comparing alert volumes against baseline thresholds and generating meta-alerts without requiring manual intervention. The computer system autonomously identifies spikes in alert activity, determines whether entities are trending high, and creates meta-alerts for management review, thereby eliminating time-consuming manual analysis while maintaining analysis accuracy through systematic automated comparison processes
Solution Approach 2:
The patent replaces manual mechanical review processes with automated computer-based analysis. The system uses computational algorithms to compare alert volumes, calculate baseline thresholds, identify trends, and generate meta-alerts automatically. This substitution of mechanical human review with automated computing systems dramatically reduces time consumption while preserving analytical precision through consistent algorithmic evaluation
2Reliability
If all entities are monitored in detail, then comprehensive risk identification is achieved, but processing load increases
Solution Approach 1:
The system extracts only the most critical information by generating meta-alerts that highlight entities with abnormal alert volumes. Instead of processing and presenting all alert data in detail, the system extracts and flags only those entities that exceed baseline thresholds or show trending high patterns. This extraction approach maintains comprehensive risk identification for problematic areas while significantly reducing the processing load by not analyzing every entity in equal detail
Solution Approach 2:
The patent applies local quality by providing differentiated monitoring intensity across different entities. Entities that exceed baseline thresholds or show high alert volumes receive focused attention through meta-alert generation, while entities within normal ranges receive standard monitoring. This localized approach ensures comprehensive risk identification for high-risk entities while reducing overall processing load by applying less intensive monitoring to low-risk entities
3Measurement precision
If baseline thresholds are set low, then more spikes are detected, but false alerts increase
Solution Approach 1:
The system employs dynamic baseline thresholds that adapt to different entities and time periods rather than using static uniform thresholds. Baseline thresholds are calculated based on each entity's historical alert volumes and peer group comparisons, allowing the system to detect spikes with appropriate sensitivity for each entity's specific context. This dynamic approach maintains high detection sensitivity while reducing false alerts by accounting for legitimate variations in alert volumes across different entities and time periods
Solution Approach 2:
The patent changes the parameter of baseline thresholds from fixed values to dynamically calculated values based on historical data and peer comparisons. By adjusting threshold parameters to reflect entity-specific patterns and industry standards, the system achieves sensitive spike detection for each entity while minimizing false alerts through context-aware threshold setting. The system also changes the parameter of alert generation by requiring entities to be trending high over multiple periods before generating meta-alerts
4Reliability
If meta-alerts are generated for all high alert volumes, then comprehensive monitoring is achieved, but management attention is dispersed
Solution Approach 1:
The system extracts and highlights only the most significant cases by generating meta-alerts for entities that meet specific criteria (exceeding baseline thresholds and trending high). This extraction approach provides comprehensive monitoring coverage for problematic entities while concentrating management attention on the most critical cases rather than dispersing it across all entities with elevated alert volumes
Solution Approach 2:
The patent applies local quality by providing intensified monitoring and meta-alert generation only for entities exhibiting problematic patterns (high alert volumes relative to baseline and peer groups, plus trending high). This localized approach ensures comprehensive monitoring of at-risk entities while improving ease of operation by focusing management attention specifically on entities requiring intervention rather than requiring review of all entities
Data Source
AI summary
Techniques are described for automatically generating meta-alerts based on operational and security risk alert volumes for an entity. In particular, a central device receives entity alert information from other devices in a computer system of an enterprise business, which may have office branches that are each staffed by employees. The central device compares alert volumes of a given entity for a given period of time (e.g., a month) to one or more baseline thresholds determined based on the average alert volume of peer entities during the same period of time and the entity's own historical alert volumes to identify spikes or increases in the volume of alerts for the given entity. If the entity is trending high for the period of time, the central device generates a meta-alert to bring awareness to the relatively high volume of alerts identified for that entity.


