Threat intelligence reports generation using artificial intelligence techniques
Patent Information
- Application Number
- PCT/US2025/032615
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-25
- Filing Date
- 2025-06-06
- Publication Date
- 2026-10-01
Smart Images

Figure US2025032615_01102026_PF_FP_ABST
Abstract
Description
THREAT INTELLIGENCE REPORTS GENERATION USING ARTIFICIAL INTELLIGENCE TECHNIQUESCROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This application claims priority to Indian non-provisional patent application-202511028023, filed on March 25, 2025, the entire contents of which are incorporated herein by reference.FIELD
[0002] The present disclosure relates to threat intelligence reports generation using Artificial Intelligence (Al) and Machine Learning (ML) techniques.BACKGROUND
[0003] The information disclosed in this background section is only for an enhancement of understanding of the general background of the disclosure and should not be taken as an acknowledgement or any form of suggestion that this information forms the prior art already known to a person skilled in the art.
[0004] Threat intelligence (TI) is a critical component of an organization’s cybersecurity framework, enabling proactive identification and mitigation of cyber threats. A TI Analyst, which is usually human personnel, plays a crucial role in this process, by manually collecting, analyzing, and disseminating threat-related information from multiple sources of data. Primary sources for such data may include really simple syndication (RSS) feeds, security blogs, news websites, and specialized threat intelligence portals. However, the existing manual approachi.e., involving human personnel processing and distributing threat intelligence presents significant technical challenges that hinder efficiency, accuracy, and scalability.
[0005] Traditional T1 gathering relies on manual analysis, leading to delays, errors, and inconsistencies in threat assessment. Human analysts struggle to process vast amounts of unstructured data, often misinterpreting threat attributes or overlooking critical indicators. As cyber threats grow in volume and complexity’, manual approaches become unsustainable, limiting scalability and creating bottlenecks. Inconsistent interpretations and subjective assessments further reduce the reliability of TI reports. Additionally, the process is resourceintensive. leading to analyst fatigue and inefficient use of skilled cybersecurity professionals. Such limitations hinder real-time threat detection, leaving organizations vulnerable to evolving cyber risks.
[0006] To address the aforementioned issues, there is a requirement to design a technologically advanced, automated system and method which streamlines the generation of threat intelligence.SUMMARY
[0007] This summary is provided to introduce a selection of concepts, in a simplified format, that are further described in the detailed description of the disclosure. This summary is neither intended to identify key or essential inventive concepts of the present disclosure nor is it intended to determine the scope of the disclosure.
[0008] According to one embodiment of the present disclosure, a method is disclosed. The method includes obtaining threat-related information from at least one data source using data retrieval techniques. Further, the method includes correlating a set of threat attributes in theobtained threat-related information with one or more asset elements. The one or more asset elements indicate uniquely identifiable entities within an organization and are retrieved from an asset management platform. The set of threat attnbutes indicates features having syntax patterns, semantic relationships, entity correlations, and statistical anomalies associated with cybersecurity threats. Furthermore, the method includes determining a relevancy score based on the correlation. The relevancy score indicates an impact of the set of threat attributes on the one or more asset elements. Furthermore, the method includes triggering a real-time notification in response to the relevancy score exceeding a predefined threshold. Furthermore, the method includes generating a threat intelligence report based on the correlation and the set of threat attributes. The threat intelligence report indicates an assessment of the cybersecurity threats from the set of threat attributes and an impact on the correlated one or more asset elements.
[0009] According to one embodiment of the present disclosure, a system is disclosed. The system is configured to obtain threat-related information from at least one data source using data retrieval techniques. Further, the system is configured to correlate a set of threat attributes in the obtained threat-related information with one or more asset elements. The one or more asset elements indicate uniquely identifiable entities within an organization which are retrieved from an asset management platfonn. The set of threat attributes indicates features may include syntax patterns, semantic relationships, entity correlations, and statistical anomalies associated with cybersecurity threats. Furthermore, the system is configured to detennine a relevancy score based on the correlation. The relevancy score indicates an impact of the set of threat attributes on the one or more asset elements. Furthermore, the system is configured to trigger a real-time notification in response to the relevancy score exceeding a predefined threshold. Furthermore, the system is configured to generate a threat intelligence report based on the correlation and theset of threat attributes. The threat intelligence report indicates an assessment of the cybersecurity threats from the set of threat attributes and an impact on the correlated one or more asset elements.
[0010] According to another embodiment of the present disclosure, a non-transitory computer-readable medium storing instructions is disclosed. The non-transitory computer-readable medium comprises one or more instructions that, when executed by one or more processors, cause the one or more processors to obtain threat-related information from at least one data source using data retrieval techniques. Further, the one or more processors are configured to correlate a set of threat attributes in the obtained threat-related information with one or more asset elements. The one or more asset elements indicate uniquely identifiable entities within an organization which are retrieved from an asset management platform. The set of threat attributes indicates features having syntax patterns, semantic relationships, entity correlations, and statistical anomalies associated with the cybersecurity threats. Furthermore, the one or more processors are configured to determine a relevancy score based on the correlation. The relevancy score indicates an impact of the set of threat attributes of the one or more asset elements. Furthennore, the one or more processors are configured to trigger a real-time notification in response to the relevancy score exceeding a predefined threshold. Further, the one or more processors are configured to generate a threat intelligence report based on the correlation and the set of threat attributes. The threat intelligence report indicates an assessment of the cybersecurity threats from the identified set of threat attributes and an impact on the correlated one or more asset elements.
