AUTONOMOUS ANALYSIS METHOD AND SYSTEM WITH EVIDENCE-DECISION MATCHING AND CLOSED-LOOP QUERY GENERATION FOR CYBER INCIDENT INVESTIGATION
Patent Information
- Authority / Receiving Office
- TR · TR
- Patent Type
- Applications
- Current Assignee / Owner
- İŞ NET ELEKTRONİK BİLGİ ÜRETİM DAĞITIM TİCARET & İLETİŞİM HİZMETLERİ ANONİM ŞİRKETİ
- Filing Date
- 2026-06-09
- Publication Date
- 2026-06-22
Smart Images

Figure 00000019_0000
Abstract
Description
1 TARIFF EVIDENCE-DECISION MATCHING AND CLOSED-LOOP QUERY FOR CYBER INCIDENT INVESTIGATION GENERATIVE AUTONOMOUS ANALYSIS METHOD AND SYSTEM Technical Area The invention enables the collection of event data from various data sources in cybersecurity environments. It is related to autonomous analysis methods and systems for analysis and evaluation. The invention specifically addresses evidence-decision matching, closed-loop query generation, and the replication of acquired evidence. 10 It relates to the autonomous analysis method and system that enables its re-execution. State of the Art The current systems used in cybersecurity operations centers (SOCs) today are based on 15 basic principles. security information and event management (SIEM), endpoint detection and response (EDR), and security It is based on orchestration, automation, and response (SOAR) solutions. These systems; for the organization data obtained from servers, network devices, user activity, applications, and security products within it. It centrally collects large volumes of log and event data, and organizes this data into a specific format. normalize by transforming and using predefined correlation rules or machine learning 20 It analyzes potential threats through various techniques and generates warnings about them. However, the word These systems are generally only for the initial detection of the event and presenting it as an alarm. The focus is on this phase, in order to understand whether the alarm is a real threat. It is unable to comprehensively automate the necessary in-depth investigation activities. In this context, during the process of verifying an alarm, analysts often manually review the relevant log records. It is examining the situation in this way, writing additional queries in different systems to determine the context of the event, By piecing together the collected data, we are trying to understand the whole situation and, if necessary, identify the threat. It involves linking information with intelligence sources. These processes use different tools and different data sources. And because it is often carried out using different methods, the process is a fragmented and time-consuming 30 It has a structure. Especially in high-volume environments, the generation of thousands of alarms every day leads analysts to... This allows for a detailed examination of only a limited portion of the data, leading to false positives. This makes it more difficult to identify and increases the risk of overlooking real threats. Furthermore... The fact that the analysis process relies heavily on human experience means that different analysts may view the same event differently. This leads to the problem of decision inconsistency by causing decisions to be made. This 35 2 As a result, existing systems are inadequate in terms of speed, consistency, and traceability in incident investigation processes. It has significant limitations. In current technologies, SIEM systems gather event data on a central platform to improve security. It provides broad visibility to its teams and allows them to use this data based on specific rules or behaviors. 5 It generates alerts regarding potential threats by analyzing them using analytics-supported methods. However, These systems mostly rely on predefined correlation rules and signature-based detection mechanisms. or because they are based on fixed analytical models, they do not reflect the specific characteristics of an emerging event. It is unable to act dynamically according to the context and adapt the investigation process to the context of the event. It cannot automatically reshape itself. In other words, after an alarm is generated, the system cannot automatically reshape itself. by identifying the information needs and creating new queries accordingly, and the results obtained it evaluates and changes the analysis method or automatically tries alternative scenarios Such abilities remain limited. Similarly, SOAR-based automation solutions accelerate incident response processes. For this purpose, it automates various workflows and processes such as alarm triage, notification, and isolation. It operates through predefined playbooks. However, these playbooks are static. Because it is defined as such, the system determines its own investigation path according to new evidence obtained during the incident. its ability to reconstruct, autonomously identify the need for additional information from different data sources, and It is not possible to evolve the decision-making process accordingly. Therefore, current solutions are not feasible every 20 years. Even though it automates certain steps, it covers the entire incident investigation process, obtaining Adaptive technology that adjusts itself according to the data received and constantly updates its decision-making logic during analysis. It does not offer a structure. While current systems offer significant benefits in terms of alarm generation and basic automation, 25 Together; gathering evidence, structuring this evidence, relating it to the decision, and the investigation process. such as recording all the steps and being able to run the same analysis again later in the same way. It fails to meet critical requirements end-to-end. Furthermore, it fails to determine which data is used to support a given decision. technically, it is based on its components, which queries and which interim evaluation steps. The inability to present it in a traceable and verifiable manner poses a risk in terms of auditability and reliability. 30 This constitutes a significant deficiency. One of the studies carried out to address the existing problems is US11463457B2 numbered and “Artificial Intelligence (AI) based cyber threat analyst to support a cyber security The invention is the subject of a patent titled "appliance". The invention is an artificial intelligence-based cyber threat analyst 35 It describes the system and identifies anomalies in the system using different data analysis processes and models. It is explained that this solution determines behaviors and forms hypotheses about potential threats. 