Automated Security Detection Onboarding via Volume and Efficacy Thresholds
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Incident management systems face challenges in efficiently analyzing and responding to security alerts due to high volumes of alerts, many of which are false positives or lack confidence, leading to inefficient resource utilization and potential security vulnerabilities.
Innovation Solution
A system that automatically onboards or rejects security detections based on volume and efficacy thresholds, using a detection instance obtainer, volume thresholder, and detection performance evaluator to ensure only reliable alerts are processed, thereby reducing false positives and conserving resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual evaluation of security alerts is used, then accuracy in identifying true threats is improved, but time consumption and resource requirements increase significantly
Solution Approach 1:
The system enables automated self-evaluation of security alerts through machine learning models that automatically assess detection instances, calculate confidence scores, and determine whether to onboard or reject detections without human intervention. This resolves the contradiction by replacing manual human evaluation with autonomous automated assessment.
Solution Approach 2:
The patent replaces the mechanical process of manual human analysis with computational algorithms and machine learning models that automatically evaluate detection instances. The system uses automated confidence scoring and threshold-based decision-making to substitute human analysts, thereby maintaining accuracy while eliminating time consumption.
2Reliability
If all security detections are onboarded for review, then comprehensive security monitoring is improved, but system resource utilization deteriorates due to high volume of false positives
Solution Approach 1:
The system performs preliminary automated evaluation of detection instances before they are onboarded for full security review. By pre-assessing confidence scores and filtering out low-confidence detections, the system prepares and prioritizes alerts in advance, ensuring comprehensive monitoring of only relevant threats while conserving system resources.
Solution Approach 2:
The patent changes the parameter of detection filtering by introducing confidence score thresholds. Detections are automatically onboarded or rejected based on whether their confidence scores meet predetermined thresholds, transforming the approach from volume-based onboarding to quality-based onboarding, thereby maintaining comprehensive monitoring while optimizing resource usage.
3Reliability
If multiple engineers manually manage security detections, then detection accuracy is improved, but scalability deteriorates as network size increases
Solution Approach 1:
The system replaces the need for multiple human engineers with an automated machine learning-based evaluation system that independently assesses and manages security detections. This autonomous system maintains detection accuracy through algorithmic consistency while providing unlimited scalability as it does not depend on human resource availability.
Solution Approach 2:
The patent creates a universal automated evaluation system that can handle any volume and type of security detections across networks of any size. The machine learning model serves multiple functions including initial assessment, confidence scoring, threshold comparison, and onboarding decisions, making the system adaptable to growing network complexities without requiring additional human engineers.
4Reliability
If manual detection evaluation is used, then false positives can be identified, but the process becomes tedious and error-prone
Solution Approach 1:
The system replaces tedious manual evaluation with automated machine learning-based assessment that consistently identifies false positives through algorithmic analysis. The automated process eliminates human errors, fatigue, and subjectivity, providing reliable false positive identification while dramatically improving operational simplicity through hands-free automated processing.
Data Source
AI summary
Methods, systems, apparatuses, and computer program products are provided for evaluating security detections. A detection instance obtainer obtains detection instances from a pool, such as a security detections pool. The detection instances may be obtained for detections that meet a predetermined criterion, such as detections that have not been onboarded or rejected, or detections that have generated detection instances for a threshold time period. The detection may be onboarded or rejected automatically based on a volume thresholder and/or a detection performance evaluator. For instance, the volume thresholder may be configured to automatically onboard the detection if the volume of the detection instances is below a first threshold, and reject the detection if the volume is above a second threshold. The detection performance evaluator may be configured to onboard or reject the detection based on an efficacy of the detection (e.g., based on a true positive rate of the detection instances).


