ML Anomaly Scoring for Network Security Alert Sequences
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems generate large volumes of low-confidence risk-based alerts, requiring laborious manual analysis by technical specialists, which is inefficient and prone to errors due to the complexity and scale of modern IT infrastructures.
Innovation Solution
A computer-implemented method using Artificial Intelligence and Machine Learning, specifically Active Learning, to process network security alerts by grouping related alerts in time windows and associating them with network devices and user identities, generating an input dataset for a machine learning model to produce an anomaly score, and performing actions based on this score.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual analysis of alert logs is performed by technical specialists, then security risk assessment can be conducted, but the process is laborious, error-prone, and inefficient due to the large volume of alerts
Solution Approach 1:
The patent replaces the manual mechanical analysis process with an automated machine learning system. The ML model processes alert sequences and generates anomaly scores automatically, substituting human specialists' manual review with algorithmic analysis that operates faster and without human error while maintaining or improving accuracy.
Solution Approach 2:
The patent introduces a machine learning model as an intermediary between alert generation and human analysis. This intermediary automatically processes large volumes of alerts, filtering and scoring them before presenting only the most relevant cases to human specialists, thereby reducing both time loss and maintaining assessment quality.
2Ease of operation
If individual alerts are analyzed in isolation, then processing is simpler, but detection accuracy is reduced because contextual relationships between alerts are missed
Solution Approach 1:
The patent merges multiple individual alerts into sequences based on temporal and contextual relationships. By combining alerts that occur within specific time windows and are associated with the same devices or users, the system preserves contextual information while maintaining manageable processing units through structured sequence formation.
Solution Approach 2:
The patent segments the overall alert analysis task into manageable components: forming alert sequences from individual alerts, processing each sequence through the ML model to generate anomaly scores, and then aggregating results. This segmentation maintains simplicity at each stage while achieving high overall accuracy through contextual analysis.
Data Source
AI summary
A method of processing network security alerts includes receiving a plurality of security alerts generated by network security devices in a network, each security alert comprising alert data relating to the security alert and specifying an alert time and a network device, a user identity associated with the security alert, or both. A group of related alerts are selected from the plurality of security alerts, the group of related alerts having an alert time within a given time window and associated with one or both of: a given network device; and a given user identity. Alert data for the selected alerts is provided as an input data set for a machine learning model configured to generate an anomaly score. An action is then performed in dependence on the anomaly score.


