Machine Learning Security Threat Investigation Guidance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Human security analysts face challenges in efficiently investigating and addressing security threats in large-scale computer systems, particularly for novice analysts who struggle to make timely and comprehensive inquiries, leading to potential missed threats.

Innovation Solution

A supervised machine learning engine is trained to provide guidance and recommendations to security analysts during investigations, utilizing data from experienced analysts and adapting based on feedback, to aid in decision-making and next steps in the investigative process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If human analysts manually investigate security alerts, then they can identify and address security threats, but the investigation process is time-consuming and inefficient, especially for novice analysts

Engineering Contradiction:
Improveinvestigation efficiencyVSAvoidinvestigation time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

An AI assistant is introduced as an intermediary between security analysts and investigation resources. The AI assistant automatically performs preliminary investigations, gathers relevant data, and provides actionable recommendations, thereby reducing the time and effort analysts need to spend on each alert while maintaining thorough investigation quality

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary investigation actions automatically before analysts need to intervene. The AI assistant pre-gathers contextual information, identifies potential threats, and prepares initial assessment reports, so that when analysts do review alerts, the foundational work has already been completed, significantly reducing their investigation time

Inventive Principle:
Principle #10Preliminary action

2Reliability

If novice analysts conduct investigations independently, then they can handle security alerts, but they may miss threats or make incomplete inquiries due to lack of experience

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidinvestigation complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The AI assistant enables novice analysts to perform investigations at an expert level by automatically providing comprehensive analysis recommendations, relevant data synthesis, and threat assessment guidance. The system serves itself by drawing from its training data to generate expert-level insights without requiring the analyst to have specialized knowledge, thereby equalizing investigation quality across experience levels

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback mechanisms where the AI assistant learns from analyst interactions and outcomes. By analyzing which investigations led to successful threat detections and which missed threats, the system continuously improves its recommendations, ensuring that novice analysts receive increasingly accurate and reliable guidance over time

Inventive Principle:
Principle #23Feedback

3Reliability

If more comprehensive investigations are conducted to ensure no threats are missed, then threat detection improves, but the time and resources required for each investigation increase

Engineering Contradiction:
Improvethreat detection completenessVSAvoidinvestigation throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The AI assistant applies partial action by focusing investigative efforts only on the most relevant and high-risk aspects of each alert based on its analysis. Rather than conducting exhaustive investigations of all possible angles, the system identifies and pursues the critical investigation paths most likely to reveal threats, achieving high detection completeness with reduced time and resource expenditure

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11544374B2Machine learning-based security threat investigation guidance
Publication Date: 2023.01.03 MICRO FOCUS LLC
  • US11544374B2 patent drawing
  • US11544374B2 patent drawing
  • US11544374B2 patent drawing

AI summary

A technique includes accessing data representing a state of a given investigation of a potential security threat to a computer system by a security analyst. The state includes a result of a current investigative step of the investigation, and the analyst conducting the investigation uses an investigation graphical user interface (GUI). The technique includes applying machine learning that is trained on observed investigations to determine a recommendation to guide the analyst in a next investigative step for the given investigation. The technique includes communicating the recommendation through an output provided to the investigation GUI.