[0011] To further clarity7the advantages and features of the present disclosure, a more particular description of the disclosure will be rendered by reference to specific embodiments thereof,which is illustrated in the appended drawing. It is appreciated that these drawings depict only typical embodiments of the disclosure and are therefore not to be considered limiting its scope. The disclosure will be described and explained with additional specificity and detail with the accompanying drawings.BRIEF DESCRIPTION OF DRAWINGS
[0012] Features, aspects, and advantages of certain exemplary embodiments of the disclosure will be described below with reference to the accompanying drawings, in which like reference numerals denote like elements, and wherein:
[0013] FIG. 1 illustrates an example of an implementation environment in which systems and / or methods may be implemented, in accordance with one embodiment of the present disclosure;
[0014] FIG.2 illustrates an example architecture of a system for generating a threat intelligence report, in accordance with one embodiment of the present disclosure;
[0015] FIG. 3 illustrates an example scenario of the system for obtaining threat-related information and disseminating a threat intelligence report, in accordance with one embodiment of the present disclosure;
[0016] FIG. 4 illustrates an example embodiment of an example device, in accordance with one embodiment of the present disclosure;
[0017] FIG.5 illustrates a flow' chart of an example method for generating a threat intelligence report, in accordance w ith one embodiment of the present disclosure;
[0018] FIG. 6 illustrates a method-step for obtaining the threat-related information, in accordance w ith one embodiment of the present disclosure;
[0019] FIG. 7 illustrates a method-step for identifying the set of threat attributes, in accordance with one embodiment of the present disclosure; and
[0020] FIG.8 illustrates a method-step for determining the relevancy score, in accordance with one embodiment of the present disclosure.DETAILED DESCRIPTION
[0021] The following detailed description of example embodiments refers to the accompanying drawings. The present disclosure provides illustrations and descriptions, but is not intended to be exhaustive or to limit the implementations to the precise form disclosed. Modifications and variations are possible in light of the present disclosure or may be acquired from practice of the implementations. Further, one or more features or components of one embodiment may be incorporated into or combined with another embodiment (or one or more features of another embodiment). Additionally, the flow chart and description of operations provided below relate to at least one of the embodiments in the present disclosure. It should be noted that it is possible to make other embodiments that do not exactly match the flowchart and its description. It is understood that in other embodiments one or more operations may be omitted, one or more operations may be added, one or more operations may be performed simultaneously (at least in part).
[0022] It will be apparent that systems and / or methods described herein may be implemented in different forms of hardware, software, or a combination of hardware and software. The actual specialized control hardware or software code used to implement these systems and / or methods should not limit their implementations. Thus, the operation and behavior of the systems and / or methods are described herein without reference to specific software code. It is understood thatsoftware and hardware may be designed to implement the systems and / or methods based on the description herein.
[0023] Even though particular combinations of features are recited in the claims and / or disclosed in the specification, the particular combinations are not intended to limit the disclosure of implementations. In fact, many of these features may be combined in ways not specifically recited in the claims and / or disclosed in the specification. Even if a dependent claim directly depends on only one claim, the present disclosure may indicate that the dependent claim is dependent on other claims in the claim set.
[0024] No element, act, or instruction used herein should be construed as critical or essential unless explicitly described as such. Also, as used herein, the articles ’ a" and "an" (in other words, nouns not mentioned in the plural) are intended to include one or more items and may be used interchangeably with “one or more.” Also, as used herein, the terms “has,” “have,” “having,” “include,” “including,” or the like are intended to be open-ended terms. Further, the phrase “based on” is intended to mean “based, at least in part, on” unless explicitly stated otherwise. Furthermore, expressions such as “at least one of [A] and [B],” “[A] and / or [B],” or “at least one of [A] or [B]” are to be understood as including only A, only B, or both A and B.
[0025] In the present disclosure, specific tasks may be perfonned using AI / ML (Artificial Intelligence / Machine Learning) models. An AI / ML model is a model generated using one or more Al technologies, one or more ML algorithm or both, and generates output data based on input data. This output data is used to perform tasks. Tasks performed using AI / ML models include those generally referred to as intellectual tasks, such as classification, prediction, natural language processing, etc.
[0026] Although Al and ML are explained separately, ML is a technology included in Al. In ML, instead of being explicitly programmed for a specific task, systems can improve their performance over time by identifying patterns and making inferences from training data. Typically, the generation of ML models includes data collection, model training, and model inference. Data collection involves gathering and preprocessing data to be used for training and inference. Model training involves developing and validating models using the collected data. Model inference involves applying the trained models to new data to generate new output data and perform tasks.
[0027] Machine learning includes various types of learning methods such as supervised learning, unsupervised learning, reinforcement learning, semi-supervised learning, selfsupervised learning, transductive learning, transfer learning, meta learning, and the like. These types of learning methods can be appropriately selected according to the embodiments. Unless otherwise specified, the application of types not mentioned in this description is not precluded. Additionally, the structure of ML models may vary depending on the embodiments and learning methods, and is not limited to the methods disclosed. Furthermore, ML includes deep learning, which uses models that include neural networks. Deep learning models may include, for example, deep neural networks (DNNs), convolutional neural networks (CNNs), etc.
[0028] It should be noted that the AI / ML models presented hereinafter are examples and are not limited to the illustrated AI / ML models. They can be modified or altered by using different Al or ML algorithms. The configuration of the neural network is not limited to the configuration disclosed in the present disclosure and can be modified.
[0029] Traditional techniques of threat intelligence (TI) collecting involves human involvement. Specifically, a human analyst may scan through large volumes of cybersecurityarticles, threat reports, and raw data to identify relevant insights. Such a process of manual scanning involves reading, analyzing, extracting key threat attributes, and then summanzing the findings into a structured threat intelligence report. Thus, such conventional manual processes significantly increase a turnaround time, leading to delays in disseminating crucial threat intelligence. Particularly, in an environment with a crucial requirement for real-time threat detection, such delays may leave organizations vulnerable to attacks.
[0030] Further, the human analysts, despite their expertise, are prone to errors when processing large volumes of unstructured threat data. In an example, errors may include misinterpretation of threat attributes, incorrect threat categorization, or missing critical indicators of compromise (loCs). The errors may lead to inaccurate assessments, causing either an overestimation consequently leading to unnecessary panic or underestimation which may result in missed threats of cybersecurity risks. Thus, considering the rapidly evolving nature of the cyber threats, any incorrect or incomplete intelligence may compromise an organization's ability to respond effectively.
[0031] Furthermore, as cyber threats increase in volume and complexity, the manual approach to threat intelligence becomes unsustainable. The human analysts are limited by the number of sources they may be able to process, the number of threats they may track, and the amount of intelligence they may produce within a given time. Specifically, large enterprises dealing with diverse information technology assets and global threat landscapes require scalable solutions that may process massive datasets quickly. However, manual processing does not scale effectively and becomes a bottleneck in handling the growing volume of cybersecurity7threats.
[0032] In a scenario, in the traditional techniques, different human analysts may interpret and summarize threat intelligence differently, leading to inconsistencies in reports. The lack ofstandardized threat correlation in the traditional techniques may result in varying levels of depth and quality in intelligence reports. Such inconsistency makes it difficult for security teams to rely on a single source of truth when assessing and mitigating threats. Additionally, the human analysts with different levels of experience may provide subjective assessments, introducing bias into the threat intelligence process.
