ML Email Classification for Automated False Alert Disposal

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge in cybersecurity is efficiently scaling threat detection and response capabilities to manage the increasing volume of security threats in cloud-based computing environments without causing technical inefficiencies.

Innovation Solution

A computer-implemented method using a machine learning-based electronic communication classification model to identify and automatically route non-malicious electronic communications, such as marketing emails, to a disposal queue, thereby reducing the workload on security analysts and focusing resources on genuine threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If security operation services scale to handle increasing volume of security threats in cloud-based environments, then threat detection coverage is improved, but technical inefficiencies increase and detection speed decreases

Engineering Contradiction:
Improvevolume of security threats processedVSAvoidthreat detection efficiency
Core Design Contradiction:
Quantity of substanceVSProductivity

Solution Approach 1:

The patent segments security alerts into different queues based on threat severity and type. A machine learning model classifies alerts into high-priority (malicious) and low-priority (non-malicious) categories, routing them to different disposal queues. This segmentation allows security operation centers to process critical threats faster while handling volume threats more efficiently, resolving the contradiction between processing volume and detection efficiency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a machine learning-based classification model as an intermediary between alert generation and human analysis. This intermediary automatically evaluates alerts, predicts maliciousness, and routes them appropriately, reducing the burden on human analysts and improving overall processing efficiency while maintaining the ability to handle increasing threat volumes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If all security alerts are routed to human analysts for review, then detection accuracy is improved, but response time increases and analyst workload becomes unsustainable

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidalert response time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements a self-service mechanism where the machine learning model automatically evaluates and classifies security alerts without human intervention. The model predicts whether alerts are malicious or non-malicious and routes them to appropriate queues. This self-service approach maintains detection accuracy through automated ML-based assessment while significantly reducing response time and analyst workload.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical system of human analysts reviewing all alerts with an automated machine learning-based classification system. This substitution maintains detection accuracy through sophisticated ML algorithms while eliminating the time constraints and workload limitations of human analysts, allowing for faster processing of high-volume threats.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If machine learning models automatically classify and route non-malicious communications, then processing speed is improved, but false positive rate may increase

Engineering Contradiction:
Improvecommunication disposition speedVSAvoidclassification accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent incorporates feedback mechanisms where security analysts can review and correct the machine learning model's classifications. The system learns from these corrections and continuously improves its accuracy. This feedback loop allows the system to maintain high processing speed while reducing false positives through iterative learning and validation, resolving the contradiction between productivity and reliability.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12531903B2Systems and methods for intelligent identification and automated disposal of non-malicious electronic communications
Publication Date: 2026.01.20 EXPEL INC
  • US12531903B2 patent drawing
  • US12531903B2 patent drawing
  • US12531903B2 patent drawing

AI summary

A system and method for accelerating a disposition of non-malicious electronic communications includes extracting one or more corpora of feature vectors from an electronic communication based on providing the electronic communication as input to a feature extractor; computing, by a machine learning-based electronic communication classification model, an electronic communication-type classification inference that includes a probability of the electronic communication being of the target non-malicious electronic communication type in response to the machine learning-based electronic communication classification model receiving the one or more corpora of feature vectors; attributing a classification label of the target non-malicious electronic communication type to the electronic communication based on the probability of the electronic communication-type classification inference satisfying a minimum electronic communication classification threshold; and automatically routing a security alert associated with the electronic communication to an alert disposal queue based on the electronic communication having the classification label of the target non-malicious electronic communication type.