Weighted Peer Group Risk Scoring for Selective Security Alerts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional user and entity behavior analytics (UEBA) techniques suffer from a high number of false positives, leading to alert fatigue and inefficiencies in identifying actual security threats due to the need for security analysts to review numerous false alarms.

Innovation Solution

Utilizing weighted peer groups to categorize and assign importance to relationships between entities, determining the extent of operation performance within these groups, and calculating a risk score to selectively trigger security alerts based on these assessments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional UEBA techniques are used to detect security threats, then detection capability is improved, but false positive rate increases

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The system segments peers into different peer groups based on their relationships with the entity (organizational, security, collaboration, behavioral relationships). This segmentation allows for more precise analysis by comparing entity behavior against multiple distinct peer groups rather than a single aggregate group, reducing false positives while maintaining detection capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different weights are assigned to different peer groups based on their relevance to the entity. For example, security peer groups may be weighted higher than organizational peer groups. This local quality approach allows the system to emphasize more critical comparison groups while downplaying less relevant ones, improving measurement precision.

Inventive Principle:
Principle #3Local quality

2Reliability

If conventional security monitoring systems review all anomalies, then threat detection thoroughness is improved, but analyst time consumption increases

Engineering Contradiction:
Improvethreat detection thoroughnessVSAvoidanalyst review time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by automatically calculating risk scores for anomalies before they reach the analyst. By pre-processing anomalies through peer group comparison and risk scoring, the system filters and prioritizes alerts, allowing analysts to focus only on high-risk items rather than reviewing all anomalies manually.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses feedback mechanisms where risk scores and peer group comparisons continuously refine anomaly detection. Analyst decisions on flagged anomalies feed back into the system, improving future risk score accuracy and reducing the need for manual review of low-risk items, thereby reducing analyst time consumption.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If peer groups are created with detailed relationship categorization, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The peer group classification system uses universal relationship categories (organizational, security, collaboration, behavioral) that can be applied across different entities and contexts. This multi-functionality allows the same framework to work for various entity types without requiring custom complex logic for each case, managing system complexity while maintaining detection accuracy.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system manages complexity by changing parameters such as peer group weights and relationship thresholds based on organizational context. These parameter adjustments allow the system to adapt to different environments without restructuring the core logic, maintaining detection accuracy while controlling system complexity through configurable parameters.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12373757B2Using weighted peer groups to selectively trigger a security alert
Publication Date: 2025.07.29 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12373757B2 patent drawing
  • US12373757B2 patent drawing
  • US12373757B2 patent drawing

AI summary

Techniques are described herein that are capable of using weighted peer groups to selectively trigger a security alert. A determination is made that an entity performs an operation. The entity has peers that are categorized among peer groups. For each peer group, an extent to which the peers in the peer group perform the operation is determined. Weights are assigned to the respective peer groups. For each peer group, the extent to which the peers in the peer group perform the operation and the weight that is assigned to the peer group are combined to provide a respective weighted group value. A risk score, which is based at least in part on the weighted group values of the peer groups, is assigned to the operation. The security alert regarding the operation is selectively triggered based at least in part on the risk score.