Security Detection Clearing Operations for Fewer False Positives
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security detection systems face challenges in balancing false positives and false negatives, with stricter thresholds introducing false negatives and less strict thresholds increasing false positives, leading to inefficiencies in threat detection.
Innovation Solution
Implementing clearing operations that validate normal operations within activity sessions using cloud computing control layer datasets to adjust thresholds, leveraging unique fields and lists of operations to reduce false positives by identifying and clearing low-risk operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If stricter detection thresholds are applied to reduce false positives, then false positive rate decreases, but false negative rate increases
Solution Approach 1:
The patent segments the detection process into two independent stages: first, machine learning models generate detections with lenient thresholds to ensure high sensitivity; second, clearing operations validate normal operations to remove false positives. This segmentation allows each stage to optimize for its specific function without compromising the other.
Solution Approach 2:
The patent introduces clearing operations as an intermediary layer between the machine learning detection model and the final security alert. This intermediary validates operations using cloud computing control layer datasets, effectively mediating between lenient detection thresholds and low false positive rates.
2Reliability
If more lenient detection thresholds are applied to reduce false negatives, then false negative rate decreases, but false positive rate increases
Solution Approach 1:
The detection system is divided into two functional segments: a sensitive detection phase using lenient thresholds to capture all potential threats, and a validation phase using clearing operations to eliminate false positives. This enables the system to operate with high sensitivity without suffering from excessive false alarms.
Solution Approach 2:
Clearing operations serve as an intermediary validation layer that processes detections from the lenient threshold model. By checking against cloud computing control layer datasets, this intermediary removes false positives while preserving true positives, enabling the use of more sensitive detection thresholds.
3Measurement precision
If detection thresholds are optimized for accuracy, then detection accuracy improves, but the number of false positives increases
Solution Approach 1:
The patent introduces clearing operations as an intermediary layer between accurate but noisy detections and final security alerts. This intermediary validates operations using cloud computing control layer datasets, filtering out false positives while preserving accurate detections.
Solution Approach 2:
The patent extracts and removes false positives from the detection output by applying clearing operations that validate normal operations. This separation allows the system to maintain high detection accuracy while eliminating the harmful effect of false positives.
Data Source
AI summary
Systems and techniques for reduction of security detection false positives are described herein. Suspicious activity data is obtained for an operation. Operation data is obtained for the operation. It is determined that the operation is related to a parent operation that has not triggered an alert. The operation is cleared from the suspicious activity data.


