Security Issue Context Analysis for Analyst Triage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security systems fail to effectively provide context and relationships between security issues to security analysts, leading to inefficient mitigation actions, as roughly 70-80% of analyzed cases are not real security incidents that need to be addressed.

Innovation Solution

A system that generates and displays information to security analysts by identifying similar cases using a model trained on linguistic contexts and natural language processing, providing a true positive rate and mitigation rate to prioritize and manage potential security issues effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security systems pass all potential security issues to security analysts for manual investigation, then all security issues can be thoroughly analyzed, but the workload and time consumption increase significantly due to the high volume of cases

Engineering Contradiction:
Improvesecurity issue analysis completenessVSAvoidanalyst time consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service by implementing automated case prioritization and triage mechanisms that allow the security system itself to pre-process and categorize cases before analyst review, reducing the burden on analysts while maintaining thorough analysis of critical issues

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary automated analysis layer between the case generation system and human analysts. This intermediary performs initial case assessment, grouping, and prioritization based on multiple factors, serving as a mediator that filters and prepares cases for efficient analyst review

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If security analysts investigate all potential security issues manually, then accurate determination of real security incidents can be achieved, but productivity decreases due to the large number of cases requiring review

Engineering Contradiction:
Improvesecurity incident identification accuracyVSAvoidcase analysis throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system segments the case analysis process into multiple stages: automated preliminary assessment, intermediate prioritization, and final analyst review. This segmentation allows different types of cases to be handled appropriately, maintaining high accuracy for critical cases while improving overall throughput by automating routine assessments

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic parameter changes by adjusting case prioritization criteria based on multiple evolving factors including case characteristics, historical data, and current security context. This allows the system to adaptively focus analyst attention on the most critical cases while maintaining comprehensive coverage

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If no context information is provided to security analysts about relationships between security issues, then the system remains simple and fast, but analysts cannot effectively determine whether potential issues are real problems needing mitigation

Engineering Contradiction:
Improveanalyst decision-making effectivenessVSAvoidsystem information processing complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-processing and organizing context information about case relationships, patterns, and historical data before presenting cases to analysts. This preliminary preparation includes grouping related cases and providing contextual insights that enable faster, more accurate analyst decision-making

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms that provide analysts with contextual information about case relationships, similar cases, and patterns derived from historical data. This feedback loop enables analysts to make more informed decisions while the system learns from analyst outcomes to improve future case prioritization and context provision

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3956791B1Providing context associated with a potential security issue for an analyst
Publication Date: 2024.01.03 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3956791B1 patent drawingFigure 1
  • EP3956791B1 patent drawingFigure 2
  • EP3956791B1 patent drawingFigure 3

AI summary

Disclosed herein is a system for generating and displaying information useful to help a security analyst understand a scale and a root cause of a potential security issue associated with a resource. The resource can include a server, a storage device, a user device (e.g., a personal computer, a tablet computer, a smartphone, etc.), a virtual machine, networking equipment, etc. The resource may be one that is under control of an entity operating a security operations center. Additionally or alternatively, the resource may be one that is configured to be monitored by the security operations center. The information provides the security analyst with a broader context of the potential security issue based on relationships between the potential security issues and other security issues. Consequently, the information enables the security analyst to implement more efficient and effective actions to handle the potential security issue.