3 when performing analyses that support or refute hypotheses using specific data points, The data obtained should be stored as structured evidence objects, and these pieces of evidence should be included in the decision. establishing a clear and traceable link between them and repeating the entire review process in the same way. It does not offer a mechanism to ensure its implementation. Therefore, it does not provide a mechanism to determine which data and processes will be used for the decision. This system allows for the verifiable demonstration, through retrospection, that it is based on a chain of transmission of exactly 5 This is not possible. Another study, numbered US10542015B2 and titled “Cognitive offense analysis using contextual data The invention is the subject of a patent titled "contextual and knowledge graphs". The invention analyzes security events contextually. It involves analyzing data using information graphs. In this solution, context 10 is derived from event data. A graph is created and enriched with relevant information sources before being presented to the analyst. Although a graphical approach allows for a better understanding of the phenomenon, the system itself is dynamic. through query generation and new data collection, ensuring that every piece of evidence forming the basis of the decision is traceable. such as recording and re-conducting the review process in a way that preserves its integrity. It appears that it does not include these functions. Furthermore, the system output shows that the final decision is made automatically. Because the decision-making process is left to analyst evaluation rather than being formulated, its autonomy is limited. It remains. Another study, numbered US11601442B2 and titled “System and method associated with expedient detection and reconstruction of cyber events in a compact scenario representation using 20 This invention is the subject of a patent titled "provenance tags and customizable policy". The invention is related to cybersecurity. reconstruction and visualization of events using provenance labels It is related to a system. This system processes the audit data stream and assigns reliability values to the data pieces. It assigns labels based on the event and creates a visual structure that represents the key components of the event. This approach is important in terms of reconstructing events and revealing key relationships. 25 While useful, an evidence-based decision-making mechanism, depending on the results obtained... The ability to generate new queries and continue the review process in a closed loop. It does not include this. Furthermore, the system ensures the verifiability of the decision and the exact repetition of the same review. because it does not provide the comprehensive logging and versioning mechanisms necessary for its execution, the analysis The reproducibility of the process remains limited. 30 Therefore, the vast majority of current technical solutions focus on event detection, data collection, or specific features. It offers functions to support the analysis steps, but not the end-to-end incident investigation process. It appears that a comprehensive and holistic approach has not been presented, especially in existing systems. Collecting data from different sources and organizing this data into a meaningful and standardized evidentiary structure. 35 transformation, systematic evaluation of the evidence obtained and the need for new information Identifying this need, automatically generating queries to address it, and organizing the results obtained into a single system. 4 The processes that need to be considered holistically within the decision-making mechanism are generally disconnected from each other and It is carried out with a limited level of automation. In addition, current solutions often base the analysis process on fixed rules or predefined principles. Since it was carried out within the framework of flows, according to the interim results obtained during the examination, 5 Dynamically changing the analysis method, trying alternative inquiry paths, and its own decision-making process It fails to offer a structure that develops iteratively. Similarly, it fails to provide a framework for determining which data supports a given decision. It is clear which components it is based on, which inquiry steps and which interim evaluation processes, The inability to present the evidence in a traceable and verifiable manner makes the decision subject to technical review. It makes it more difficult. 10 Furthermore, in existing systems, all steps of the review process, the data sources used, and the query... Saving the sets and the results obtained along with version information, so that the same event can be repeated. Furthermore, the mechanisms that would allow for re-analysis under the same conditions are also limited. This situation ensures both the verifiability of the analysis results and the standardization of the processes. 15 This makes it more difficult. For all these reasons, a system that can dynamically determine its own analytical path and obtain results... able to establish a clear and structured relationship between the evidence and the decision, and to consider the entire investigation process. an autonomous and integrated review approach that makes it possible to re-execute in a preserved state It is considered that this cannot be fully provided by technical solutions. Brief Description of the Invention The present invention meets the aforementioned requirements while eliminating all disadvantages. and data obtained from different data sources in cybersecurity environments, which brings some additional advantages. Autonomous analysis method for collecting, analyzing and evaluating event data 25 and is related to the system. Based on the current state of the art, the aim of the invention is to analyze cybersecurity incidents. In its investigation, the processes of evidence gathering, inquiry generation, and decision-making are autonomous and repeatable. by integrating decisions within an executable structure, making them technically verifiable and traceable. 30 The goal is to ensure its production. The purpose of the invention is to standardize information obtained from heterogeneous security data sources into a standard form of evidence. By converting it into an object structure, different data types can be presented in a consistent and analyzable form. The goal is to bring them together. 35 Another aim of the invention is to create closed systems that can dynamically generate new queries based on existing evidence. Thanks to the online inquiry mechanism, the incident investigation process is automated. The aim is to deepen the analysis and reduce the need for manual analysis. Another aim of the invention is to include information on the source, time, and transformation of each piece of evidence obtained. By storing the data in a structured manner, the data chain forming the basis of the decision remains open and transparent. The goal is to ensure that it can be traced. Another aim of the invention is to systematically integrate supporting and refuting evidence into a decision-making mechanism. By relating them in this way, the decisions made are objective and evidence-based. 10 The goal is to ensure its creation. Another purpose of the invention is iterative evaluation that guides the flow of analysis according to the sufficiency of evidence. Its structure allows for a higher level of accuracy and reliability in the crime investigation process. The goal is to ensure accessibility. 