[0033] Furthermore, threat intelligence must be processed and disseminated quickly to be actionable. The manual approach often leads to significant delays in identifying and responding to threats. Thus, by the time the human analyst compiles the threat intelligence report and shares it with security teams, the threat may have already evolved or spread. Cyber adversaries operate in real-time, launching attacks that require immediate defensive action. The delay in generating threat intelligence reports reduces the organization's ability to proactively mitigate threats before such threats escalate into incidents.
[0034] Furthermore, the process of collecting, analyzing, and disseminating threat intelligence requires extensive human resources (i. e. , a team of the human analysts). The organizations must allocate skilled human analysts to manually extract and summarize threat data, which is a repetitive and labor-intensive task. This results in inefficient resource utilization, where highly skilled cybersecurity professionals spend a disproportionate amount of time on low-level data processing rather than on higher-value activities such as security' strategy and threat mitigation.
[0035] Consequently, considering the time and effort required for manual processing, the human analysts may not be able to cover all available threat intelligence sources. This creates a coverage gap, where critical threats from overlooked sources remain undetected. The cyber attackers or cyber trolls continuously evolve their tactics, techniques, and procedures (TTPs), often exploiting new vulnerabilities that may not be covered in manually compiled reports.Therefore, organizations rely on partial threat intelligence and consequently risk missing critical indicators that could have helped prevent cyber incidents.
[0036] Furthermore, the repetitive nature of manually processing vast amounts of threat intelligence contributes to the human analysts fatigue and burnout. It is required that cybersecurity professionals must continuously monitor multiple sources, extract meaningful insights, and generate reports within strict timelines. The sheer volume of data to be processed may overwhelm the cybersecurity professionals (i.e.. the human analysts), reducing their efficiency and increasing the likelihood of errors.
[0037] To address the aforementioned issues, there is a requirement to design a technologically advanced, automated system and method which streamlines the collection, correlation, analysis, and dissemination of threat intelligence. Such a system and method must be capable of handling large-scale threat data, reducing processing time, improving accuracy, and providing real-time intelligence updates to security teams.
[0038] FIG. 1 is a diagram of an example of implementation environment 100 in which systems and / or methods, described herein, may be implemented. The implementation environment 100 includes a UE (User equipment) 110, a service environment 120, and a network 130. The service environment 120 includes one or more sub-environments 121. To illustrate this, FIG. 1 shows, for convenience, examples of a 1st sub-environment 121-1, a 2nd sub-environment 121-2, and anN-th sub-environment 121-N (where N is any natural number).
[0039] The UE 110 is connected to the network 130, and the network 130 is connected to the service environment 120. The connections may be wired, wireless, or a combination of both wired and wireless. The UE 110 and the service environment 120 are connected via the network 130.
[0040] The UE 110 is a device that communicates with the service environment 120. The UE 110 receives information from the service environment 120 and / or sends information to the service environment 120. Also, the UE 110 may generate and / or store information to be transmitted, as necessary. Also, the UE 110 may store and / or process information that is received, as necessary.
[0041] The example FIG. 1 refers to the “UE”. However, it should be understood by those skilled in the art that general terms such as “user device,” “terminal.” “terminal device,” “communication device,” and “communication terminal” can be used interchangeably with the term “UE.”
[0042] For example, the UE 110 may include a computing device (e.g., a desktop computer, a laptop computer, a tablet computer, a handheld computer, a smart speaker, a server, etc ), a mobile phone (e.g., a smart phone, a radiotelephone, etc.), a wearable device (e.g., a pair of smart glasses or a smart watch), or a similar device.
[0043] The service environment 120 is an environment that communicates with the UE 110 to provide one or more services. The service environment 120 receives information from the UE 110 and / or sends information to the UE 110. Also, the service environment 120 may generate and / or store information to be transmitted, as necessary'. Also, the service environment 120 may store and / or process information that is received, as necessary'. For example, the sendee environment 120 may provide computing resources as one of the services. It should be noted that the service is not limited to being provided to the UE; it may also be provided to devices other than the UE. For example, based on communication from the UE, the service may perform processes such as anomaly detection or traffic analysis and notify the results to a predetermined destination.
[0044] The example FIG. 1 refers to the '‘service environment”. The term "service environment" is used to refer to the broader context within which services operate. For example, cloud environments, platforms, computing systems, network systems, and cloud systems generally represent the environments in which services are conducted, and these are included within the "service environment." However, the "service environment" is not limited to these examples. Additionally, the specific types of environments within the "service environment" are not restricted. For instance, cloud environments and cloud systems can be categorized as private cloud, public cloud, hybrid cloud, or multi-cloud, all of which are included within the "service environment."
[0045] The one or more sendees provided by the service environment 120 is not specifically limited and can be adjusted according to the embodiments. For example, the services may include a service that provides information to the UE 110, a service that stores information from the UE 110, or a service that performs processing based on information from the UE 110 and returns the results of the processing.
[0046] In an embodiment, the service environment 120 may also provide computing resources as the service. The computing resources can be hardware resources and / or software resources. For example, applications, processors, memory, and storage can be included in the provided computing resources. Each computing resource can communicate with other computing resources via wired connections, wireless connections, or a combination of wired and wireless connections.
[0047] The provided computing resources can be actual resources (also referred to as physical resources) and / or virtual resources. Furthermore, means of virtualization for virtual resources can be selected as appropriate. That is, in this disclosure, the use of adjectives such as "Virtual"or "Virtualized" to describe names does not imply that they are virtualized by a specific means of virtualization. For example, “virtual machine7’ refers to software that operates like an actual computer, realized through means of virtualization, and it is not intended to exclude those realized by specific means of virtualization such as Hypervisors or Containers. Conversely, when means of virtualization such as Hypervisors or containers are mentioned in this disclosure, it is merely cited as a general method of implementation. It should also be interpreted that embodiments implemented with other virtualization means are also disclosed. Also, the services may also be provided using resources virtualized by different means.
[0048] The sendee environment 120 includes one or more devices, such as servers and network devices, which provide services or perform processes. The placement of these devices within the service environment 120 can be determined as appropriate. Additionally, if the service environment 120 includes one or more sub-environments 121, the placement of devices can be determined based on predetermined policies for each sub-environment 121. For example, devices related to the first service may be placed in the 1st sub-environment 121-1, and devices related to the second service may be placed in the 2nd sub-environment 121-2. In another example, devices expected to have a higher load than a predetermined threshold may be placed in the 1st sub-environment 121-1, while devices expected to have a lower load than the predetermined threshold may be placed in the 2nd sub-environment 121-2. In this way, specific devices can be placed in specific sub-environments 121. Conversely, each sub-environment 121 can be specialized for a particular purpose.
