Co-stimulation Algorithms

Simple conditional rules (if attribute X present at time of alert, then...)
Bayesian decision processing (Kruegel, Mutz, Robertson, Valeur)
unsupervised learning with profile tuning through human feedback (supervised inclusion or exclusion of data that was associated with a false positive)

There is great academic work in this area, but we need more implementations to actually determine the value in operational environments.