15 Another purpose of the invention is to enrich asset information, threat intelligence, and contextual data. thanks to its mechanisms, the event can be evaluated within a comprehensive context. is to ensure. Another purpose of the invention is to improve the queries, model versions, and processes used in the investigation process. By recording the steps, the analysis process can be monitored and tracked again. The goal is to ensure that it is brought to that state. Another purpose of the invention is to allow the same analysis to be repeated later using a replay manifest structure. the verifiability and technical reproducibility of decisions thanks to their execution is to ensure. Another purpose of the invention is to create digital trace mechanisms, such as hashes, that verify the integrity of evidence. This ensures data reliability and prevents subsequent alteration. 30 Another objective of the invention is to reduce dependence on external systems thanks to the model architecture that operates in a local environment. The goal is to enable secure analysis in closed networks without requiring additional resources. Another aim of the invention is to enable autonomous analysis and decision-making, thereby allowing human analysts to... 35 The goal is to reduce dependence and increase operational efficiency. 6 The structural and characteristic features and all the advantages of the invention are given in the figures below and in relation to these figures. This will be understood more clearly thanks to the detailed explanation written with references. Therefore, the evaluation should be made taking these figures and detailed explanations into consideration. It is required. 5 Brief Description of the Figures The structure of the current invention and the best understanding of its advantages, including additional components. This should be evaluated together with the figures explained below. 10 Figure 1; the cyber incident investigation process, starting from the receipt of the incident, including evidence gathering and inquiry generation, The steps of evidence evaluation and decision-making are interconnected within a closed-loop structure. This shows the general architecture of the autonomous analysis system in which it is performed. Reference Numbers 100. Autonomous analysis system 101. Event / alarm reception module 102. Initial evidence gathering module 20 103. Creating evidence objects module 104. Evidence integrity verification module 105. Hypothesis and investigation plan creation module 106. Closed-loop query generation module 107. SIEM query execution module 25 108. Module for converting query results into evidence 109. Evidence sufficiency / contradiction assessment module 110. Asset enrichment module 111. External threat intelligence enrichment module 112. Kill chain stage transition module 30 113. Decision and supporting evidence matching module Version 114 and transaction history logging module. 115. Replay manifest creation module 116. Remote command and question-and-answer interface. 117. Replay module 35 118. Difference report / final output module 7 Detailed Description of the Invention This detailed explanation describes how the invention relates to data obtained from various data sources in cybersecurity environments. autonomous analysis for collecting, analyzing and evaluating event data system (100) and method are only examples to better understand the subject and no 5 It is described in a way that will not create a limiting effect. The subject of the invention is an autonomous analysis system (100) that analyzes cybersecurity incidents that are dependent on human intervention. It is a method and system designed to enable end-to-end examination without any issues; the event The collection of data from diverse and distributed sources, and the standardization of this data into structured evidence. 10 transforming the objects into data, dynamically generating new interrogations based on the evidence obtained, the decision is made by iteratively evaluating the evidence and the entire investigation process is streamlined. recorded along with the information and repeated under the same conditions if necessary. It refers to an integrated and modular architecture that provides this functionality. Autonomous analysis system (100) analyzes heterogeneous datasets from different security components. Not only to analyze, but also to create your own query based on the information needs that arise during the analysis. determining the course of action, directly linking the evidence obtained to the decision-making process, and this relationship It is structured in a way that stores information in a traceable and verifiable manner. The system closes the investigation process. By continuing with a cyclical logic, each evaluation result will determine the next step. by using it in this way, and thus gradually increasing the accuracy and confidence level of event analysis. It increases. In Figure 1, the general architecture of the autonomous analysis system (100), its components and these components are shown. The data flow between them is shown. Event / alarm reception module (101) included in the autonomous analysis system (100), autonomous analysis 25 It serves as the (100) entry point of the system and receives from different security sources. It initiates the investigation process by receiving alarm and event logs. This module is compatible with SIEM systems and EDR systems. solutions, network security devices, authentication systems or other security data By collecting events from various sources, it compiles basic information such as timestamp, source information, and event type. It converts the data, along with its attributes, into a standard input format, enabling 30 different systems to receive data from various sources. It enables heterogeneous data to be processed together. Also, the event / alarm reception module (101), by enabling preliminary level correlation of simultaneous or related events, thus broader understanding of the event. It contributes to considering it within a context. The first evidence collection module (102) collects the first 35 incidents related to the incident received by the incident / alarm reception module (101). responsible for collecting the dataset, the basic characteristics of the event, the relevant log records, and the beginning It brings together contextual information at the level. The first evidence gathering module (102) only collects raw data. 8 It not only collects data but also makes initial data calls from relevant systems depending on the nature of the event. It identifies critical data points that will form the basis of the analysis and establishes first-level relationships between these data points. By establishing this, it creates the preliminary context that will be used in later stages of the investigation process. Thus autonomous analysis system (100), extracting the event from the raw data level in the first stage 5. This data set should be prepared for interpretation and provide a suitable starting point for subsequent analysis modules. It ensures the preparation of the set. The collected data are processed by the evidence object creation module (103) and each is converted into a standard object. It is converted into an evidence object. The evidence object creation module (103) creates a source for each piece of data. Identifier, acquisition time, raw data summary or hash value, normalized fields, and conversion 10 It creates a structured data structure that includes information such as history. Thus, data obtained from different sources... The heterogeneous data obtained are represented in a common format, making them available for joint analysis. Furthermore, a meaningful database is created for further analysis steps. Also, an object of evidence. The creation module (103) establishes event, entity, or transaction-based relationships among the generated evidence. It forms the basis of the relational data structure to be used in the review process. 