Security Vulnerability Recommendation via Analyst Expertise Modeling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security management systems fail to effectively recommend the most relevant and urgent security vulnerabilities to human analysts, as they lack the ability to prioritize issues based on analyst expertise and issue severity, leading to inefficient resolution of security threats.

Innovation Solution

A data processing system that generates analyst-issue models by analyzing interaction logs and issue data, using machine learning to recommend security vulnerabilities that match an analyst's expertise and criticality, thereby prioritizing issues for efficient resolution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If automated security testing tools are used to identify vulnerabilities, then the quantity of detected security issues increases, but the ability to prioritize and resolve critical issues efficiently deteriorates due to lack of personalization to analyst expertise

Engineering Contradiction:
Improvequantity of detected security vulnerabilitiesVSAvoidefficiency of vulnerability resolution
Core Design Contradiction:
Quantity of substanceVSProductivity

Solution Approach 1:

The system automatically generates analyst models and issue recommendations without manual intervention. The security management system self-services by autonomously analyzing interaction logs, building analyst profiles, and generating personalized vulnerability recommendations, eliminating the need for manual prioritization configuration

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system monitors and analyzes security analyst interactions with vulnerability issues to generate feedback loops. By continuously learning from analyst behavior patterns, the system refines its understanding of analyst expertise and adjusts recommendations accordingly, improving prioritization accuracy over time

Inventive Principle:
Principle #23Feedback

2Loss of information

If security management systems provide comprehensive vulnerability lists to analysts, then complete information is available, but analysts spend excessive time filtering and prioritizing issues, leading to loss of time

Engineering Contradiction:
Improvecompleteness of vulnerability informationVSAvoidtime spent by analysts on issue prioritization
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system performs preliminary prioritization actions by pre-analyzing vulnerability data and matching it with analyst expertise models before presenting issues to analysts. This advance preparation ensures that when analysts receive vulnerability lists, they are already personalized and prioritized according to each analyst's specific expertise and the criticality of issues

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system extracts and separates the prioritization function from the comprehensive vulnerability list. By using machine learning to identify and extract the most relevant vulnerabilities for each analyst based on their expertise, the system presents only the necessary subset of issues rather than the complete unfiltered list

Inventive Principle:
Principle #2Taking out (Extraction)

3Device complexity

If generic vulnerability recommendations are provided to all analysts, then system complexity is reduced, but the relevance and urgency of recommendations to individual analysts deteriorates

Engineering Contradiction:
Improvecomplexity of recommendation systemVSAvoidprecision of vulnerability relevance to analyst expertise
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The system dynamically changes recommendation parameters based on individual analyst characteristics. By adjusting recommendation criteria according to each analyst's demonstrated expertise, interaction patterns, and performance metrics, the system transforms static generic recommendations into dynamic personalized suggestions without requiring complex manual configuration

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11030322B2Recommending the most relevant and urgent vulnerabilities within a security management system
Publication Date: 2021.06.08 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11030322B2 patent drawing
  • US11030322B2 patent drawing
  • US11030322B2 patent drawing

AI summary

Mechanisms are provided for accessing security vulnerability issue information. The mechanisms monitor security analyst interactions with security vulnerability issues via the security management system to generate analyst interaction log data, and generate one or more security analyst models corresponding to one or more security analysts by performing a machine learning operation on the analyst interaction log data. The mechanisms generate an analyst-issue model based on the one or more security vulnerability issue models and the one or more security analyst models, and generate an issue recommendation for a security analyst based on the analyst-issue model.