[0049] In an embodiment, all processes executed in a single service may run within a single sendee environment, or in multiple service environments. Multiple processes executed in a single service could be provided by different service environments.
[0050] The network 130 is a network that exchanges information between the UE 110 and the service environment 120. The network 130 includes one or more wired and / or wireless networks.
[0051] For example, the network 130 may include a cellular network (e.g., a fifth generation (5G) network, a long-term evolution (LTE) network, a third generation (3G) network, a code division multiple access (CDMA) network, etc.), a public land mobile network (PLMN), a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), a telephone network (e.g., the public switched telephone network (PSTN)), a private network, an ad hoc network, an intranet, the Internet, a fiber optic-based network, or the like, a nonterrestrial network (NTN), and / or a combination of these or other types of networks.
[0052] The network 130 can be a part of a network. For example, in a 5G network that includes a RAN, a transport network, and a core network, the network 130 can be at least one of the RAN, the transport network, or the core network. For example, the service environment 120 could be in the core network, in which case the network 130 could correspond to a network that is a combination of a RAN and a transport network and is part of the 5G network.
[0053] The number and arrangement of devices and networks shown in FIG. 1 is provided as an example. It should be understood that any changes that may be implemented by those skilled in the art, such as the addition or rearrangement of w ell-known devices or networks at the time of implementation, are included in this disclosure.
[0054] In an embodiment, the service environment 120 in the implementation environment 100 as illustrated in FIG. 1, advantageously facilitates automated threat intelligence processing, analysis, and dissemination. The UE 110, which may include in a non-limiting example computing devices such as security operation center (SOC) w orkstations or endpoint securityplatforms, interacts with the service environment 120 over the network 130 to transmit threat data and receive analyzed intelligence. The service environment 120 includes multiple subenvironments 121, which may include distributed cloud-based processing units, machine learning inference engines, and cybersecurity analytics modules. The sub-environments 121 collaboratively perform key functionalities such as obtaining threat-related information, natural language processing (NLP) models based threat detection, risk scoring, and integration with external security systems. Consequently, in an advantageous aspect, based on utilizing computing resources, including virtualized environments and scalable cloud infrastructure within the service environment 120, the cyber threat intelligence operations are performed with enhanced efficiency, accuracy, and scalability. In an advantageous aspect, ensuring real-time detection, classification, and alerting of security threats as explained in detail in the description of FIG. 2 and FIG. 3.
[0055] FIG. 2 illustrates an example architecture of a system 200 for generating a threat intelligence report 208, in accordance with one embodiment of the present disclosure.
[0056] In an embodiment, the system 200 may reside in the service environment 120. The system 200 is configured to obtain threat-related information from a data source 202 using data retrieval techniques. Further, the sy stem 200 is configured to interact with an asset management platfonn 206 and consequently retrieve asset elements from the asset management platfonn. Further, the system is configured to generate the threat intelligence report 208 which may be further transmitted or disseminated the threat intelligence report 208 through distribution channels 210. In a non-limiting example, the distribution channels 210 may include an electronic mail (email), an internal portal, or an online messaging platform. In an advantageousaspect, the threat intelligence report 208 indicates an assessment of the cybersecurity threats and an impact of the cybersecurity threats on the asset elements.
[0057] In an embodiment, the system 200 is configured to obtain the threat-related information from the data source 202 using the data retrieval techniques. In a non-limiting example, the threat-related information may include structured data from various data sources (i.e., the data source 202) such as threat intelligence feeds, vulnerability databases, security information and event management logs, and security advisories. In a non-limiting example, the threat-related information may include unstructured data from various data sources (i.e., the data source 202) such as research papers, blogs, hacker forums, dark web sources, and security incident reports. In an embodiment, the system 200 may employ automated data retrieval techniques, such as web scraping and an application programming interface (API) based threat feed ingestion for collecting cybersecurity updates in real-time. In other non-limiting examples of the data retrieval techniques may include database querying to retrieve existing reports, advisories, and malware analysis datasets. Thus, in an advantageous aspect, obtaining the threat-related information may serve purpose for further contextualization and intelligence extraction in forthcoming steps.
[0058] In an embodiment, to obtain the threat-related information the system 200 is configured to extract metadata from the threat-related information. The metadata indicates representational attributes for identification, categorization, contextualization, and extraction of the threat-related information The system 200 is configured to identify key attributes from raw data (i.e., as sources from the data source 102) using Natural Language Processing (NLP) and Named Entity Recognition (NER). In a non-limiting example, the metadata may include threat ty pes: such as malware, phishing, or ransomware. In a non-limiting example, the metadata mayinclude affected entities such as specific software, hardware, or infrastructure. In a non-limiting example, the metadata may include severity level or categorization such as high, medium or low.
[0059] In an advantageous aspect, the system 200 may use the metadata to categorize the threat-related information into predefined taxonomies such as malware families (e.g.. Trojan. Worm. Rootkit), and industries targeted (e.g., Healthcare. Finance, Manufacturing).
[0060] Further, in an embodiment, the system 200 is configured to filter the threat-related information based on contextual relevance. The contextual relevance may correspond to relevance to organizational assets, historical attack patterns or threat impact data associated with the asset elements, or any correlation wi th recent cyber incidents. In an advantageous aspect, the contextual filtering or the contextual relevance ensures that only the most relevant and actionable threats are selected for further processing. Consequently, the system 200 is configured to obtain the threat-related infonnation based on the metadata and the contextual relevance. Thus, the threat-related information corresponds to structured and unstructured data indicative of the cybersecurity threats.
[0061] In an embodiment, the system 200 is configured to generate, using a natural language processing (NLP) model, a summarized representation of content in the threat-related infonnation. In an advantageous aspect, the summarized representation is an extraction of the most relevant portions of content in the threat-related information or intelligence while eliminating unnecessary7details. In an example, the system 200 may select the most informative sentences directly from text (i.e., the data source 102) and consequently retain the original wording, ensuring accuracy in cybersecurity -related details in the summarized representation. In another example, the system 200 may rewrite the content using deep learning models toprovide a concise and coherent summary. Thus, advantageously ensuring readability while retaining essential threat intelligence details in the summarized representation.