15 Evidence integrity verification module (104) for the purpose of preserving the reliability of evidence objects It then uses a hash or similar digital trace to verify the integrity of each piece of evidence. It guarantees that the data has not been altered by using its mechanisms. However, the integrity of the evidence... The verification module (104) verifies evidence by tracking the source, acquisition time and conversion steps of each piece of evidence. It ensures the preservation of the chain of evidence (provenance) and thus an autonomous analysis system of evidence (100) It becomes possible to trace the processing steps involved in obtaining it retrospectively. Therefore, not only the integrity of the data but also the data process on which the decision is based is considered. Reliability and auditability are also ensured. The hypothesis and investigation plan creation module (105) involves developing a hypothesis and investigation plan based on the available evidence regarding the incident. or generates more hypotheses and determines the steps to be followed in the investigation process. Hypothesis and The investigation plan creation module (105) analyzes the pieces of information contained in the evidence obtained. It evaluates the possible causes of the incident, related assets, and potential threat scenarios, and It formulates alternative hypotheses that need to be tested accordingly. Furthermore, it identifies which hypotheses are among the 30. By determining what type of data is needed for verification, the investigation plan is dynamically designed. It forms a hypothesis and provides a decision framework that guides the subsequent steps of the system. Investigation plan creation module (105), hypotheses set in line with new evidence obtained By updating it, it enables the review process to progress in an iterative and adaptive manner. 35 In this regard, the closed-loop query generation module (106) uses the available evidence and hypotheses. It generates new queries at its core, and these queries are designed to lead to a better understanding of the event. 9 It enables the creation of contextually sensitive, dynamic queries. Queries are tied to a specific template. without further ado, the data fields, time intervals, entity relationships and suspects indicated by the available evidence It is created by taking into account the indicators. In this way, the autonomous analysis system (100) is created for each event. by following a differentiated inquiry path, the analysis process is made independent of static rules. It can be shaped. 5 The generated queries are executed on the relevant data sources via the SIEM query execution module (107) and The results obtained are converted into evidence objects again by the query result evidence conversion module (108). It is converted into the format and included back into the autonomous analysis system (100). During this conversion process The interrogation outputs are normalized and integrated into the existing evidence structure, and the source is compared with previous evidence, 10 Time, entity, or process-based relationships are established and organized within a relational structure. Thus, the autonomous analysis system (100) not only obtains new data but also processes each new query This makes the result a component that is integrated into the existing network of evidence and influences the flow of analysis. In this context, each new piece of evidence must be examined to determine which interrogation resulted in its production and which previous pieces of evidence it relates to. This is evaluated along with the information on which it is based and which hypothesis it supports or refutes, and this Relationships are recorded within the autonomous analysis system (100). This new information obtained is used to formulate the hypothesis. and the existing hypotheses are re-evaluated by the investigation plan creation module (105) The analysis involves updating, formulating new hypotheses, or eliminating some hypotheses. It provides feedback to the process. Thanks to this feedback mechanism, the autonomous analysis system 20 (100) not only increases the amount of data in each iteration, but also improves the quality of information. By increasing [the effectiveness of the system], it creates the necessary conditions for more accurate decision-making. Thanks to this closed-loop structure, the autonomous analysis system (100) acquires new information in each iteration. It dynamically updates the direction of the investigation and the analysis strategy according to the results obtained. It adapts and gradually matures the decision-making process. This enables autonomous analysis. The system (100), unlike static analysis methods, adapts itself according to the evolving context of the event. By continuously updating it, it aims to reach a more accurate, reliable, and evidence-based conclusion. At this point, the autonomous analysis system (100), the evidence sufficiency / contradiction assessment module (109) and 30 It assesses whether the evidence obtained is sufficient and consistent with each other. Evidence sufficiency / contradiction assessment module during evaluation (109); available evidence criteria such as number, variety, reliability, and degree to which they support or refute a particular hypothesis It determines the sufficiency of evidence by taking these factors into consideration. It also identifies contradictions and inconsistencies among different pieces of evidence. By identifying data or points of lack of information, the areas in which the investigation process should be deepened are determined. 