Security Alert Deduplication Using Recurring Data Identifiers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computing systems face challenges in efficiently managing and scaling the triage, investigation, and management of security alerts due to the increasing volume generated by large and complex architectures, leading to inefficiencies and high costs.

Innovation Solution

Implementing an alert management system that utilizes serverless cloud computing to automatically suppress and deduplicate recurring security alerts through unique identifier calculations, such as UUID and hashing algorithms, to reduce manual effort and enhance scalability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual triage and management of security alerts is performed, then alert accuracy and investigation quality are improved, but system cost and operational complexity increase significantly

Engineering Contradiction:
Improvealert management reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service alert management by automatically suppressing duplicate alerts based on recurring data identifiers. The alert management system compares incoming alert data against stored historical data, identifies duplicates using hashing algorithms, and automatically suppresses redundant alerts without requiring manual intervention, thereby reducing operational complexity while maintaining reliability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring alert patterns and using historical data to inform future alert suppression decisions. The system learns from past alert resolutions and adjusts its suppression logic accordingly, improving both reliability and efficiency over time

Inventive Principle:
Principle #23Feedback

2Reliability

If security alert volume increases with system scaling, then coverage and detection capability are improved, but processing burden and cost increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidalert processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system extracts and removes duplicate alerts from the processing stream by identifying them through recurring data identifiers and suppressing them automatically. This extraction of redundant information maintains comprehensive security coverage while significantly reducing the processing burden on the system

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes the state of alert processing by introducing suppression flags and status modifications. Alerts are marked as suppressed or processed based on their uniqueness, allowing the system to maintain thorough monitoring while optimizing processing efficiency through state-based management

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If all security alerts are processed manually, then investigation quality is improved, but time consumption and operational cost increase

Engineering Contradiction:
Improveinvestigation qualityVSAvoidtriage time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary action by automatically suppressing duplicate alerts before they reach manual triage. By pre-processing alerts and removing obvious duplicates using data identifier comparison, the system preserves investigation quality for unique alerts while eliminating time-consuming manual review of redundant alerts

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12368733B2Automated alert deduplication or suppression in data processing systems based on recurring data identifiers
Publication Date: 2025.07.22 BREX INC
  • US12368733B2 patent drawing
  • US12368733B2 patent drawing
  • US12368733B2 patent drawing

AI summary

There are provided systems and methods for automated alert deduplication or suppression in data processing systems based on recurring data identifiers. An entity, such as company or business, may utilize computing services provided by a service provider. When providing these services, one or more computing services, processors, or the like of the service provider's computing architecture may be used. Use of computing services may generate security alerts when computing events are flagged as risky, fraudulent, malicious, computing attacks, or the like. To automate security alert management, the service provider may utilize an alert management system that may parse and extract data from incoming security alerts and calculate identifiers from such data, such as by transforming or converting using identifier functions. Recurring identifiers may be automatically organized for suppression or deduplication based on past occurrence of such identifiers with other security alerts.