IP Library › Granted Patent US 12,289,338
Granted Patent B2
US 12,289,338 · App. 18/389,730 · Granted Apr 29, 2025

Threat disposition analysis and modeling using supervised machine learning

Inventors: Gary I. Givental (Bloomfield Hills, MI); Aankur Bhatia (Bethpage, NY); Paul J. Dwyer (Pewaukee, WI)
Assignee: International Business Machines Corporation
H04L63/1433G06F21/552G06N20/00H04L63/1408G06N5/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,289,338
App. No.
18/389,730
Granted
Apr 29, 2025
Kind
B2
Abstract

An enhanced threat disposition analysis technique is provided. In response to receipt of a security threat identified in an alert, a threat disposition score (TDS) is retrieved. The TDS is generated from a machine learning scoring model that is built from information about historical security threats, including historical disposition of one or more alerts associated with the historical security threats. The TDS is based in part on an effectiveness of a prior calculated TDS to predict a particular historical disposition associated with the alert. The system augments an alert to include the threat disposition score, optionally together with a confidence level, to generate an enriched alert. The enriched alert is then presented to the security analyst for handling directly. Preferably, the machine learning model is updated continuously as the system handles security threats, thereby increasing the predictive benefit of the TDS scoring.

Claims (43)

1. A method for threat disposition analysis, comprising:

responsive to receipt of a security threat identified in an alert, retrieving a threat disposition score (TDS), the threat disposition score generated from a machine learning scoring model built from information about historical security threats, including historical disposition of one or more alerts associated with the historical security threats, the TDS based in part on an effectiveness of a prior calculated TDS to predict a particular historical disposition associated with the alert; and

augmenting the alert to include the threat disposition score to generate an enriched alert.

2. The method as described in claim 1 wherein the enriched alert also includes historical information about how the security threat has been handled previously.

3. The method as described in claim 1 wherein the historical disposition comprises one of: an action taken by a security analyst in response to an alert associated with the historical security threat, and feedback on handling of the alert associated with the historical security threat.

4. The method as described in claim 1 further including building the machine learning scoring model, wherein the machine learning scoring model also is built from a set of attributes regarding an alert.

5. The method as described in claim 4 further including receiving data configuring the set of attributes.

6. The method as described in claim 1 further including updating the machine learning scoring model.

7. The method as described in claim 1 , further comprising:

providing a confidence level associated with the TDS; and

responsive to the confidence level reaching a threshold, automatically performing a set of one or more actions to respond to the security threat.

8. The method as described in claim 1 wherein the further handling is one of: closing the security threat as a false positive, and escalating the security threat.

9. An apparatus, comprising:

a processor;

computer memory holding computer program instructions executed by the processor for threat disposition analysis, the computer program instructions operative to:

retrieve a threat disposition score (TDS) in response to receipt of a security threat identified in an alert, the threat disposition score generated from a machine learning scoring model built from information about historical security threats, including historical disposition of one or more alerts associated with the historical security threats, the TDS based in part on an effectiveness of a prior calculated TDS to predict a particular historical disposition associated with the alert; and

augment the alert to include the threat disposition score to generate an enriched alert.

10. The apparatus as described in claim 9 wherein the enriched alert also includes historical information about how the security threat has been handled previously.

11. The apparatus as described in claim 9 wherein the historical disposition comprises one of: an action taken by a security analyst in response to an alert associated with the historical security threat, and feedback on handling of the alert associated with the historical security threat.

12. The apparatus as described in claim 9 wherein the computer program instructions are further operative to build the machine learning scoring model, wherein the machine learning scoring model also is built from a set of attributes regarding an alert.

13. The apparatus as described in claim 12 wherein the computer program instructions also are operative to receive data configuring the set of attributes.

14. The apparatus as described in claim 9 wherein the computer program instructions also are operative to update the machine learning scoring model.

15. The apparatus as described in claim 9 wherein the computer program instructions also are operative to:

provide a confidence level associated with the TDS; and

responsive to the confidence level reaching a threshold, automatically perform a set of one or more actions to respond to the security threat.

16. The apparatus as described in claim 9 wherein the further handling is one of: closing the security threat as a false positive, and escalating the security threat.

