IP Library Patent Application 18525672
Patent Application
App. No. 18/525,672

METHOD, PRODUCT, AND SYSTEM FOR AUTOMATICALLY ISOLATING MALICIOUS SECURITY ALERTS FROM BENIGN ALERTS USING AN ENSEMBLE MODEL OF PATTERN RECOGNITION TECHNIQUES

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/525,672
Abstract

Disclosed is an improved approach for managing security alerts to automatically isolate malicious security alerts from benign alerts using an ensemble model of pattern recognition techniques. In some embodiments, the approach provides for automatically isolating security alerts of malicious attack from security alerts that correspond to undesirable, yet benign, activity in computer networks, cloud infrastructures and SAAS applications. Specifically, the approach provides for qualitative contextual assessments of these alerts using an ensemble of models. These ensemble models leverage a history of security events on a computer network, cloud infrastructure and SAAS applications to determine a level of relevance for received alerts and determine, based on that level of relevance, how or if they should be presented to an administrator.

Claims (37)

1 . A method for automatically isolating malicious security alerts from benign alerts using an ensemble model of pattern recognition techniques, comprising:

maintaining an alert history comprising a plurality of stored alerts;

receiving a new alert;

processing the new alert using an ensemble of models, wherein the ensemble of models comprises two or more of an account-specific model, a site-specific model, and a type specific model, and the two or more of an account-specific model, a site-specific model, and a type-specific model each generate a model score;

generating a score for the new alert by combining model scores from the ensemble of models according to a set of logic; and

applying a threshold to the score to determine handling of the new alert.

2 . The method of claim 1 , wherein the ensemble of models comprises the account-specific model, the site-specific model, and the type specific model.

3 . The method of claim 1 , wherein the account-specific model analyzes the new alert against one or more stored alerts of the plurality of stored alerts of the alert history, and the one or more stored alerts and the new alert having the same alert type and corresponding to the same account.

4 . The method of claim 1 , wherein the site-specific model analyzes the new alert against one or more stored alerts of the plurality of stored alerts of the alert history, and the one or more stored alerts and the new alert having the same alert type and corresponding to the same site.

5 . The method of claim 1 , wherein the type-specific model analyzes the new alert against one or more stored alerts of the plurality of stored alerts of the alert history, and the one or more stored alerts and the new alert having the same alert type.

6 . The method of claim 1 , wherein a qualitative label is assigned to the new alert, the qualitative label being assigned based on at least a determination of which model is most significant for the score and whether the new alert is common or uncommon as determined by a threshold.

7 . The method of claim 6 , wherein alert handling comprises at least grouping the new alert with one or more other alerts having the same type and qualitative label.

8 . The method of claim 7 , wherein alerts in a group are presented together and changes to a member of the group can be applied to all member of the group with a single action.

9 . The method of claim 1 , wherein the ensemble of models comprises sigmoid functions, and respective ones of the sigmoid functions are used to determine a frequency or persistence value of a corresponding feature in the new alert.

10 . The method of claim 9 , wherein frequency or persistence values determined based on respective sigmoid functions are combined to generate a single value for each model in the ensemble of models, and the frequency or persistence values are combined using any combination of a min, max, mean, mode, or a union of probabilities.

11 . A non-transitory computer readable medium having stored thereon a set of instructions, the set of instructions, when executed by a processor, causing a set of acts for automatically isolating malicious security alerts from benign alerts using an ensemble model of pattern recognition techniques, the set of acts comprising:

maintaining an alert history comprising a plurality of stored alerts;

receiving a new alert;

processing the new alert using an ensemble of models, wherein the ensemble of models comprises two or more of an account-specific model, a site-specific model, and a type specific model, and the two or more of an account-specific model, a site-specific model, and a type-specific model each generate a model score;

generating a score for the new alert by combining model scores from the ensemble of models according to a set of logic; and

applying a threshold to the score to determine handling of the new alert.

12 . The non-transitory computer readable medium of claim 11 , wherein the ensemble of models comprises the account-specific model, the site-specific model, and the type specific model.

13 . The non-transitory computer readable medium of claim 11 , wherein the account-specific model analyzes the new alert against one or more stored alerts of the plurality of stored alerts of the alert history, and the one or more stored alerts and the new alert having the same alert type and corresponding to the same account.

14 . The non-transitory computer readable medium of claim 11 , wherein the site-specific model analyzes the new alert against one or more stored alerts of the plurality of stored alerts of the alert history, and the one or more stored alerts and the new alert having the same alert type and corresponding to the same site.

15 . The non-transitory computer readable medium of claim 11 , wherein the type-specific model analyzes the new alert against one or more stored alerts of the plurality of stored alerts of the alert history, and the one or more stored alerts and the new alert having the same alert type.

16 . The non-transitory computer readable medium of claim 11 , wherein a qualitative label is assigned to the new alert, the qualitative label being assigned based on at least a determination of which model is most significant for the score and whether the new alert is common or uncommon as determined by a threshold, alert handling comprises at least grouping the new alert with one or more other alerts having the same type and qualitative label, and alerts in a group are presented together where changes to a member of the group can be applied to all members of the group with a single action.

17 . The non-transitory computer readable medium of claim 11 , wherein the ensemble of models comprises sigmoid functions, and respective ones of the sigmoid functions are used to determine a frequency or persistence value of a corresponding feature in the new alert, and frequency or persistence values determined based on respective sigmoid functions are combined to generate a single value for each model in the ensemble of models, and the frequency or persistence values are combined using any combination of a min, max, mean, mode, or a union of probabilities.

18 . A computing system for automatically isolating malicious security alerts from benign alerts using an ensemble model of pattern recognition techniques comprising:

a memory storing a set of instructions; and

a processor to execute the set of instructions to perform a set of acts comprising:

maintaining an alert history comprising a plurality of stored alerts;

receiving a new alert;

processing the new alert using an ensemble of models, wherein the ensemble of models comprises two or more of an account-specific model, a site-specific model, and a type specific model, and the two or more of an account-specific model, a site-specific model, and a type-specific model each generate a model score;

generating a score for the new alert by combining model scores from the ensemble of models according to a set of logic; and

applying a threshold to the score to determine handling of the new alert.

19 . The computing system of claim 18 , wherein the ensemble of models comprises the account-specific model, the site-specific model, and the type specific model.

20 . The computing system of claim 18 , wherein the account-specific model analyzes the new alert against one or more stored alerts of the plurality of stored alerts of the alert history, and the one or more stored alerts and the new alert having the same alert type and corresponding to the same account; the site-specific model analyzes the new alert against one or more stored alerts of the plurality of stored alerts of the alert history, and the one or more stored alerts and the new alert having the same alert type and corresponding to the same site; and the type-specific model analyzes the new alert against one or more stored alerts of the plurality of stored alerts of the alert history, and the one or more stored alerts and the new alert having the same alert type.

Assignments (2)
SECURITY INTEREST Recorded Oct 29, 2024
From: VECTRA AI, INC.
To: AB PRIVATE CREDIT INVESTORS LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 069061/0588 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2023
From: CHEN, HSIN; MHATRE, HIMANSHU; JAVED, IRINA; HANNAH, DANIEL CARLTON
To: VECTRA AI, INC.
Reel/Frame 065724/0548 →