Security Issue Context Analysis for Analyst Triage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security systems fail to effectively provide context and relationships between security issues to security analysts, leading to inefficient mitigation actions, as roughly 70-80% of analyzed cases are not real security incidents that need to be addressed.
Innovation Solution
A system that generates and displays information to security analysts by identifying similar cases using a model trained on linguistic contexts and natural language processing, providing a true positive rate and mitigation rate to prioritize and manage potential security issues effectively.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security systems pass all potential security issues to security analysts for manual investigation, then all security issues can be thoroughly analyzed, but the workload and time consumption increase significantly due to the high volume of cases
Solution Approach 1:
The system enables self-service by implementing automated case prioritization and triage mechanisms that allow the security system itself to pre-process and categorize cases before analyst review, reducing the burden on analysts while maintaining thorough analysis of critical issues
Solution Approach 2:
The patent introduces an intermediary automated analysis layer between the case generation system and human analysts. This intermediary performs initial case assessment, grouping, and prioritization based on multiple factors, serving as a mediator that filters and prepares cases for efficient analyst review
2Measurement precision
If security analysts investigate all potential security issues manually, then accurate determination of real security incidents can be achieved, but productivity decreases due to the large number of cases requiring review
Solution Approach 1:
The system segments the case analysis process into multiple stages: automated preliminary assessment, intermediate prioritization, and final analyst review. This segmentation allows different types of cases to be handled appropriately, maintaining high accuracy for critical cases while improving overall throughput by automating routine assessments
Solution Approach 2:
The patent implements dynamic parameter changes by adjusting case prioritization criteria based on multiple evolving factors including case characteristics, historical data, and current security context. This allows the system to adaptively focus analyst attention on the most critical cases while maintaining comprehensive coverage
3Ease of operation
If no context information is provided to security analysts about relationships between security issues, then the system remains simple and fast, but analysts cannot effectively determine whether potential issues are real problems needing mitigation
Solution Approach 1:
The system performs preliminary actions by pre-processing and organizing context information about case relationships, patterns, and historical data before presenting cases to analysts. This preliminary preparation includes grouping related cases and providing contextual insights that enable faster, more accurate analyst decision-making
Solution Approach 2:
The patent implements feedback mechanisms that provide analysts with contextual information about case relationships, similar cases, and patterns derived from historical data. This feedback loop enables analysts to make more informed decisions while the system learns from analyst outcomes to improve future case prioritization and context provision
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Disclosed herein is a system for generating and displaying information useful to help a security analyst understand a scale and a root cause of a potential security issue associated with a resource. The resource can include a server, a storage device, a user device (e.g., a personal computer, a tablet computer, a smartphone, etc.), a virtual machine, networking equipment, etc. The resource may be one that is under control of an entity operating a security operations center. Additionally or alternatively, the resource may be one that is configured to be monitored by the security operations center. The information provides the security analyst with a broader context of the potential security issue based on relationships between the potential security issues and other security issues. Consequently, the information enables the security analyst to implement more efficient and effective actions to handle the potential security issue.