Sigma Rule Filter Recommendation for False Positive Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current sigma rule systems for malicious content detection face challenges with manual review of false positives, leading to inefficiencies in time, cost, and resource consumption due to the need for weekly or monthly updates, and the lack of automated filtering and updating mechanisms.

Innovation Solution

A computerized method using machine learning algorithms, such as TRIE or recurrent neural networks, to automatically determine filters for sigma rules by analyzing candidate sets of tags, log sources, and selections, enabling real-time or near real-time updates and reducing redundant rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual review of logs is performed to identify false positives and update sigma rules, then accuracy of malicious content detection is improved, but time consumption and resource cost increase significantly

Engineering Contradiction:
Improveaccuracy of malicious content detectionVSAvoidtime consumption for manual review
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables self-service by automatically analyzing logs to identify false positives and autonomously updating sigma rules with appropriate filters. The machine learning model processes log data, determines which detections are false positives, and modifies sigma rules without human intervention, allowing the system to improve its own accuracy automatically.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual mechanical process of reviewing logs and updating rules is replaced with an automated computational system. The machine learning model substitutes human analysts by processing log data and generating filter updates, thereby eliminating the time-consuming manual review process while maintaining or improving detection accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual review and updating of sigma rules is performed, then false positives are reduced, but resource cost and operational burden increase

Engineering Contradiction:
Improvereduction of false positivesVSAvoidoperational burden of manual processes
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs self-service by automatically identifying false positives in logs and updating sigma rules with appropriate filters. The machine learning model analyzes detection patterns, determines false positives, and modifies rules autonomously, eliminating the need for manual operational intervention while maintaining reliability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback by continuously analyzing log data from malicious content detections, using the results to update sigma rules, and thereby improving future detection accuracy. This closed-loop feedback mechanism automatically reduces false positives by learning from past detection outcomes and adjusting rules accordingly.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If sigma rules are manually updated with filters, then detection accuracy improves, but the process requires frequent updates consuming significant resources

Engineering Contradiction:
Improvedetection accuracyVSAvoidfrequency of updates required
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system ensures continuity of useful action by continuously and automatically analyzing logs and updating sigma rules without interruption. The machine learning model operates continuously to identify false positives and apply filters, eliminating the need for periodic manual update cycles and maintaining constant detection accuracy improvement.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system performs self-service by automatically updating sigma rules with filters based on continuous log analysis. The machine learning model autonomously identifies patterns indicating false positives and modifies rules in real-time, eliminating the need for frequent manual intervention and resource-intensive update cycles.

Inventive Principle:
Principle #25Self-service

4Measurement precision

If extensive log review is performed to identify false positives, then filter accuracy improves, but time and computational resources are consumed

Engineering Contradiction:
Improvefilter accuracyVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The computationally intensive manual log review process is replaced with a machine learning-based automated system. The ML model efficiently processes log data using learned patterns, reducing the computational resources required compared to exhaustive manual analysis while maintaining or improving filter accuracy through intelligent pattern recognition.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12621330B2Systems and methods for automated filter recommendation for sigma rules
Publication Date: 2026.05.05 MORGAN STANLEY SERVICES GROUP INC
  • US12621330B2 patent drawing
  • US12621330B2 patent drawing
  • US12621330B2 patent drawing

AI summary

System and method for automated filter determination of Sigma rules used in a malicious content detection system is provided. The system and method can include training a machine learning algorithm based on candidate sets that can be determined based on a plurality of sigma rules, and performing inference for a plurality candidate sets corresponding to a plurality of sigma rules based on the machine learning algorithm to detect malicious content.