Dynamic Alert Prioritization for Real-Time Situational Awareness: A Hidden Markov Model Framework With Active Learning

Yeongwoo Kim, György Dán · IEEE Transactions on Dependable and Secure Computing · 2025

Real-time cyber situational awareness (SA) is crucial for effective and timely incident response. However, maintaining SA requires substantial human effort; security analysts must analyze large volumes of alerts, many of which are false positives triggered by anomaly-based intrusion detection systems (IDSs). Efficiently prioritizing these alerts is vital to enable analysts to focus on real threats without delay. In this paper, we present two key contributions designed to improve real-time SA. First, we propose modeling dynamic alert prioritization as an active learning problem in a hidden Markov model (HMM) with the objective to minimize the mean squared error (MSE) of the belief. We propose to use the uncertainty of the belief as a proxy for the MSE of the belief, and we develop two computationally tractable policies for choosing alerts to investigate. Second, we propose and evaluate a state space and an exploit space reduction method to reduce the computational complexity of the belief update. We use simulations on synthetic and real dependency graphs to evaluate the proposed policies. Our results show that the proposed investigation policies reduce the MSE of the belief by up to 50% compared to baseline policies, and they are robust to high false alert rates and to investigation errors. Our results also show that state space reduction can reduce the computation time by 85% without a significant increase in the belief MSE.

Read the paper · More papers on PaperTik