[0062] The NLP model may include named entity recognition (NER) to extract and classify key entities in the threat-related information (i.e., from both the structured and unstructured threat intelligence sources). In a non-limiting example, the key entities may correspond to organization names, internet protocol addresses, malware names, and vulnerability identifiers from the threat-related information. In a non-limiting example, the NLP model is a large language model (LLM) tuned for threat intelligence and trained to recognize terminology and patterns associated with the cybersecurity threats.
[0063] In an embodiment, the NLP model may split the threat-related information, particularly the text into words and phrases. Further, the NLP model may identify nouns, verbs, and other grammatical structures in the threat-related information. Furthermore, the NLP model may recognize words or phrases that belong to predefined cybersecurity categories and consequently map the extracted key entities to structured threat intelligence databases. In an advantageous aspect, the NLP model provides an automated entity recognition and mapping framework which significantly enhances threat detection, classification, and response automation.
[0064] Consequently, the system 200 is configured to identify a set of threat attributes in the content using the NLP model. The set of threat attributes may correspond to features or detailed characterization of the cybersecurity threats.
[0065] In an embodiment, the set of threat attributes may be syntax patterns such as, structural features within the threat-related information. Further, the set of threat attributes may be semantic relationships such as contextual meaning and associations within the threat-related information. Furthermore, the set of threat attributes may be entity correlations such as linkagesbetween threat-related entities. Furthermore, the set of threat attributes may be statistical anomalies such as the detection of unusual patterns within the threat-related information. In an advantageous aspect, the set of threat attributes may enhance threat detection, classification, and response automation in the system 200 for generating the threat intelligence report 208. Furthermore, in a non-limiting example, the set of threat attributes may include at least one of malware, threat actors, vulnerabilities, or indicators of compromise (loC) (e.g., malicious IPs. domains, file hashes. URLs).
[0066] In an embodiment, the system 200 is configured to retrieve the asset elements from the asset management platform 206. The asset elements may correspond to uniquely identifiable entities within an organization, digital or physical resources or human-centric assets (e.g. employees) that possess business critical significance to the organization and are susceptible to the cybersecurity threats.
[0067] In a non-limiting example, the asset elements may include network infrastructure such as IP addresses, DNS records, and subnets. In anon-limiting example, the asset elements may include electronic devices such as workstations, mobile devices, and Internet of Things (loT) devices. In a non-limiting example, the asset elements may include applications and services such as SaaS platforms. In a non-limiting example, the asset elements may include user accounts and identities such as employees, employee accounts, and access credentials. In anon-limiting example, the asset elements may include employees and executives such as C-suite executives, IT administrators, finance department personnel, and employees with access to critical systems (e.g., system administrators).
[0068] In an advantageous aspect, retrieving the asset elements, the system 200 ensures that threat intelligence is contextualized and prioritized based on actual risks to enterpriseinfrastructure or enterprise personnel or employees. Further, in an advantageous aspect. retrieval of the asset elements assists the system 200 in determining if an emerging cybersecurity threat is relevant to the organization's environment. Thus, the system 200 advantageously prioritizes vulnerabilities thus ensuring that threats targeting business-critical assets are addressed first.
[0069] In an embodiment, the system 200 is configured to correlate the set of threat attributes in the threat-related infonnation with the asset elements. In an advantageous aspect, the correlation enhances the threat intelligence report 208 based on mapping the cybersecurity threats directly to the organization's infrastructure, digital assets, and human personnel (asset elements). Thus, based on the correlation, the system 200 advantageously ensures that cybersecurity alerts are actionable, providing security teams with the exact asset elements at risk, rather than generic alerts. Consequently, reducing false positives, prioritizing mitigation efforts, and enhancing real-time threat response. In an embodiment, the system 200 cross-references the set of threat attributes with organizational asset data (asset elements) using techniques such as entity matching and contextual matching. In an example, the entity matching may correspond to comparing extracted IPs, domains, file hashes, and email addresses with known organizational assets (i.e., asset elements). In an example, the contextual matching may correspond to identifying role-based risks such as if a cybercriminal group is targeting finance personnel.
[0070] In an embodiment, the system 200 is configured to determine the relevancy score. The relevancy score may refer to the quantification of an association of the set of threat attributes (e.g., malware, threat actors, vulnerabilities, loC) with the asset elements (e.g., employees, digital systems, servers, applications).
[0071] The system 200 is configured to obtain asset data associated with the asset elements from the asset management platfonn 206. In a non-limiting example, the asset data may include information related to organizational assets (asset elements) such as computing devices, servers, databases, network endpoints, applications, user accounts, and employees or personnel within the organization.
[0072] In an embodiment, the system 200 is configured to obtain the asset data to establish contextual relationships between the asset elements and potential cybersecurity threats. For instance, the system 200 may extract employee roles, department affiliations, and system access privileges to assess the potential impact of a threat on specific personnel or infrastructure components. Additionally, the asset data may include historical security incidents, known vulnerabilities, and remediation records, which provide further insights into an asset’s susceptibility to cyber threats.
[0073] In an advantageous aspect, thus based on the asset data, the system 200 enables a more comprehensive risk assessment, ensuring that threat intelligence is contextualized based on real-world asset exposure and relevance. This process enhances the accuracy of threat detection, impact analysis, and response prioritization, ultimately strengthening the organization's cybersecurity measures.
[0074] The system 200 is configured to map the correlated set of threat attributes to the corresponding asset elements using predefined association rules and contextual dependencies. In an example, the predefined association rules may refer to known threat-to-asset relationships for instance, a malware signature matches targeting w indow s servers. Thus, the system 200 may map the malware to all windows servers in the asset database (the asset management platform 206). In an example, the contextual dependencies may refer to the close relation of an asset toa threat, for instance, determining if at-risk employee (asset element) has administration rights. Thus, the mapping of the correlated set of threat attributes to the corresponding asset elements corresponds to a refinement step where each correlated threat attribute among the set of threat attributes is specifically assigned to the asset element using predefined rules and contextual dependencies. In an advantageous aspect, the mapping thus ensures that the relevancy score is accurately determined based on structured relationships.
[0075] The system 200 is configured to determine the relevancy score based on the mapping.
[0076] In an example, once the set of threat attributes is mapped to the asset elements, the system 200 is configured to determine the relevancy score by analyzing logical reasoning such as checking causal relationships between the asset elements & the threats. For instance, if employee A has access to customer databases, and a phishing attack is detected targeting employee A's email, the attack is highly relevant because it can lead to a data breach.
[0077] In an example, once the set of threat attributes is mapped to the asset elements, the system 200 is configured to determine the relevancy score by analyzing contextual analysis such as considering organizational context, asset criticality, and exposure. For instance, a vulnerability in a public-facing web server is more relevant than one in a backup file that is disconnected from the internet.
