Security Alert Prioritization via Belief Propagation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network traffic monitoring systems generate a high number of false positive security alerts due to broadly inclusive rules, overwhelming organizations with resource-intensive manual verification and lacking prioritization of alerts by significance, leading to inaccurate security issue identification and characterization.

Innovation Solution

A security alert prioritization system that uses belief propagation to infer security states of hosts and domains from initial ground truth information, generating a host-domain access map to prioritize alerts based on communication patterns and security states, thereby reducing the burden of reviewing false positives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If broadly inclusive rules are used to detect malicious network traffic, then the detection coverage is improved, but the number of false positive security alerts increases

Engineering Contradiction:
Improvedetection coverageVSAvoidalert accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent introduces an intermediary prioritization system that sits between the intrusion detection system and security analysts. This intermediary uses belief propagation algorithms to process security alerts, infer security states of hosts and domains, and assign priorities based on communication patterns. The intermediary does not replace the detection rules but adds a layer of intelligent filtering that reduces false positives while maintaining detection coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback loops where security alert outcomes and analyst decisions are used to refine belief states about hosts and domains. The belief propagation algorithm continuously updates security state probabilities based on new information from security alerts and communication patterns, creating a self-improving system that becomes more accurate over time while maintaining broad detection coverage.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If manually verified security alerts are increased to reduce false positives, then the alert accuracy is improved, but the resource consumption and time required increase

Engineering Contradiction:
Improvealert accuracyVSAvoidmanual verification time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically inferring security states and assigning priorities to security alerts before they reach human analysts. The belief propagation algorithm pre-processes alerts, communicates with the intrusion detection system to obtain security states, and ranks alerts by likelihood of being true positives. This preliminary automation reduces the manual verification burden while maintaining high accuracy.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If all security alerts are reviewed equally, then no priority information is lost, but the productivity of security monitoring decreases

Engineering Contradiction:
Improvesecurity significance informationVSAvoidsecurity monitoring efficiency
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The patent applies local quality by treating different security alerts differently based on their inferred significance. Instead of uniform processing, the system assigns different priority levels to different alerts based on the security states of involved hosts and domains, communication patterns, and belief propagation results. High-priority alerts receive immediate attention while low-priority alerts are deferred or automatically handled, optimizing security monitoring productivity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9124621B2Security alert prioritization
Publication Date: 2015.09.01 MICRO FOCUS LLC
  • US9124621B2 patent drawing
  • US9124621B2 patent drawing
  • US9124621B2 patent drawing

AI summary

In one implementation, a security alert prioritization system identifies a host and a domain associated with a security alert that was generated in response to a communication between the host and the domain. The security alert prioritization system accesses a security state associated with the host and a security state associated with the domain, and compute a priority of the security alert based on the security state associated with the host and the security state associated with the domain.