Threat Intelligence Correlation for Anomaly Detection Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Evaluating the effectiveness and behavior of behavior anomaly detection algorithms in SIEM systems is challenging due to the lack of a ground truth, making it difficult to distinguish between high-impact cyber intrusions and commodity malware, and to determine the type of attack occurring.

Innovation Solution

The use of threat intelligence, structured in formats like STIX, CybOX, or TAXII, is integrated with machine learning to associate behavior anomalies with context, enabling the characterization of anomaly detection engine performance and identifying false negatives by correlating Indicators of Compromise (IOCs) with detected features.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If behavior anomaly detection algorithms are used in SIEM systems, then security events can be detected and alerts generated, but the effectiveness and behavior of these algorithms cannot be properly evaluated due to lack of ground truth

Engineering Contradiction:
Improvedetection effectivenessVSAvoidperformance evaluation accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent introduces threat intelligence data as an intermediary to bridge the gap between anomaly detection outputs and ground truth. By correlating detected anomalies with external threat intelligence (IOC databases, threat feeds), the system can evaluate detection effectiveness without requiring perfect ground truth labels, thus resolving the measurement precision problem while maintaining reliability assessment capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where anomaly detection results are continuously compared against threat intelligence data, and performance metrics are fed back to refine detection algorithms. This closed-loop approach allows progressive improvement of detection effectiveness while enabling accurate performance measurement through systematic evaluation against known threat patterns

Inventive Principle:
Principle #23Feedback

2Measurement precision

If analysts manually investigate security alerts, then they can identify alerts of concern and determine remediation actions, but a relatively large staff is required which increases operational complexity

Engineering Contradiction:
Improvealert identification accuracyVSAvoidoperational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system enables self-service capability where the anomaly detection engine automatically enriches alerts with threat intelligence context and prioritizes them based on severity. This automation reduces the manual investigative burden on analysts while maintaining high accuracy in identifying critical alerts, thus improving alert identification accuracy without proportionally increasing operational complexity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-enriching alerts with threat intelligence data, pre-classifying severity levels, and pre-prioritizing critical alerts before they reach analysts. This preparatory work reduces the complexity of manual investigation while preserving accurate alert identification, as analysts receive pre-processed, context-rich alerts rather than raw data requiring extensive manual analysis

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If threat intelligence is integrated with machine learning to characterize anomaly detection performance, then true positive and false negative rates can be determined, but the system complexity increases

Engineering Contradiction:
Improveperformance characterization precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the performance evaluation function into distinct modular components: anomaly detection module, threat intelligence correlation module, performance metrics calculation module, and reporting module. This segmentation allows precise performance characterization through systematic evaluation while managing system complexity through modular architecture, where each component can be independently developed, tested, and maintained

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10728264B2Characterizing behavior anomaly analysis performance based on threat intelligence
Publication Date: 2020.07.28 MICRO FOCUS LLC
  • US10728264B2 patent drawing
  • US10728264B2 patent drawing
  • US10728264B2 patent drawing

AI summary

A technique includes receiving data identifying behavior anomalies that are exhibited by entities that are associated with a computer system. The technique includes associating the behavior anomalies with contexts based at least in part on threat intelligence to provide modified anomalies. The threat intelligence associates the contexts with indicators of potential breach. The technique includes characterizing the behavior anomaly identification based at least in part on the threat intelligence. The characterization includes applying machine learning to features of the modified anomalies to classify the identified behavior anomalies.