17. A computer program product in a computer readable storage device for use in a data processing system for threat disposition analysis, the computer program product holding computer program instructions that, when executed by the data processing system, are operative to:

retrieve a threat disposition score (TDS) in response to receipt of a security threat identified in an alert, the threat disposition score generated from a machine learning scoring model built from information about historical security threats, including historical disposition of one or more alerts associated with the historical security threats, the TDS based in part on an effectiveness of a prior calculated TDS to predict a particular historical disposition associated with the alert; and

augment the alert to include the threat disposition score to generate an enriched alert.

18. The computer program product as described in claim 17 wherein the enriched alert also includes historical information about how the security threat has been handled previously.

19. The computer program product as described in claim 17 wherein the historical disposition comprises one of: an action taken by a security analyst in response to an alert associated with the historical security threat, and feedback on handling of the alert associated with the historical security threat.

20. The computer program product as described in claim 17 wherein the computer program instructions are further operative to build the machine learning scoring model, wherein the machine learning scoring model also is built from a set of attributes regarding an alert.

21. The computer program product as described in claim 20 wherein the computer program instructions also are operative to receive data configuring the set of attributes.

22. The computer program product as described in claim 17 wherein the computer program instructions also are operative to update the machine learning scoring model.

23. The computer program product as described in claim 17 wherein the computer program instructions also are operative to:

provide a confidence level associated with the TDS; and

responsive to the confidence level reaching a threshold, automatically perform a set of one or more actions to respond to the security threat.

24. The computer program product as described in claim 17 wherein the further handling is one of: closing the security threat as a false positive, and escalating the security threat.

25. A security threat analysis platform, comprising:

one or more hardware processors;

computer memory storing computer program instructions configured to:

retrieve a threat disposition score (TDS) in response to receipt of a security threat identified in an alert, the threat disposition score generated from a machine learning scoring model built from information about historical security threats, including historical disposition of one or more alerts associated with the historical security threats, the TDS based in part on an effectiveness of a prior calculated TDS to predict a particular historical disposition associated with the alert; and

augment the alert to include the threat disposition score to generate an enriched alert.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 19, 2023
From: GIVENTAL, GARY I.; BHATIA, AANKUR; DWYER, PAUL J.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 065917/0017 →
Continuity (2)
Continuation 15623125 · Jun 14, 2017
Related Publication 20240129331A1 · Apr 18, 2024
References Cited (21)
US 9516053B1 · Muddu · 2016 [cited by examiner]
US 9690938B1 · Saxe · 2017 [cited by examiner]
US 10091231B1 · Gates · 2018 [cited by examiner]
US 12058135B2 · Djosic · 2024 [cited by examiner]
US 20090099988A1 · Stokes · 2009 [cited by applicant]
US 20150067857A1 · Symons · 2015 [cited by applicant]
US 20150172321A1 · Kirti · 2015 [cited by applicant]
US 20150286819A1 · Coden et al. · 2015 [cited by applicant]
US 20160364163A1 · Kamble · 2016 [cited by examiner]
US 20170063912A1 · Muddu · 2017 [cited by applicant]
US 20170118240A1 · Devi Reddy · 2017 [cited by applicant]
US 20170214708A1 · Gukal · 2017 [cited by applicant]
US 20180083988A1 · Kataoka · 2018 [cited by examiner]
US 20180183827A1 · Zorlular · 2018 [cited by applicant]
US 20180248893A1 · Israel · 2018 [cited by examiner]
IPCOM000243925d, “Analytic Forecasting of Future Electronic Cyber Threats with Deep Learning and Coevolutionary Strategies,” Oct. 28, 2015. [cited by applicant]
Kumar et al, IPCOM000239081D, “Machine Learning Based Predictive Model for Analyzing the Sentiments in Short Text,” Oct. 10, 2014. [cited by applicant]
List of IBM Patents or Patent Applications Treated as Related (signed 2022) 2 pages. [cited by applicant]
Santos et al, IPCOM000248565D, “Adaptive Learning Model for Application-Based Trust and Risk Scoring Using Consistent Profile Creation,” Dec. 19, 2016. [cited by applicant]
Stiborek et al, IPCOM000238197D, “Realistic Simulation of Network Behavior for Evaluation and Self-Adjustment of Intrusion Detection System,” Aug. 7, 2014. [cited by applicant]
U.S. Appl. No. 15/623,125, filed Jun. 14, 2017 titled “Threat disposition analysis and modeling using supervised machine learning”. [cited by applicant]