Security Detection Clearing Operations for Fewer False Positives

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security detection systems face challenges in balancing false positives and false negatives, with stricter thresholds introducing false negatives and less strict thresholds increasing false positives, leading to inefficiencies in threat detection.

Innovation Solution

Implementing clearing operations that validate normal operations within activity sessions using cloud computing control layer datasets to adjust thresholds, leveraging unique fields and lists of operations to reduce false positives by identifying and clearing low-risk operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If stricter detection thresholds are applied to reduce false positives, then false positive rate decreases, but false negative rate increases

Engineering Contradiction:
Improvefalse positive rateVSAvoidfalse negative rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent segments the detection process into two independent stages: first, machine learning models generate detections with lenient thresholds to ensure high sensitivity; second, clearing operations validate normal operations to remove false positives. This segmentation allows each stage to optimize for its specific function without compromising the other.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces clearing operations as an intermediary layer between the machine learning detection model and the final security alert. This intermediary validates operations using cloud computing control layer datasets, effectively mediating between lenient detection thresholds and low false positive rates.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If more lenient detection thresholds are applied to reduce false negatives, then false negative rate decreases, but false positive rate increases

Engineering Contradiction:
Improvefalse negative rateVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The detection system is divided into two functional segments: a sensitive detection phase using lenient thresholds to capture all potential threats, and a validation phase using clearing operations to eliminate false positives. This enables the system to operate with high sensitivity without suffering from excessive false alarms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Clearing operations serve as an intermediary validation layer that processes detections from the lenient threshold model. By checking against cloud computing control layer datasets, this intermediary removes false positives while preserving true positives, enabling the use of more sensitive detection thresholds.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If detection thresholds are optimized for accuracy, then detection accuracy improves, but the number of false positives increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidfalse positives
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The patent introduces clearing operations as an intermediary layer between accurate but noisy detections and final security alerts. This intermediary validates operations using cloud computing control layer datasets, filtering out false positives while preserving accurate detections.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts and removes false positives from the detection output by applying clearing operations that validate normal operations. This separation allows the system to maintain high detection accuracy while eliminating the harmful effect of false positives.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12443708B2Reduction of security detection false positives
Publication Date: 2025.10.14 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12443708B2 patent drawing
  • US12443708B2 patent drawing
  • US12443708B2 patent drawing

AI summary

Systems and techniques for reduction of security detection false positives are described herein. Suspicious activity data is obtained for an operation. Operation data is obtained for the operation. It is determined that the operation is related to a parent operation that has not triggered an alert. The operation is cleared from the suspicious activity data.