Weighted Peer Group Risk Scoring for Selective Security Alerts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional user and entity behavior analytics (UEBA) techniques suffer from a high number of false positives, leading to alert fatigue and inefficiencies in identifying actual security threats due to the need for security analysts to review numerous false alarms.
Innovation Solution
Utilizing weighted peer groups to categorize and assign importance to relationships between entities, determining the extent of operation performance within these groups, and calculating a risk score to selectively trigger security alerts based on these assessments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional UEBA techniques are used to detect security threats, then detection capability is improved, but false positive rate increases
Solution Approach 1:
The system segments peers into different peer groups based on their relationships with the entity (organizational, security, collaboration, behavioral relationships). This segmentation allows for more precise analysis by comparing entity behavior against multiple distinct peer groups rather than a single aggregate group, reducing false positives while maintaining detection capability.
Solution Approach 2:
Different weights are assigned to different peer groups based on their relevance to the entity. For example, security peer groups may be weighted higher than organizational peer groups. This local quality approach allows the system to emphasize more critical comparison groups while downplaying less relevant ones, improving measurement precision.
2Reliability
If conventional security monitoring systems review all anomalies, then threat detection thoroughness is improved, but analyst time consumption increases
Solution Approach 1:
The system performs preliminary action by automatically calculating risk scores for anomalies before they reach the analyst. By pre-processing anomalies through peer group comparison and risk scoring, the system filters and prioritizes alerts, allowing analysts to focus only on high-risk items rather than reviewing all anomalies manually.
Solution Approach 2:
The system uses feedback mechanisms where risk scores and peer group comparisons continuously refine anomaly detection. Analyst decisions on flagged anomalies feed back into the system, improving future risk score accuracy and reducing the need for manual review of low-risk items, thereby reducing analyst time consumption.
3Measurement precision
If peer groups are created with detailed relationship categorization, then detection accuracy is improved, but system complexity increases
Solution Approach 1:
The peer group classification system uses universal relationship categories (organizational, security, collaboration, behavioral) that can be applied across different entities and contexts. This multi-functionality allows the same framework to work for various entity types without requiring custom complex logic for each case, managing system complexity while maintaining detection accuracy.
Solution Approach 2:
The system manages complexity by changing parameters such as peer group weights and relationship thresholds based on organizational context. These parameter adjustments allow the system to adapt to different environments without restructuring the core logic, maintaining detection accuracy while controlling system complexity through configurable parameters.
Data Source
AI summary
Techniques are described herein that are capable of using weighted peer groups to selectively trigger a security alert. A determination is made that an entity performs an operation. The entity has peers that are categorized among peer groups. For each peer group, an extent to which the peers in the peer group perform the operation is determined. Weights are assigned to the respective peer groups. For each peer group, the extent to which the peers in the peer group perform the operation and the weight that is assigned to the peer group are combined to provide a respective weighted group value. A risk score, which is based at least in part on the weighted group values of the peer groups, is assigned to the operation. The security alert regarding the operation is selectively triggered based at least in part on the risk score.