35 It is shown that it is necessary. In this way, the autonomous analysis system (100) is not only based on the amount of data, but also on the results obtained. It conducts an evaluation based on the accuracy and consistency of the information received. If the evidence is insufficient or contradictory, the autonomous analysis system (100) repeats the closed-loop query. Returning to the production module (106), it generates new queries and continues the inspection cycle. This return The feedback is based on identified missing or contradictory data points, rather than a random query process. It is directed in such a way as to focus and thus the autonomous analysis system (100) fills the information gaps. It generates questions that will fill in the gaps or resolve contradictions. Thanks to this approach, the analysis process is 5 It is deepened in a systematic and goal-oriented manner. Thanks to this closed-loop structure, the autonomous analysis system (100) can perform multiple analyses on the same event. By performing iterations, we not only collect more data, but also the obtained It improves the quality of evidence and the accuracy of the decision. New evidence obtained in each iteration enhances the existing 10 It creates an effect that strengthens, weakens, or changes the hypotheses, and this effect influences the reliability of the final decision. It enables the level to increase gradually. Thus, the autonomous analysis system (100) analyzes The process is not seen as a static flow, but rather as one that constantly updates itself according to the quality of the information obtained, and It operates within a structure that fosters maturity. In order to make the analysis process more comprehensive, the asset enrichment module (110) and External threat intelligence enrichment module (111) is activated. Asset enrichment module (110) is responsible for collecting additional information about systems, users or entities associated with the incident; the location of the relevant entities on the network, ownership information, behavioral history, and other related entities. It obtains information such as existing connections and includes it in the current set of evidence. Asset enrichment 20 module (110) records the event not only as a singular record but also in the associated system and user context. It allows for evaluation within that context. External threat intelligence enrichment module (111) is the threat intelligence obtained from external sources. It enriches existing evidence with intelligence data. In this context, known malicious IP addresses, domain 25 names, file signatures, indicators of compromise, and similar threat data. Using this method, the relationship of the event to known threat patterns is evaluated. This enrichment process is only performed for this purpose. It is not limited to adding data, but also ensures that existing evidence is interpreted within the context of the threat. and is used to determine which evidence is critical. In this way, the context of the event is not limited only to the data within the autonomous analysis system (100) This is expanded, and a multidimensional analysis becomes possible. This expanded context provides both By directly influencing both the hypothesis evaluation process and the decision-making mechanism, it leads to more accurate and It contributes to the production of reliable results. 35 Kill chain phase transition module (112) determines the position of the event within the cyberattack lifecycle. It directs the analysis process by determining the Kill Chain Stage Transition Module (112), the evidence obtained and 11 Based on the enrichment results, it determines which stage of the attack the incident is in. and, if necessary, directs the analysis process to the next stage. Thus, autonomous analysis. The system (100) not only analyzes the current situation, but also the possible scenarios in which the event may progress. By taking these stages into account, we can conduct a proactive assessment and review process. It can adapt to the evolving dynamics of the threat. 5 Decision and supporting evidence matching module (113) is created by autonomous analysis system (100). It forms the structure that links the final decision with the evidence supporting or refuting that decision. The decision. and supporting evidence matching module (113) only establishes a simple relationship between the decision and the evidence. not only that, but each decision depends on which objects of evidence, which data were derived from which interrogation outputs, and 10 a structured approach that details which interim assessment steps it is based on It creates a decision-evidence matching model. This model enables the entire data chain on which the decision is based. It becomes transparent, traceable, and technically verifiable. Also, the decision and supporting evidence are matched. Module (113) records supporting evidence as well as refuting evidence that contradicts the decision. This ensures that the decision is evaluated in a more transparent and balanced manner. 15 The version and transaction history log module (114) records the queries used during the review process. It enables the recording of model versions, rule sets, and all process steps. This The records show not only the sequence of operations, but also which inputs were used to perform each step, and which inputs were used. The outputs produced are stored, including which evidence or hypotheses they are associated with. 20 Thus, the autonomous analysis system (100) can track the entire review process retrospectively. and makes it reproducible. In addition, the version and operation history logging module (114) is different This allows for the comparison of analyses performed at different times or under different system conditions. It also manages version information in a way that allows for recognition. Thanks to this comprehensive record structure, the review... so that the process can be reviewed again later, independently audited, and the same analysis 25 This makes it possible to verify the steps by running them again on the same dataset. Replay manifest creation module (115), evidence, queries, version used in the investigation process. It creates a manifest structure that includes information and execution steps. This manifest structure includes each piece of evidence. object ID, relevant query sets, used model, rule and parameter versions, execution 30 It is structured to include the sequence and the chain of operations followed during the analysis. Thus, it not only Not only the analysis output but also the entire technical context regarding how that output was reached is recorded, and This makes it possible to repeat the same analysis later under the same conditions. Remote command and question-answer interface (116), autonomous analysis system (100) with external systems 35 by enabling interaction, users can send commands related to the analysis process or It allows the request for information. Through the remote command and question-answer interface (116) 12 Users can request a rerun of a specific review and query interim results. or it can obtain information regarding evidence and decision structures generated by the system. Thus, it can become autonomous. The analysis system (100) not only works autonomously but also interacts with the user when necessary. It offers a flexible architecture that can work interactively. Replay module (117) uses the generated manifest structure as before Replays the performed analysis under the same conditions. (117) analyzed using recorded query sets, evidence IDs and version information. It repeats the process step by step and compares the results obtained with the previous analysis outputs. This makes them comparable. This allows not only the reproduction of results but also 10 This ensures that the analysis process is repeated in a deterministic and verifiable manner. Finally, the difference report / final output module (118), the analysis rerun with the