Risk-Based Alert Prioritization in Event Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security platforms in large network environments fail to provide reliable prioritization of security event alerts, leading to critical events being overlooked amidst a high volume of alerts, which can result in ineffective and timely addressing of potential threats.
Innovation Solution
An event management system that includes a beacon to collect web device profile characteristics, such as geographic location data, and generates alerts with priority levels based on risk assessments, allowing administrators to prioritize security risks effectively.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security platforms provide security event alerts in large network environments, then the administrator receives notifications about security threats, but the alerts lack prioritization context causing critical events to be overlooked amidst high volume
Solution Approach 1:
The system performs preliminary risk assessment by collecting web device profile characteristics (geographic location, device type, browser information) before generating security alerts. This advance preparation of context information enables reliable prioritization when alerts are generated, preventing critical events from being overlooked.
Solution Approach 2:
The patent introduces an intermediary risk assessment mechanism that bridges raw security events and administrator alerts. By inserting this intermediate layer that evaluates device profiles and assigns risk scores, the system transforms unprioritized event data into context-rich, prioritized alerts without losing critical information.
2Quantity of substance
If the security platform collects and processes a large volume of event alerts, then comprehensive security monitoring is achieved, but critical events do not stand out and response time increases
Solution Approach 1:
The system applies local quality by assigning different risk levels and priority characteristics to different alerts based on their specific device profile characteristics. Instead of treating all alerts uniformly, each alert receives localized prioritization based on geographic location, device type, and other profile attributes, enabling administrators to quickly identify critical events.
Solution Approach 2:
The patent changes the parameter of alert prioritization by introducing risk scores derived from device profile analysis. This parameter transformation converts a large volume of undifferentiated alerts into a prioritized stream where critical events are distinguished by their risk characteristics, reducing administrator response time.
3Loss of information
If conventional platforms provide all security events without filtering or prioritization, then complete event visibility is maintained, but administrators cannot effectively identify and address critical threats
Solution Approach 1:
The system segments security alerts into different priority levels based on risk assessment of device profiles. By dividing the complete set of security events into prioritized categories, the system maintains information completeness while improving alert management efficiency through structured segmentation.
Solution Approach 2:
The patent implements feedback by continuously monitoring device profile characteristics and using this information to dynamically prioritize alerts. The system learns from device behavior patterns and adjusts prioritization accordingly, maintaining complete event visibility while enhancing ease of operation through intelligent feedback-driven sorting.
Data Source
AI summary
Embodiments relate to the generation of alerts in an event management system based upon risk. When an event device associated with the event management system, presents a logon page to a client device, the event device includes a beacon as part of the page to monitor and collect web device profile characteristics related to the client device. In response to a logon attempt by the client device, an event management device receives a notification regarding logon attempt and a risk assessment associated with the web device profile characteristics of the client device. Based upon a correlation of the notification and the corresponding risk assessment, the event management device can generate an alert, such as a SIEM alert, and can include an indication of priority, whether relatively low or high, and/or a confidence factor, whether or not the alert can be suppressed as part of the alert.


