Machine Learning Security Threat Investigation Guidance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Human security analysts face challenges in efficiently investigating and addressing security threats in large-scale computer systems, particularly for novice analysts who struggle to make timely and comprehensive inquiries, leading to potential missed threats.
Innovation Solution
A supervised machine learning engine is trained to provide guidance and recommendations to security analysts during investigations, utilizing data from experienced analysts and adapting based on feedback, to aid in decision-making and next steps in the investigative process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If human analysts manually investigate security alerts, then they can identify and address security threats, but the investigation process is time-consuming and inefficient, especially for novice analysts
Solution Approach 1:
An AI assistant is introduced as an intermediary between security analysts and investigation resources. The AI assistant automatically performs preliminary investigations, gathers relevant data, and provides actionable recommendations, thereby reducing the time and effort analysts need to spend on each alert while maintaining thorough investigation quality
Solution Approach 2:
The system performs preliminary investigation actions automatically before analysts need to intervene. The AI assistant pre-gathers contextual information, identifies potential threats, and prepares initial assessment reports, so that when analysts do review alerts, the foundational work has already been completed, significantly reducing their investigation time
2Reliability
If novice analysts conduct investigations independently, then they can handle security alerts, but they may miss threats or make incomplete inquiries due to lack of experience
Solution Approach 1:
The AI assistant enables novice analysts to perform investigations at an expert level by automatically providing comprehensive analysis recommendations, relevant data synthesis, and threat assessment guidance. The system serves itself by drawing from its training data to generate expert-level insights without requiring the analyst to have specialized knowledge, thereby equalizing investigation quality across experience levels
Solution Approach 2:
The system incorporates feedback mechanisms where the AI assistant learns from analyst interactions and outcomes. By analyzing which investigations led to successful threat detections and which missed threats, the system continuously improves its recommendations, ensuring that novice analysts receive increasingly accurate and reliable guidance over time
3Reliability
If more comprehensive investigations are conducted to ensure no threats are missed, then threat detection improves, but the time and resources required for each investigation increase
Solution Approach 1:
The AI assistant applies partial action by focusing investigative efforts only on the most relevant and high-risk aspects of each alert based on its analysis. Rather than conducting exhaustive investigations of all possible angles, the system identifies and pursues the critical investigation paths most likely to reveal threats, achieving high detection completeness with reduced time and resource expenditure
Data Source
AI summary
A technique includes accessing data representing a state of a given investigation of a potential security threat to a computer system by a security analyst. The state includes a result of a current investigative step of the investigation, and the analyst conducting the investigation uses an investigation graphical user interface (GUI). The technique includes applying machine learning that is trained on observed investigations to determine a recommendation to guide the analyst in a next investigative step for the given investigation. The technique includes communicating the recommendation through an output provided to the investigation GUI.