current analysis. It reveals the differences between them and reports the final results. Difference report / final output module (118), 15 in terms of factors such as decisions made, evidence used, interrogation results and confidence levels. It identifies any differences that may exist between the two analyses and compiles these differences into a systematic report. It presents it in this format. Thus, the autonomous analysis system (100) not only produces a decision, but also... a comparative analysis that can reveal how the decision has changed over time or under different circumstances It also provides analytical skills. The autonomous analysis method begins with the reception of an event by the event / alarm reception module (101). Then The first evidence gathering module (102) collects the initial data relating to the incident and the evidence object creation module (103) This data makes standard evidence. The evidence integrity verification module (104) makes these pieces of evidence standard evidence. It confirms its reliability and ensures the integrity of the chain of evidence. Formulating a hypothesis and investigation plan. module (105), one or more hypotheses based on available information and a related investigation plan 25 It creates and the closed-loop query generation module (106) generates the necessary queries in accordance with this plan. Queries are performed on specific data fields over time to confirm or refute the hypotheses that have been formed. It is structured to focus on ranges and related assets. The SIEM query execution module (107) runs the generated queries on the relevant data sources and the resulting 30 The results are converted back into evidence by the query result evidence conversion module (108). It is included in the autonomous analysis system (100). The query outputs obtained in this process are normalized. It is integrated into the existing evidence structure and linked to previous evidence during the analysis process. The integrity of the relational data to be used is preserved. Thus, the autonomous analysis system (100) can perform each query The result should be considered not only as a new piece of data, but also as something that influences existing hypotheses and warrants review. 35 It is considered an evidentiary element that can alter the course of the process. 13 Thanks to this mechanism, the autonomous analysis system (100) can initially obtain a limited data set. the analysis process initiated from the above, adding new evidence in each iteration and combining this evidence with the existing It expands by relating it to the information structure. Thus, the autonomous analysis system (100) is static and one-time. Unlike an analytical approach, query generation and data are based on the results obtained. an adaptive and self-directed review process that constantly updates the collection strategy 5 It accomplishes. The evidence obtained in this process includes asset enrichment module (110) and external threat intelligence. It can be contextually enriched through the enrichment module (111) and the kill chain stage The transition module (112) determines the position of the event in the attack lifecycle and analyzes it. 10 is directed. The additional information obtained as a result of these enrichment processes is only provided as evidence for existing use. not only are the details added to the evidence set, but the importance of the evidence is determined, prioritized, and Actively participate in the evaluation process in order to more clearly reveal the relationships with the hypotheses. It is included as such. Thus, the autonomous analysis system (100) expands the context of the event while at the same time It can identify critical information elements that influence the decision-making process over time. 15 All evidence obtained is evaluated by the evidence sufficiency / contradiction assessment module (109). The evidence is evaluated, and if it is found to be insufficient or inconsistent, the process is repeated in a closed loop. New queries are generated by directing to the query generation module (106). During this evaluation The reliability and diversity of the evidence, the degree to which it supports or refutes hypotheses, and the 20 factors between them. Consistency relationships are taken into account. Additionally, any identified areas of missing information or contradictory data points are considered. The next query will be addressed in a targeted manner in the production step, providing feedback to the analysis process. provides. In this way, the autonomous analysis system (100) performs an iterative analysis cycle until sufficient evidence is provided. 25 It works within and adjusts the analysis strategy based on new evidence obtained in each iteration. It updates dynamically. This cycle is not only for the purpose of collecting more data, but also for the purpose of gathering existing information. It is guided by the goal of improving its structure, resolving contradictions, and increasing decision accuracy. Thus, the autonomous analysis system (100) uses a fixed and single-step inspection approach instead of the obtained It carries out an analysis process that constantly evolves and matures according to the nature of the information. 30 When sufficient and consistent evidence is obtained, the final decision is made through the supporting evidence matching module (113). A decision is made and this decision is correlated with supporting and corroborating evidence. At this stage... The decision should not be considered merely as a summary of the outcome, but also in terms of the degree to which each piece of evidence contributes to the decision, and the hypotheses involved. 35 (Support or refutation situation and evaluation steps that are effective in decision-making) It is represented in a structured way together. Thus, the autonomous analysis system (100) represents the decision made. It presents not only the result but also how that result was reached in a clear and traceable way. 14 All steps of the review process, the queries used, the datasets, and version information are included in the version and process. The history is recorded by the logging module (114). These records show which step of each process This will include how it was performed with the inputs, what outputs it produced, and what evidence it is related to. This is done in detail. Thus, the analysis process is not only results-oriented but also process-oriented. It also becomes traceable. This process is represented by the replay manifest generation module (115). A manifest structure is created, and this structure includes all the components used in the review process. The parameters are configured to include query sets and evidence references. The manifest created in this way not only stores the analysis results but also includes the same review a comprehensive 10 that makes it possible to repeat the process step by step under the same conditions It creates a reference set and verifies the decision-making process of the autonomous analysis system (100). and becomes a key component supporting its auditability. If needed, the replay module (117) uses the generated manifest structure. Run the analysis again under the same conditions and the difference report / final output module (118) again 15 It produces the final output by revealing the differences between the results of the current analysis and the results of previous analyses. During the replay process, the module retrieves the recorded evidence references, query sets, and transactions. By using the steps and version information, it repeats the analysis process step by step, and thus... This process ensures that the analysis outputs can be consistently reproduced under the same conditions. Furthermore, this process... The interim results obtained during this process became comparable to the interim results obtained in the previous analysis. 