Threat Relevancy Identification via User Affinity Clustering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current threat-detection security techniques fail to accurately identify the relevancy of detected potential threats, leading to deficiencies in threat prioritization and ineffective threat information provision, especially with the increasing number of threats and attacks.
Innovation Solution
A method that identifies threat relevancy based on user affinity by accessing and enriching security-related training data, creating user clusters based on similarity, and determining a risk posture without user interaction, using indicators of compromise, security observables, and artifacts to enhance threat relevancy identification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional threat detection systems analyze all detected threats equally, then comprehensive threat coverage is achieved, but the accuracy of threat prioritization deteriorates due to inability to identify relevant threats among large volumes
Solution Approach 1:
The patent segments users into distinct clusters based on their security profiles, roles, and historical behavior patterns. This segmentation allows the system to prioritize threats differently for different user groups, improving relevancy identification accuracy without requiring analysis of all threats for all users equally.
Solution Approach 2:
The system dynamically changes prioritization parameters based on user cluster characteristics, threat types, and contextual factors. By adjusting relevance weights and prioritization criteria according to specific user profiles and threat contexts, the system achieves higher accuracy in identifying relevant threats among large volumes.
2Measurement precision
If security teams manually review all threats to ensure accurate prioritization, then threat relevancy identification improves, but the productivity and response speed deteriorate due to limited human resources
Solution Approach 1:
The system performs automatic threat prioritization and relevancy identification without requiring manual human review. By implementing automated clustering algorithms and machine learning models that analyze user profiles, threat characteristics, and contextual data, the system achieves accurate threat prioritization independently, maintaining both high accuracy and productivity.
Solution Approach 2:
The patent replaces manual human analysis (mechanical system) with automated computational algorithms. Machine learning models and clustering algorithms process and prioritize threats based on learned patterns from user behavior and threat data, substituting human cognitive processes with computational processes that scale without additional human resources.
3Measurement precision
If the system requests user input and interaction to determine threat relevancy, then the accuracy of individual user threat assessment improves, but the ease of operation and user burden worsen
Solution Approach 1:
The system automatically determines user clusters and threat relevancy without requiring users to provide input or interact with the system. User profiles are constructed from observed behavior patterns, historical data, and system metadata, allowing the system to self-determine threat prioritization accurately without user burden.
Solution Approach 2:
The system uses implicit feedback from user interactions with security tools, system logs, and observed behavior patterns to continuously refine user profiles and cluster assignments. This feedback mechanism allows the system to improve individual user threat assessment accuracy passively, without requiring explicit user input or interaction.
Data Source
AI summary
Embodiments of the present disclosure provide enhanced threat relevancy identification user affinity of users within a security system. Security-related training data within a security system including indicators of compromise (IoC), security observables, and artifacts are evaluated and enriched to provide training data enrichment results for features collection. Clusters of users are created based on similarity of training data enrichment results between users. A risk posture of a cluster of users is determined based on relevancy of a risk detected by a user in the user cluster.


