XAI Alert Screening for Malicious Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the context of cyber security, existing AI models struggle with transparency and efficiency due to high false positives and the complexity of analyzing large volumes of malicious log data, leading to a need for improved threat detection methods that require direct human intervention.
Innovation Solution
A valuable alert screening method utilizing Explainable Artificial Intelligence (XAI) and statistical analysis techniques, specifically through SHAP value calculations and Feature Outlier Score (FOS) aggregation, to generate a reliability indicator for AI predictions and efficiently detect malicious threats by processing and analyzing important features without bias.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If AI technology is introduced to analyze large amounts of malicious log data, then the detection capability is improved, but the transparency and understandability of the model decreases
Solution Approach 1:
The patent introduces XAI (Explainable AI) technology as an intermediary layer between the AI model and the analyst. The XAI module generates explanations for AI model decisions, making the black-box model transparent. This allows analysts to understand why the model made certain predictions without compromising the model's detection capability.
Solution Approach 2:
The patent implements a feedback mechanism where the system provides explanations for its decisions to the analyst, and the analyst can provide feedback on false positives and false negatives. This feedback loop allows the system to learn and improve its accuracy over time while maintaining transparency through continuous explanation generation.
2Productivity
If the number of analysts is reduced to handle the large volume of alerts, then the productivity is improved, but the measurement precision of the analysis decreases
Solution Approach 1:
The patent enables the system to perform self-service by automatically prioritizing and explaining alerts. The AI model automatically analyzes log data and generates explanations for potential threats, allowing analysts to focus only on high-priority items that require human intervention. This significantly increases productivity while maintaining analysis accuracy through intelligent automation.
Solution Approach 2:
The patent segments the alert handling process into multiple levels: automatic AI-based triage for routine alerts, and human analyst intervention only for complex or high-priority cases. This segmentation allows the system to handle the majority of alerts automatically, increasing productivity while preserving measurement precision for critical analysis through targeted human review.
3Loss of information
If XAI technology is used to explain AI model decisions, then the transparency is improved, but the complexity of the system increases
Solution Approach 1:
The patent extracts the explanation generation functionality from the core AI model by using separate XAI libraries and modules. This allows the explanation system to be added independently without redesigning the entire AI model architecture. The explanation layer is extracted as a separate component that works with the existing model, reducing overall system complexity while maintaining transparency.
4Measurement precision
If the entire log data is analyzed to ensure accurate analysis, then the measurement precision is improved, but the loss of time increases
Solution Approach 1:
The patent applies partial action by having the AI model perform preliminary filtering and prioritization of log data before it reaches the analyst. The system analyzes the most critical portions of the data first and provides explanations only for potential threats, rather than requiring comprehensive analysis of all log data. This partial approach maintains measurement precision for critical security issues while significantly reducing the time required for analysis.
Data Source
AI summary
A valuable alert screening method for detecting malicious threat includes generating an AI model based on training data for predicting test data, generating XAI explainability and selecting important features based on summary plot by using an explainer and training data, performing range processing based on data distribution of important features selected for analysis without bias, calculating a SHAP value average and standard deviation of each range group and then storing them to determine suspicion and reliability of test data, making prediction by using an AI model generated in advance after feature processing in the same way as the training data at the time of inputting the test data, calculating a SHAP value by using the test data and the explainer, loading FOS calculation information to calculate FOS for each important feature, and calculating a suspicion score for each data by aggregating the FOS after calculating the FOS for each feature.