20 by identifying differences not only at the final decision level but at every stage of the analysis process. It is made possible to do so. Difference report / final output module (118), decision, evidence set, query as a result of the comparison in question. It systematically analyzes the differences that arise based on the outputs and evaluation steps, and these 25 It reports the differences. Thus, the autonomous analysis system (100) can determine whether a particular decision changes over time. that it hasn't changed, how it's affected under different data conditions, or at which steps of the analysis process This can reveal that divisions have occurred. In this way, the autonomous analysis method not only produces a decision, but also analyzes that decision in 30 steps. Closed-loop system that also ensures verifiability, traceability and reproducibility. It offers a verifiable review process. In addition, the autonomous analysis system (100) provides all the basis on which the decision is based. By enabling the retrospective examination of the data and transaction chain, the technical analysis results... This allows it to be explained and independently verified. 35
Claims
REQUESTS 1. Event data obtained from different data sources in cybersecurity environments Autonomous analysis system for collecting, analyzing and evaluating (100) and its feature is; 5 - the process of reviewing alarm and incident logs from different security sources initiating event / alarm receiving module (101), - the first evidence gathering module that collects the first data set related to the incident received (102), - a module for creating evidence objects that converts collected data into standard evidence objects. (103), 10 - evidence integrity verification module (104) which verifies the integrity of the evidence created. - by generating one or more hypotheses about the event based on the available evidence hypothesis and investigation plan creation module (105), - a closed-loop system that generates new inquiries based on existing evidence and hypotheses. query generation module (106), 15 - SIEM query execution module (107) which runs the mentioned queries on the relevant data sources, - query result evidence, which converts query results back into evidence object format. conversion module (108), - by evaluating whether the evidence obtained is sufficient or contradictory, the necessary action is taken. Evidence sufficiency / contradiction assessment module 20, which enables the generation of a new inquiry in this situation. (109), - the final decision and the basis for that decision, relating the evidence supporting or refuting it. evidence matching module (113), - queries, model versions, rule sets, and processes used in the review process Version and transaction history log module (114), which keeps a record of the steps, 25 - evidence, interrogations, release information, and execution steps used in the investigation process replay manifest creation module (115) which creates a manifest structure containing a manifest structure, - replay / re-running the review using the generated manifest structure execution module (117), - Difference report, which reports the differences between the current analysis and the re-run analysis / 30 The final output module (118) is included.
2. Autonomous analysis system (100) in accordance with Request 1, its feature is; event / alarm reception module (101), event data from different security data sources, timestamp, source It should include a standard input format containing information and the type of event.
3. The autonomous analysis system (100) compliant with Claim 1, its feature is; the first evidence collection module (102) 35 the basic characteristics of the event, relevant log records, and basic contextual information. 16 by bringing them together and making additional data calls from relevant systems depending on the nature of the event. It includes critical data points that it identifies to form the basis for the initial analysis.
4. The autonomous analysis system (100) in accordance with claim 1, its feature is; creating evidence object. the module (103) creates a source identifier, acquisition time, raw for each piece of data. 5 data summary or hash value, normalized fields and conversion history It contains a structured object of evidence.
5. Autonomous analysis system (100) conforming to claim 1, its feature is; event related systems, an entity that expands the existing set of evidence by gathering additional information about users or entities It includes the enrichment module (110).
6. The autonomous analysis system (100) conforming to claim 1, its feature is; 10 obtained from external sources. Threat intelligence data enriches existing evidence and identifies known malicious IP addresses and domains. using names, file signatures, or attack indicators, the incident is associated with known threat patterns. It includes an external threat intelligence enrichment module (111) which evaluates the relationship.
7. The autonomous analysis system (100) in accordance with Claim 1, its feature is; the evidence obtained and Based on the enrichment results, the event falls within the 15th stage of the cyberattack lifecycle. determining its position and, if necessary, directing the analysis process to the next stage. It contains the kill chain phase transition module (112).
8. The autonomous analysis system (100) compliant with claim 1, its feature is; version and operation history recording. Which inputs are used to perform each step of the module (114), and which outputs are used? It includes a record of what it produced and to which evidence or hypotheses it is associated. 20 9. The autonomous analysis system (100) compliant with claim 1, its feature is; generating replay manifest. The module (115) identifies each evidence object, the relevant query sets, the model used, rule and parameter versions, execution order, and the process chain followed during analysis It includes a manifest structure that encompasses everything.
10. Autonomous analysis system (100) in accordance with claim 1, whose feature is that users can use a certain 25 to request that the investigation be rerun, to question interim results, or enabling the system to obtain information regarding the evidence and decision structures created by the system. It includes a remote command and question-answer interface (116).
