Machine Learning Security Alert Triage Guidance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security operation centers face challenges in managing a high volume of security alerts generated by SIEM systems, requiring human analysts to triage and escalate alerts efficiently, as the sheer number of alerts can overwhelm even a well-staffed team.

Innovation Solution

A supervised machine learning engine is implemented within the SIEM system to analyze security alerts, classify them into incident categories, and provide guidance to analysts with confidence levels, aiding in the sorting of alerts into incidents or false positives, thereby assisting in the triage process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If human security analysts manually triage and evaluate all security alerts, then accurate security threat detection is achieved, but the workload and time consumption increase significantly due to high alert volume

Engineering Contradiction:
Improvesecurity threat detection accuracyVSAvoidalert triage time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent introduces a machine learning model as an intermediary between the SIEM system and human security analysts. The model automatically evaluates security alerts, extracts features, and generates predictions about potential security threats, thereby reducing the manual triage workload while maintaining detection accuracy through human-in-the-loop verification

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary evaluation of security alerts using the machine learning model before human analysts review them. The model pre-processes alerts by extracting features, generating predictions, and ranking them by likelihood of being security threats, so that analysts only need to review pre-filtered high-priority alerts

Inventive Principle:
Principle #10Preliminary action

2Productivity

If more security analysts are hired to handle increased alert volume, then security monitoring coverage is improved, but operational costs and system complexity increase

Engineering Contradiction:
Improvesecurity alert processing capacityVSAvoidoperational structure complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The machine learning model operates autonomously to evaluate and prioritize security alerts without requiring additional human analysts. The system self-services by automatically extracting features from alerts, generating predictions, and providing ranked results, thereby increasing processing capacity without proportionally increasing operational complexity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical system of manual alert evaluation by human analysts with an automated machine learning-based evaluation system. This substitution handles the high-volume routine triage work automatically, freeing human analysts to focus on complex cases and reducing the need to hire additional staff

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If all security alerts are escalated to incidents for thorough investigation, then no security threats are missed, but resource consumption and false positive impact increase

Engineering Contradiction:
Improvesecurity threat detection reliabilityVSAvoidinvestigation resource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The machine learning model applies different evaluation criteria and feature extraction approaches based on the specific characteristics of each alert type. The system identifies and focuses investigative resources on local areas of high risk (alerts with high predicted probability of being security threats) rather than uniformly investigating all alerts

Inventive Principle:
Principle #3Local quality

4Measurement precision

If human analysts review every security alert in detail, then detection accuracy is maximized, but the sheer volume of alerts overwhelms even well-staffed teams

Engineering Contradiction:
Improvesecurity alert evaluation accuracyVSAvoidalert processing throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system applies partial action by having the machine learning model evaluate all alerts to generate predictions and rankings, but only requiring detailed human analysis of the top-ranked alerts that exceed a certain probability threshold. This approach maintains high detection accuracy for critical threats while improving overall processing throughput

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11562064B2Machine learning-based security alert escalation guidance
Publication Date: 2023.01.24 MICRO FOCUS LLC
  • US11562064B2 patent drawing
  • US11562064B2 patent drawing
  • US11562064B2 patent drawing

AI summary

A technique includes receiving, by a processor, a security alert that is generated in response to one or more events occurring in a computer system. The technique includes applying, by the processor, machine learning to the security alert to predict a probability that the security alert will be escalated to an incident; and displaying an output on a display to guide processing of the security alert based on the predicted probability.