ML Anomaly Scoring for Network Security Alert Sequences

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems generate large volumes of low-confidence risk-based alerts, requiring laborious manual analysis by technical specialists, which is inefficient and prone to errors due to the complexity and scale of modern IT infrastructures.

Innovation Solution

A computer-implemented method using Artificial Intelligence and Machine Learning, specifically Active Learning, to process network security alerts by grouping related alerts in time windows and associating them with network devices and user identities, generating an input dataset for a machine learning model to produce an anomaly score, and performing actions based on this score.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual analysis of alert logs is performed by technical specialists, then security risk assessment can be conducted, but the process is laborious, error-prone, and inefficient due to the large volume of alerts

Engineering Contradiction:
Improvesecurity risk assessment accuracyVSAvoidtime required for alert analysis
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces the manual mechanical analysis process with an automated machine learning system. The ML model processes alert sequences and generates anomaly scores automatically, substituting human specialists' manual review with algorithmic analysis that operates faster and without human error while maintaining or improving accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a machine learning model as an intermediary between alert generation and human analysis. This intermediary automatically processes large volumes of alerts, filtering and scoring them before presenting only the most relevant cases to human specialists, thereby reducing both time loss and maintaining assessment quality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If individual alerts are analyzed in isolation, then processing is simpler, but detection accuracy is reduced because contextual relationships between alerts are missed

Engineering Contradiction:
Improvealert processing simplicityVSAvoidanomaly detection accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent merges multiple individual alerts into sequences based on temporal and contextual relationships. By combining alerts that occur within specific time windows and are associated with the same devices or users, the system preserves contextual information while maintaining manageable processing units through structured sequence formation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent segments the overall alert analysis task into manageable components: forming alert sequences from individual alerts, processing each sequence through the ML model to generate anomaly scores, and then aggregating results. This segmentation maintains simplicity at each stage while achieving high overall accuracy through contextual analysis.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250047693A1Systems and methods for machine learning based network alert sequence anomaly detection
Publication Date: 2025.02.06 HSBC GRP MANAGEMENT SERVICES LTD
  • US20250047693A1 patent drawing
  • US20250047693A1 patent drawing
  • US20250047693A1 patent drawing

AI summary

A method of processing network security alerts includes receiving a plurality of security alerts generated by network security devices in a network, each security alert comprising alert data relating to the security alert and specifying an alert time and a network device, a user identity associated with the security alert, or both. A group of related alerts are selected from the plurality of security alerts, the group of related alerts having an alert time within a given time window and associated with one or both of: a given network device; and a given user identity. Alert data for the selected alerts is provided as an input data set for a machine learning model configured to generate an anomaly score. An action is then performed in dependence on the anomaly score.