Home
International Journal of Science and Research Archive
International, Peer reviewed, Open access Journal ISSN Approved Journal No. 2582-8185

Main navigation

  • Home
    • Journal Information
    • Abstracting and Indexing
    • Editorial Board Members
    • Reviewer Panel
    • Journal Policies
    • IJSRA CrossMark Policy
    • Publication Ethics
    • Instructions for Authors
    • Article processing fee
    • Track Manuscript Status
    • Get Publication Certificate
    • Current Issue
    • Issue in Progress
    • Past Issues
    • Become a Reviewer panel member
    • Join as Editorial Board Member
  • Contact us
  • Downloads

ISSN Approved Journal || eISSN: 2582-8185 || CODEN: IJSRO2 || Impact Factor 8.2 || Google Scholar and CrossRef Indexed

Fast Publication within 48 hours || Low Article Processing Charges || Peer Reviewed and Referred Journal || Free Certificate

Research and review articles are invited for publication in January 2026 (Volume 18, Issue 1)

Reducing benign positives in threat detection systems: A graph-based approach to contextualizing security alerts

Breadcrumb

  • Home
  • Reducing benign positives in threat detection systems: A graph-based approach to contextualizing security alerts

Emmanuel Joshua *

Department of Computer Science, Texas Southern University, Texas, USA.

Review Article

International Journal of Science and Research Archive, 2025, 14(03), 346-352

Article DOI: 10.30574/ijsra.2025.14.3.0641

DOI url: https://doi.org/10.30574/ijsra.2025.14.3.0641

Received on 19 January 2025; revised on 03 March 2025; accepted on 05 March 2025

Threat detection systems form the backbone of modern enterprise cybersecurity programs, analyzing massive volumes of logs, network flows, and user activities to identify potentially malicious events. Despite continuous advances in detection techniques, these systems generate an abundance oding to alert fatigue, wasted analyst resources, and a delayed response to actual threats. This paper surveys the problem of benign positives and proposes a graph-based framework that unifies alerts, user roles, infrastructure metadata, and historical dispositions in a knowledge graph. By representing alerts and contextual entities as interconnected nodes and edges, security teams can quickly detect recurring benign patterns (e.g., routine scanning tasks, staging environment bulk transfers) and implement precise suppression rules. Experimental findings from a simulated enterprise environment indicate that this approach significantly reduces benign positives compared to conventional static filters or standalone machine learning methods. The paper closes with recommendations for integrating multi-cloud data, automated rule generation, privacy safeguards, and user-friendly interfaces that support non-expert security analysts.

Cybersecurity; Threat Detection; Benign Positives; False Positives; Security Automation; Anomaly Detection Graph-Based Modeling; Security Intelligence; Machine Learning; Security Data Visualization

https://journalijsra.com/sites/default/files/fulltext_pdf/IJSRA-2025-0641.pdf

Preview Article PDF

Emmanuel Joshua. Reducing benign positives in threat detection systems: A graph-based approach to contextualizing security alerts. International Journal of Science and Research Archive, 2025, 14(03), 346-352. Article DOI: https://doi.org/10.30574/ijsra.2025.14.3.0641.

Copyright © 2025 Author(s) retain the copyright of this article. This article is published under the terms of the Creative Commons Attribution Liscense 4.0

For Authors: Fast Publication of Research and Review Papers


ISSN Approved Journal publication within 48 hrs in minimum fees USD 35, Impact Factor 8.2


 Submit Paper Online     Google Scholar Indexing Peer Review Process

Footer menu

  • Contact

Copyright © 2026 International Journal of Science and Research Archive - All rights reserved

Developed & Designed by VS Infosolution