Prioritized Security Recommendations via Collaborative Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security analysts face challenges in providing relevant and timely recommendations to clients for mitigating or preventing security incidents, often resulting in ineffective responses and increased costs due to the volume of log data and the need for customized actions.

Innovation Solution

A method utilizing a trained action model and collaborative filtering model to determine and prioritize recommended actions based on historical success and similarity to target organizations, reducing the time and expense of security experts by providing tailored and contextually relevant responses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If security analysts manually analyze log data and create customized recommendations for each client, then the recommendations are tailored to specific client needs, but the time and cost required increases significantly

Engineering Contradiction:
Improvecustomization of recommendationsVSAvoidtime for analysts to create recommendations
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system creates templates for security recommendations based on patterns from historical incidents. These templates can be automatically instantiated and customized for specific clients, reducing the time analysts spend creating recommendations from scratch while maintaining relevance and effectiveness

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system dynamically adjusts recommendation parameters based on client-specific factors such as industry, organization size, and historical incident data. This allows automated generation of customized recommendations by changing key parameters rather than manually creating each recommendation

Inventive Principle:
Principle #35Parameter changes

2Reliability

If security analysts provide comprehensive recommendations for all potential security incidents, then client satisfaction increases, but the volume of recommendations becomes overwhelming and may be ignored

Engineering Contradiction:
Improveclient satisfactionVSAvoidvolume of recommendations
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system prioritizes recommendations based on client-specific risk factors, industry characteristics, and historical incident patterns. This ensures that the most relevant and high-impact recommendations are presented first, rather than providing an undifferentiated list of all possible recommendations

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system provides a prioritized subset of the most critical recommendations rather than all possible recommendations. This partial action approach ensures clients receive the essential security measures without being overwhelmed by excessive information

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If security recommendations are generated quickly using automated systems, then response time decreases, but the relevance and effectiveness of recommendations may be reduced

Engineering Contradiction:
Improvespeed of generating recommendationsVSAvoidrelevance of recommendations
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system incorporates feedback loops that continuously learn from client responses to recommendations and historical incident outcomes. This allows the automated system to improve recommendation relevance over time by adjusting based on what actions are actually taken and what incidents occur

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system pre-processes and analyzes client data, industry patterns, and historical incidents before generating recommendations. This preliminary preparation enables the system to quickly generate relevant recommendations when needed without sacrificing accuracy or relevance

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11811520B2Making security recommendations
Publication Date: 2023.11.07 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11811520B2 patent drawing
  • US11811520B2 patent drawing
  • US11811520B2 patent drawing

AI summary

Embodiments are disclosed for a method. The method includes determining multiple recommended actions based on a security incident using an action model trained to make recommendations. The method also includes determining multiple similar targets to a target of the security incident using a collaborative filtering model trained to assign a confidence value of similarity between two targets. The method further includes assigning a plurality of weights to the recommended actions based on one or more actions taken by the similar targets and the confidence value, and a success or failure of the recommended actions. Additionally, the method includes generating a prioritized list of the recommended actions that is sorted based on the assigned weights.