[0078] In an example, once the set of threat attributes is mapped to the asset elements, the system 200 is configured to determine the relevancy score based on analyzing historical threat impact data such as analyzing the past threat incidents to determine the likelihood of exploitation. For instance, if a malware strain has previously impacted similar asset elements, then the malware strain gets a higher relevancy score.
[0079] Consequently, the system 200 is configured to determine the relevancy score from a combination of the logical reasoning, the contextual analysis, and the historical threat impact data associated with the asset elements and the set of threat attributes.
[0080] In an embodiment, the system 200 is configured to categorize the threat-related information into one of a plurality of threat levels based on the relevancy score. The categorization may correspond to assigning the threat-related information into one of a high, medium, or low threat levels. In an example, each of the category (high, medium, or low threat levels) may have certain characteristics.
[0081] For instance, if the relevancy score is between 80% - 100% then the threat-related information may be categorized as the high level thus having characteristics such as “directly impacting critical assets (asset elements)’ and ‘urgent remedy required'.
[0082] For instance, if the relevancy score is between 50% - 79% then the threat-related information may be categorized as the medium level thus having characteristics such as ‘potential threat with limited exposure’ and ‘no immediate exploitation detected'.
[0083] For instance, if the relevancy score is less than 50% then the threat-related information may be categorized as the low level thus having characteristics such as ‘minimum risk’ and ‘no immediate action required'.
[0084] Further, the system 200 is configured to store the loC from among the set of threat attributes via API in a structured data repository accessible by a data analytics platform (e.g. Splunk) and corresponding threat-related information. The structured data repository' comprises historical loC records along with associated timestamps, thus advantageously enabling timeseries analysis of emerging cybersecurity' threats.
[0085] Furthermore, the system 200 is configured to generate an alarm notification based on the categorization of the threat-related information and the storage of loC. For instance, if the threat-related information is categorized as the high level or the medium level, then the system 200 triggers an alert. Consequently, the system 200 ensures that the loC is logged in a repository and sends the alarm notification such as real-time alerts via email, messaging platforms (e.g.. Slack™, Microsoft Teams™), or security information and event management (SIEM) dashboards. In an advantageous aspect, the system 200 ensures efficient threat prioritization, proactive defense, and enhanced situational awareness against evolving the cybersecurity threats.
[0086] In an embodiment, the system 200 is configured to trigger a real-time notification when the relevancy score exceeds a predefined threshold. In an advantageous aspect, the real-time notification ensures immediate awareness and swift action against potential the cybersecurity threats.
[0087] The real-time notification may be triggered upon comparing the relevancy score against the predefined threshold. The real-time notification corresponds to sending alerts through the distributing channels 210 (e.g., Email, SIEM, SOAR, Slack, Microsoft Teams).
[0088] In an embodiment, the system 200 is configured to generate the threat intelligence report 208 based on the correlation and the set of threat attributes.
[0089] The system 200 correlates threat intelligence data (i.e., the threat intelligence report 208) based on correlating the set of threat attributes (e.g., loCs, attack vectors, malware signatures), with the historical cybersecurity events (e.g., previous breaches, incidents) and the asset elements (e.g., affected servers, applications, users).
[0090] The threat intelligence report 208 indicates an assessment of the cybersecurity threats from the set of threat attributes and the impact on the correlated asset elements. Thus, advantageously the threat intelligence report 208 corresponds to a comprehensive document for security teams. SOC analysts, and threat researchers for evaluation of the cybersecurity threats.
[0091] The threat intelligence report 208 may include interactive visualizations, such as a malware dashboard displaying identified malware families and associated attributes. The threat intelligence report 208 may include interactive visualizations, such as a threat actor profile section listing detected adversarial entities and associated activities. The threat intelligence report 208 may include interactive visualizations, such as an loC summary’ panel including identified loC. The threat intelligence report 208 may include interactive visualizations, such as a vulnerability tracker displaying detected identification markers corresponding to common vulnerabilities and exposures and associated risk levels.
[0092] Furthermore, the system 200 is configured to disseminate the threat intelligence report 208 through the distributing channels 210 such as the email, an internal portal, or the online messaging platform.
[0093] FIG. 3 illustrates an example scenario of the system 200 configured to obtain threat-related information and disseminating the threat intelligence report 208, in accordance with one embodiment of the present disclosure.
[0094] In an embodiment, as depicted in FIG. 3, the system 200 obtains the threat-related infonnation from various data sources (the data source 102), including human input, RSS feeds, websites, and threat intelligence articles. Additionally, the system 200 retrieves asset elements from the asset management platform 206, such as Axonius™.
[0095] The system 200 is configured to generate the threat intelligence report 208, which may be disseminated through the distributed channels 210, including email, internal portals, and online messaging platforms. In one scenario, the loCs from the threat intelligence report 208 are uploaded to Splunk™ (a distributed channel) for further analysis. Additionally, summarized threat intelligence report 208 may be processed and uploaded to the large language models (LLMs) (the distributed channel) for enhanced contextual understanding and analysis.
[0096] FIG. 4 illustrates an embodiment of an example device 400. As shown in FIG. 4. the example device 400 includes processor 410, a memory’ 420, a storage component 430, an input component 440, an output component 450, a communication interface 460, and a bus 470. In an embodiment, the system 200 may reside in the example device 400.
[0097] The processor 410, as used herein, means any type of computational circuit that may comprise hardware elements and software elements. The processor 410 may be embodied as a multi-core processor, a single core processor, or a combination of one or more multi-core processors and / or one or more single core processors, a distributed processing system, or the like. The processor 410 may be a Central Processing Unit (CPU), a graphics processing unit (GPU), an accelerated processing unit (APU), an application-specific integrated circuit (ASIC), or another type of processing component.
[0098] Memory' 420 includes a non-transitory computer readable medium. Memory' 420 includes a random-access memory (RAM), a read only memory (ROM), and / or another ty pe of dynamic or static storage device (e.g., a flash memory', a magnetic memory’, and / or an optical memory ) that stores information and / or instructions for use by processor 410. The memory' 420 comprises machine-readable instructions which are executable by the processor 410. Thesemachine-readable instructions when executed by the processor 410 cause the processor 410 to perform one or more method steps of an embodiment described above.
