Article

Improving Anomaly Detection and Reducing False Positives

Improving Anomaly Detection and Reducing False Positives

One of the major operational challenges faced by Security Operations Centres is the volume of alerts that require review. Many alerts are legitimate detections, but they may describe expected changes, repeated activity or low-risk events that do not require investigation.

aSIEMmetry aims to improve this situation through behavioural analysis and security entropy. The project is developing models that evaluate how strongly current activity differs from the established state of an asset or environment.

Moving beyond static thresholds

Static thresholds are useful when a clear limit exists, but they may produce false positives in environments where behaviour varies by user, device or time period. A server that normally handles large traffic volumes should not be evaluated in the same way as an employee workstation.

The security entropy model can incorporate the role and history of the monitored entity. This allows the system to consider whether an activity is unusual in context rather than merely whether it exceeds a fixed value.

Correlating deviations across several sources

A single weak signal may not justify an alert. Several related changes, however, may indicate a developing incident. For example, a new login location, an unusual process and unexpected outbound traffic may become significant when they occur together.

aSIEMmetry’s multi-agent architecture is designed to analyse different parts of this picture and combine them into a more complete assessment. This can help identify attacks that remain below the threshold of individual detection rules.

Making model output useful to analysts

Reducing false positives does not mean hiding uncertain information. Analysts need to understand which observations influenced an anomaly score and how the current behaviour differs from the baseline.

The project is therefore placing importance on explainability and the relationship between the entropy model and the LLM SOCagent. The SOCagent can help organize the evidence and present the reasons for prioritization in a more accessible form.

As the models are trained and validated, the consortium will continue measuring detection quality, stability and operational usefulness. The goal is to help SOC teams spend less time reviewing repetitive noise and more time investigating behavioural changes that may represent genuine security risk.

Back to Project News
Back to top