Security Alert Prioritization via Belief Propagation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network traffic monitoring systems generate a high number of false positive security alerts due to broadly inclusive rules, overwhelming organizations with resource-intensive manual verification and lacking prioritization of alerts by significance, leading to inaccurate security issue identification and characterization.
Innovation Solution
A security alert prioritization system that uses belief propagation to infer security states of hosts and domains from initial ground truth information, generating a host-domain access map to prioritize alerts based on communication patterns and security states, thereby reducing the burden of reviewing false positives.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If broadly inclusive rules are used to detect malicious network traffic, then the detection coverage is improved, but the number of false positive security alerts increases
Solution Approach 1:
The patent introduces an intermediary prioritization system that sits between the intrusion detection system and security analysts. This intermediary uses belief propagation algorithms to process security alerts, infer security states of hosts and domains, and assign priorities based on communication patterns. The intermediary does not replace the detection rules but adds a layer of intelligent filtering that reduces false positives while maintaining detection coverage.
Solution Approach 2:
The system implements feedback loops where security alert outcomes and analyst decisions are used to refine belief states about hosts and domains. The belief propagation algorithm continuously updates security state probabilities based on new information from security alerts and communication patterns, creating a self-improving system that becomes more accurate over time while maintaining broad detection coverage.
2Measurement precision
If manually verified security alerts are increased to reduce false positives, then the alert accuracy is improved, but the resource consumption and time required increase
Solution Approach 1:
The system performs preliminary actions by automatically inferring security states and assigning priorities to security alerts before they reach human analysts. The belief propagation algorithm pre-processes alerts, communicates with the intrusion detection system to obtain security states, and ranks alerts by likelihood of being true positives. This preliminary automation reduces the manual verification burden while maintaining high accuracy.
3Loss of information
If all security alerts are reviewed equally, then no priority information is lost, but the productivity of security monitoring decreases
Solution Approach 1:
The patent applies local quality by treating different security alerts differently based on their inferred significance. Instead of uniform processing, the system assigns different priority levels to different alerts based on the security states of involved hosts and domains, communication patterns, and belief propagation results. High-priority alerts receive immediate attention while low-priority alerts are deferred or automatically handled, optimizing security monitoring productivity.
Data Source
AI summary
In one implementation, a security alert prioritization system identifies a host and a domain associated with a security alert that was generated in response to a communication between the host and the domain. The security alert prioritization system accesses a security state associated with the host and a security state associated with the domain, and compute a priority of the security alert based on the security state associated with the host and the security state associated with the domain.