11. Autonomous analysis system (100) in accordance with claim 1, its feature is; difference report / final output module (118) decisions, evidence sets, interrogation results, confidence levels or 30 There is a difference between the current analysis and the re-conducted analysis in terms of evaluation steps. It includes a report format that systematically presents the differences it has made.
12. The autonomous analysis system (100) conforming to claim 1 is characterized by its hypothesis and investigation plan. creation module (105), closed-loop query generation module (106), SIEM query execution module (107), module for converting query result into evidence (108) and evidence sufficiency / contradiction 35 the evaluation module (109) working together until sufficient evidence is provided It involves an iterative analysis cycle that it creates. 17 13. Analysis of event data obtained from different data sources in cybersecurity environments. It is an autonomous analysis method aimed at..., and its characteristic is; - the acquisition of an event, the collection of the initial data set related to the acquired event, - converting the mentioned data into standard evidentiary objects, - verification of the integrity of the evidence gathered, 5 - to formulate at least one hypothesis and a related investigation plan based on the available evidence, - generating at least one query based on the hypotheses formulated, - running the generated query on the relevant data sources, - by transforming the obtained interrogation results into new pieces of evidence, the existing evidence inclusion in its structure, 10 - evaluating the sufficiency and consistency of the evidence obtained, - If the evidence is found to be insufficient or contradictory, new interrogations will be conducted to continue the process. repetition, - steps for making a final decision if sufficient evidence is obtained It includes. 15 14. This is an autonomous analysis method compliant with claim 13, characterized by its different event acquisition steps. Timestamp, source information, and event type of events from security data sources. This includes the process of converting the input into a standard input format.
15. This is an autonomous analysis method compliant with claim 13, characterized by the collection of the initial dataset. In the next step, log records and contextual information related to the event are gathered and the event is analyzed on the 20th. Depending on its nature, it includes the step of making additional data calls.
16. This is an autonomous analysis method in accordance with Claim 13, characterized by its ability to transform evidence into a verifiable object. In this step, for each piece of data, the source identifier, acquisition time, raw data summary or hash is obtained. the creation of a structure that includes the value, normalized fields and transformation history, and Establishing relationships based on events, entities, or transactions among the evidence gathered is process 25 It includes the steps.
17. This is an autonomous analysis method compliant with Claim 13, characterized by its verification of the integrity of the evidence. in this step the immutability of the evidence is ensured by using hash or similar digital trace mechanisms This involves checking and tracing the chain of evidence.
18. This is an autonomous analysis method compliant with claim 13, and its characteristic feature is that it has 30 available steps in the hypothesis formulation phase. Generating multiple hypotheses about the possible causes of the event based on the evidence, and these Determining the data needs required to verify the hypotheses are the process steps. It includes.
19. This is an autonomous analysis method compliant with claim 13, and its characteristic feature is that it is available in the query generation step. Data fields, time intervals, entity relationships, and suspicious indicators pointed to by the evidence 35 This involves creating at least one query, taking this into consideration. 18 20. This is an autonomous analysis method compliant with claim 13, characterized by its ability to execute queries and analyze the results as evidence. In the conversion step, the query outputs obtained are normalized and integrated into the existing evidence structure. The process involves integrating and correlating the evidence with previous records.
21. This is an autonomous analysis method in accordance with Claim 13, characterized by its ability to analyze the available evidence. Re-evaluation and analysis based on whether the hypotheses are supported or refuted. 5 Updating the process accordingly includes the necessary steps.
22. This is an autonomous analysis method in accordance with Claim 13, characterized by its sufficiency of evidence and contradiction. the number, variety, reliability of evidence and support for hypotheses in the evaluation step The process of analyzing data according to its degree and identifying missing or contradictory data. It includes the steps. 10 23. This is an autonomous analysis method in accordance with Claim 13, characterized by the fact that the evidence is insufficient or contradictory. If found, the process involves repeating the steps by generating new queries.
24. This is an autonomous analysis method in accordance with Claim 13, characterized by its use of factual information and data from the evidence obtained. This includes the step of enriching the process with external threat intelligence data.
25. This is an autonomous analysis method compliant with Claim 13, characterized by its ability to analyze the cyberattack lifecycle of the event. the process of determining its position within the system and directing the analysis process accordingly. It includes the steps.
26. This is an autonomous analysis method in accordance with Claim 13, characterized by the fact that, if sufficient evidence is obtained... The process step involves correlating the established decision with supporting and corroborating evidence. It includes. 20 27. This is an autonomous analysis method compliant with Claim 13, characterized by the use of a specific method in the investigation process. logging of queries, datasets, model and rule versions, and process stages It includes the acquisition process step.
28. This is an autonomous analysis method in accordance with Claim 13, and its characteristic feature is that it is used in the investigation process. a manifest structure containing evidence, inquiries, release information, and execution steps 25 It includes the creation process step.
29. This is an autonomous analysis method compliant with Claim 13, characterized by the use of the generated manifest. This involves repeating the analysis process under the same conditions.
30. This is an autonomous analysis method compliant with Claim 13, characterized by its ability to re-execute the previous analysis. Analysis of differences between analysis results based on decision, evidence set and interrogation outputs 30 This includes the process step of reporting the findings.