[0099] Storage component 430 stores information and / or software related to the operation and use of the device 400. For example, storage component 430 may include a hard disk (e.g.. a magnetic disk, an optical disk, a magneto-optic disk, and / or a solid-state disk), a compact disc (CD), a digital versatile disc (DVD), a floppy disk, a cartridge, a magnetic tape, and / or another type of non-transitory computer-readable medium, along with a corresponding drive.
[0100] Input component 440 is configured to receive information, such as user input. For example, the input component 440 may include, but not be limited to. a touch screen display, a keyboard, a keypad, a mouse, a button, a switch, and / or a microphone. Additionally, or alternatively, the input component 440 may include a sensor for sensing information (e.g., a global positioning system (GPS), an accelerometer, a gyroscope, and / or an actuator).
[0101] Output component 450 is configured to provide output information from the device 400. For example, the output component 450 may be, but not limited to, a display, a speaker, an instruction device to an external device, and / or one or more light-emitting diodes (LEDs).
[0102] Communication interface 460 is an interface that provides a communication connection to other devices, such as external devices and internal devices. The connection by the communication interface 460 can be a wired connection, a wireless connection, or a combination of wired and wireless connections, and can be a direct connection or an indirect connection via a communication network that exists between the device 400 and other devices. In other words, the standard of the communication interface 460 is not limited.
[0103] The bus 470 acts as an interconnect between the processor 410, the memory 420, the storage component 430, the input component 440, the output component 450, and thecommunication interface 460 of the device 400. The bus 470 may include a wired interconnection or a wireless interconnection.
[0104] The number and arrangement of components shown in FIG. 4 are provided as an example. In practice, device 400 may include additional components, fewer components, different components, or differently arranged components than those shown in FIG. 4. Additionally, or alternatively, a set of components (e.g., one or more components) of device 400 may perform one or more functions described as being performed by another set of components of device 400. Further, one or more method steps described in any of the embodiments may be performed utilizing a plurality of devices 400 in communication with one another.
[0105] FIG. 5 illustrates a flow chart of an example method 500 for generating the threat intelligence report 208, in accordance with one embodiment of the present disclosure. The method 500 may be a computer-implemented method executed, for example, by the system 200.
[0106] At step 502, the method 500 may include obtaining the threat-related information from the data source 102 using the data retrieval techniques.
[0107] At step 504, the method 500 may include correlating the set of threat attributes in the threat-related information with the asset elements, retrieved from the asset management platfonu 206. The set of threat attributes indicates features having syntax patterns, semantic relationships, entity correlations, and statistical anomalies associated with cybersecurity threats.
[0108] At step 506, the method 500 may include determining the relevancy score based on the correlation. The relevancy score indicates the impact of the set of threat attributes on the asset elements.
[0109] At step 508, the method 500 may include triggering the real-time notification in response to the relevancy score exceeding the predefined threshold.
[0110] At step 510, the method 500 may include generating the threat intelligence report 208 based on the correlation and the set of threat attributes. The threat intelligence report 208 indicates the assessment of the cybersecurity threats from the set of threat attributes and the impact on the correlated asset elements.
[0111] FIG. 6 illustrates a method-step 600 for obtaining the threat-related information, in accordance with one embodiment of the present disclosure.
[0112] At step 602, the method-step 600 may include extracting the metadata from the threat-related information. The metadata may indicate representational attributes for the identification, categorization, and extraction of the threat-related information.
[0113] At step 604, the method-step 600 may include obtaining the threat-related information based on the metadata and the contextual relevance. The threat-related information indicates structured and unstructured data indicative of the cybersecurity threats.
[0114] FIG. 7 illustrates a method-step 700 for identifying the set of threat attributes, in accordance with one embodiment of the present disclosure.
[0115] At step 702, the method-step 700 may include generating, using the NLP model, the summarized representation of content in the threat-related information. The NLP model may include NER to extract the key entities indicating organization names, internet protocol addresses, malware names, and vulnerability identifiers from the threat-related infonnation.
[0116] At step 704, the method-step 700 may include identifying the set of threat attributes in the content using the NLP model.
[0117] FIG.8 illustrates a method-step 800 for determining the relevancy score, in accordance with one embodiment of the present disclosure.
[0118] At step 802, the method-step 800 may include obtaining the asset data associated with the asset elements from the asset management platform 206.
[0119] At step 804. the method-step 700 may include mapping the correlated set of threat attributes to the corresponding asset elements using predefined association rules and contextual dependencies.
[0120] At step 806, the method-step 800 may include determining the relevancy score based on the mapping. The relevancy score is derived from the combination of the logical reasoning, the contextual analysis, and the historical threat impact data associated with the asset elements and the set of threat attributes.
[0121] Examples of the techniques and apparatus described herein include, but are not limited to, the following enumerated embodiments:[1] A method comprising:obtaining threat-related information from at least one data source using data retrieval techniques;correlating a set of threat attributes in the obtained threat-related information with one or more asset elements, wherein the one or more asset elements indicate uniquely identifiable entities within an organization retrieved from an asset management platform, wherein the set of threat attributes indicates features having syntax patterns, semantic relationships, entity correlations, and statistical anomalies associated with cybersecurity' threats;determining a relevancy score based on the correlation, wherein the relevancy score indicates an impact of the set of threat attributes on the one or more asset elements;triggering a real-time notification in response to the relevancy score exceeding a predefined threshold; andgenerating a threat intelligence report based on the correlation and the set of threat attributes, wherein the threat intelligence report indicates an assessment of the cybersecurity threats from the set of threat attributes and an impact on the correlated one or more asset elements.[2] The method as described in [1]. wherein obtaining the threat-related information comprises:extracting metadata from the threat-related information, wherein the metadata indicates representational attributes for identification, categorization, and extraction of the threat-related information; andobtaining the threat-related information based on the metadata and contextual relevance, wherein the obtained threat-related information indicates structured and unstructured data indicative of the cybersecurity threats.[3] The method as described in [ l]-[2] , wherein prior to correlating, the method comprises: generating, using a natural language processing (NLP) model, a summarized representation of content in the obtained threat-related information, wherein the NLP model comprises named entity recognition (NER) to extract key entities indicating organization names, internet protocol addresses, malware names, and vulnerability identifiers from the obtained threat-related information; andidentifying the set of threat attributes in the content using the NLP model.[4] The method as described in [l]-[3], wherein the NLP model is a large language model (LLM) tuned for threat intelligence and trained to recognize terminology and patterns associated with the cybersecurity threats.[5] The method as described in [l]-[4], wherein determining the relevancy score comprises: obtaining asset data associated with each of the one or more asset elements from the asset management platform;mapping the correlated set of threat attributes to the corresponding one or more asset elements using predefined association rules and contextual dependencies: and determining the relevancy score based on the mapping, wherein the relevancy score is derived from a combination of logical reasoning, contextual analysis, and historical threat impact data associated with the one or more asset elements and the set of threat attributes.[6] The method as described in [l]-[5], comprising:categorizing the obtained threat-related information into one of a plurality of threat levels based on the relevancy score, wherein the categorization indicates assigning the obtained threat-related information into one of a high, medium, or low threat levels;storing indicators of compromise (loC) from among the set of threat attributes via API in a structured data repository accessible by a data analytics platform and a corresponding obtained threat-related information; andgenerating an alarm notification based on the categorization of the obtained threat-related information and the storage of loC.[7] The method as described in [l]-[6], wherein the structured data repository comprises historical loC records along with associated timestamps, enabling time-series analysis of emerging cybersecurity threats.[8] The method as described in [l]-[7], comprising:disseminating the threat intelligence report through at least one of an electronic mail, an internal portal, or an online messaging platform.[9] The method as described in [l]-[8], wherein triggering the real-time notification comprises: transmitting using an application programming interface (API), the real-time notification to an online messaging platfonn.
