US 12,294,600 B2
Real time behavioral alert processing in computing environments
Hemant Kumar Sivaswamy, Pune (IN); and Alberto Pelliccione, Amsterdam (NL)
Assigned to International Business Machines Corporation, Armonk, NY (US)
Filed by International Business Machines Corporation, Armonk, NY (US)
Filed on Aug. 30, 2022, as Appl. No. 17/823,097.
Prior Publication US 2024/0073229 A1, Feb. 29, 2024
Int. Cl. H04L 9/40 (2022.01)
CPC H04L 63/1425 (2013.01) [H04L 63/1416 (2013.01)] 21 Claims
OG exemplary drawing
 
1. A computer implemented method for processing alerts, the computer implemented method comprising:
creating, by a computer system, a representation of an alert received for processing;
determining, by the computer system, a similarity of the alert with previously processed alerts using the representation of the alert and representations of the previously processed alerts;
evaluating, by a first evaluator in the computer system, an alert level for the alert based on previously processed similar alerts in response to the similarity being above a similarity threshold for similar alerts, wherein evaluating, by the first evaluator in the computer system, the alert level for the alert based on previously processed similar alerts in response to the similarity being above the similarity threshold for similar alerts comprises:
collecting, by the computer system, previously processed alerts that are identical to the alert and the previously processed alerts that are above the similarity threshold to form previously processed similar alerts;
determining, by the computer system, an aggregated verdict using the previously processed similar alerts;
determining, by the computer system, whether the aggregated verdict is ambiguous; and
marking, by the computer system, the alert as ambiguous in response to the aggregated verdict of the previously processed similar alerts being ambiguous; and
evaluating, by a second evaluator in the computer system, the alert level for the alert using a machine learning model in response to the similarity not being above the similarity threshold, wherein evaluating, by the second evaluator in the computer system, the alert level for the alert further comprises:
identifying, by the second evaluator in the computer system, the alert as serious if an alert score is greater than or equal to a serious threshold;
identifying, by the second evaluator in the computer system, the alert as ambiguous if the alert score is greater than an inconsequential threshold and less than the serious threshold; and
identifying, by the second evaluator in the computer system, the alert as inconsequential if the alert score is less than or equal to the inconsequential threshold.