Automated Security Narrative Construction from Alerts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Security analysts face significant challenges in manually sifting through thousands of security alerts to identify real security incidents, leading to alert fatigue and potential unresolved incidents, which compromises the organization's security posture.
Innovation Solution
Utilizing a deep learning architecture, such as Long Short-Term Memory (LSTM), to automatically construct a timeline of relevant security alerts in reverse chronological order, forming a kill-chain or security narrative, thereby reducing the burden on security analysts and enhancing incident response.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If security analysts manually sift through thousands of security alerts to identify real security incidents, then they can construct security narratives and determine containment strategies, but this leads to alert fatigue and prolonged incident response time
Solution Approach 1:
The patent segments the large volume of security alerts into smaller, manageable groups using clustering algorithms. Alerts are divided into clusters based on similarity in characteristics such as alert type, severity, source, and target, allowing analysts to review condensed representations rather than individual alerts. This segmentation maintains detection accuracy while significantly reducing the time required to analyze security incidents.
Solution Approach 2:
The patent introduces an automated alert clustering system as an intermediary between raw security alerts and analyst review. This intermediary process automatically groups related alerts, identifies patterns, and presents consolidated security narratives to analysts, eliminating the need for manual sifting through thousands of individual alerts while preserving the ability to detect real security incidents.
2Reliability
If multiple security products from various vendors are deployed to protect end-point devices, then comprehensive security coverage is achieved, but the number of security alerts increases significantly
Solution Approach 1:
The patent merges alerts from multiple different security products and vendors into unified clusters based on their underlying security patterns. By combining alerts that share common characteristics (such as similar attack vectors, affected systems, or temporal patterns), the system consolidates the output from numerous security products into a manageable number of meaningful security incidents, maintaining comprehensive security coverage while reducing alert volume.
Solution Approach 2:
The patent creates a universal alert clustering framework that can process and group alerts from diverse security products and vendors regardless of their specific formats or classification schemes. This multi-functional approach allows the system to handle heterogeneous alert data from multiple security sources uniformly, transforming the quantity of diverse alerts into a standardized set of clustered security incidents that can be analyzed effectively.
3Measurement precision
If analysts review each security alert individually to construct security narratives, then thorough analysis is possible, but this exhaustive manual analysis is extremely taxing and daunting
Solution Approach 1:
The patent performs preliminary analysis by automatically clustering alerts and identifying potential security incidents before presenting them to analysts. The system pre-processes the alert data, groups related alerts together, and prepares consolidated security narratives in advance, so that analysts receive pre-organized information rather than raw individual alerts. This preliminary action maintains thorough analysis capability while dramatically improving ease of operation.
Data Source
AI summary
Methods, computer readable media, and devices to automatically construct kill-chain from security alerts are disclosed. One method may include collecting a plurality of security alerts, receiving a selection of a high severity security alert associated with a node and a user from among the plurality of security alerts, creating a security narrative for the high severity security alert by providing a set of historical security alerts to a deep learning architecture, the set including security alerts selected based on a relation to the node and the user, and identifying a subset of the set of historical security alerts, including security alerts relevant to the high severity security alert, in a reverse time order by the deep learning architecture, and providing the security narrative as part of a response to the high severity security alert.


