Automated Security Narrative Construction from Alerts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security analysts face significant challenges in manually sifting through thousands of security alerts to identify real security incidents, leading to alert fatigue and potential unresolved incidents, which compromises the organization's security posture.

Innovation Solution

Utilizing a deep learning architecture, such as Long Short-Term Memory (LSTM), to automatically construct a timeline of relevant security alerts in reverse chronological order, forming a kill-chain or security narrative, thereby reducing the burden on security analysts and enhancing incident response.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security analysts manually sift through thousands of security alerts to identify real security incidents, then they can construct security narratives and determine containment strategies, but this leads to alert fatigue and prolonged incident response time

Engineering Contradiction:
Improveaccuracy of security incident identificationVSAvoidincident response time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the large volume of security alerts into smaller, manageable groups using clustering algorithms. Alerts are divided into clusters based on similarity in characteristics such as alert type, severity, source, and target, allowing analysts to review condensed representations rather than individual alerts. This segmentation maintains detection accuracy while significantly reducing the time required to analyze security incidents.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an automated alert clustering system as an intermediary between raw security alerts and analyst review. This intermediary process automatically groups related alerts, identifies patterns, and presents consolidated security narratives to analysts, eliminating the need for manual sifting through thousands of individual alerts while preserving the ability to detect real security incidents.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple security products from various vendors are deployed to protect end-point devices, then comprehensive security coverage is achieved, but the number of security alerts increases significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidnumber of security alerts
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges alerts from multiple different security products and vendors into unified clusters based on their underlying security patterns. By combining alerts that share common characteristics (such as similar attack vectors, affected systems, or temporal patterns), the system consolidates the output from numerous security products into a manageable number of meaningful security incidents, maintaining comprehensive security coverage while reducing alert volume.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal alert clustering framework that can process and group alerts from diverse security products and vendors regardless of their specific formats or classification schemes. This multi-functional approach allows the system to handle heterogeneous alert data from multiple security sources uniformly, transforming the quantity of diverse alerts into a standardized set of clustered security incidents that can be analyzed effectively.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If analysts review each security alert individually to construct security narratives, then thorough analysis is possible, but this exhaustive manual analysis is extremely taxing and daunting

Engineering Contradiction:
Improvethoroughness of security analysisVSAvoidease of alert analysis
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent performs preliminary analysis by automatically clustering alerts and identifying potential security incidents before presenting them to analysts. The system pre-processes the alert data, groups related alerts together, and prepares consolidated security narratives in advance, so that analysts receive pre-organized information rather than raw individual alerts. This preliminary action maintains thorough analysis capability while dramatically improving ease of operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12210621B2System and method to automatically construct kill-chain from security alert
Publication Date: 2025.01.28 SALESFORCE INC
  • US12210621B2 patent drawing
  • US12210621B2 patent drawing
  • US12210621B2 patent drawing

AI summary

Methods, computer readable media, and devices to automatically construct kill-chain from security alerts are disclosed. One method may include collecting a plurality of security alerts, receiving a selection of a high severity security alert associated with a node and a user from among the plurality of security alerts, creating a security narrative for the high severity security alert by providing a set of historical security alerts to a deep learning architecture, the set including security alerts selected based on a relation to the node and the user, and identifying a subset of the set of historical security alerts, including security alerts relevant to the high severity security alert, in a reverse time order by the deep learning architecture, and providing the security narrative as part of a response to the high severity security alert.