[0010] The method as described in [I]-[9], wherein the set of threat attributes comprises at least one of a malware, one or more threat actors, one or more vulnerabilities, or one or more indicators of compromise (loC).
[0011] The method as described in [l]-
[0010] . wherein the one or more asset elements comprises uniquely identifiable entities that possess critical significance to an organization and are susceptible to the cybersecurity threats.
[0012] The method as described in [1]-
[0011] . wherein the threat intelligence report comprises at least one interactive visualization, selected from:a malware dashboard displaying identified malware families and associated attributes; a threat actor profile section listing detected adversarial entities and associated activities;an loC summary panel comprising identified loC; anda vulnerability tracker displaying detected identification markers corresponding to common vulnerabilities and exposures and associated risk levels.
[0013] A system configured to:obtain threat-related information from at least one data source using data retrieval techniques;correlate a set of threat attributes in the obtained threat-related information with one or more asset elements, wherein the one or more asset elements indicate uniquely identifiable entities within an organization retrieved from an asset management platform, wherein the set of threatatributes indicates features having syntax paterns, semantic relationships, entity correlations. and statistical anomalies associated with the cybersecurity threats;determine a relevancy score based on the correlation, wherein the relevancy score indicates an impact of the set of threat atributes for the one or more asset elements; trigger a real-time notification in response to the relevancy score exceeding a predefined threshold; andgenerate a threat intelligence report based on the correlation and the set of threat atributes, wherein the threat intelligence report indicates an assessment of the cybersecurity threats from the identified set of threat atributes and an impact on the correlated one or more asset elements.
[0014] The system as described in
[0013] , wherein to obtain the threat-related infomiation, the system is configured to:extract metadata from the threat-related information, wherein the metadata indicates representational atributes for identification, categorization, and extraction of the threat-related information; andobtain the threat-related infomiation based on the metadata and contextual relevance, wherein the obtained threat-related information indicates structured and unstructured data indicative of the cybersecurity threats.
[0015] The system as described in
[0013] -
[0014] , wherein prior to correlating, the system is configured to:generate, using a natural language processing (NLP) model, a summarized representation of content in the obtained threat-related information, wherein the NLP model is a large language model (LLM) tuned for threat intelligence and trained to recognizeterminology and patterns associated with the cybersecurity threats, the NLP model comprises named entity recognition (NER) to extract key entities indicating organization names, internet protocol addresses, malware names, and vulnerability identifiers from the obtained threat-related information; andidentifying the set of threat attributes in the content using the NLP model.
[0016] The system as described in
[0013] -
[0015] , wherein to determine the relevancy score, the system is configured to:obtain asset data associated with each of the one or more asset elements from the asset management platform;map the correlated set of threat attributes to the corresponding one or more asset elements using predefined association rules and contextual dependencies: anddetermine the relevancy score based on the mapping, wherein the relevancy score is derived from a combination of logical reasoning, contextual analysis, and historical threat impact data associated with the one or more asset elements and the set of threat attributes.
[0017] The system as described in
[0013] -
[0016] , wherein the system is configured to:categorize the obtained threat-related information into one of a plurality of threat levels based on the relevancy score, wherein the categorization indicates assigning the obtained threat-related information into one of a high, medium, or low threat levels;store indicators of compromise (loC) from among the set of threat attributes via API in a structured data repository accessible by a data analytics platform and a corresponding obtained threat-related information, wherein the structured data repository comprises historical loC records along with associated timestamps, enabling time-series analysis of emerging cybersecurity7threats; andgenerate an alarm notification based on the categorization of the obtained threat-related information and the storage of loC.
[0018] The system as described in
[0013] -
[0017] , the system is configured to:disseminate the threat intelligence report through at least one of an electronic mail, an internal portal, or an online messaging platform, wherein the threat intelligence report comprises at least one interactive visualization, selected from:a malware dashboard displaying identified malware families and associated attributes;a threat actor profile section listing detected adversarial entities and associated activities;an loC summary panel comprising identified loC; anda vulnerability’ tracker displaying detected identification markers corresponding to common vulnerabilities and exposures and associated risk levels.
[0019] The system as described in
[0013] -
[0018] , wherein the set of threat attributes comprises at least one of a malware, one or more threat actors, one or more vulnerabilities, or one or more indicators of compromise (loC).
[0020] A non-transitory computer-readable medium storing instructions, the instructions comprising: one or more instructions that, when executed by one or more processors, cause the one or more processors to:obtain threat-related information from at least one data source using data retrieval techniques;correlate a set of threat attributes in the obtained threat-related information with one or more asset elements, wherein the one or more asset elements indicate uniquely identifiableentities within an organization retrieved from an asset management platform, wherein the set of threat attributes indicates features having syntax patterns, semantic relationships, entity correlations, and statistical anomalies associated with the cybersecurity threats;determine a relevancy score based on the correlation, wherein the relevancy score indicates an impact of the set of threat attributes of the one or more asset elements; triggering a real-time notification in response to the relevancy score exceeding a predefined threshold; andgenerate a threat intelligence report based on the correlation and the set of threat attributes, wherein the threat intelligence report indicates an assessment of the cybersecurity threats from the identified set of threat attributes and an impact on the correlated one or more asset elements.
[0122] The embodiments disclosed herein can be implemented through at least one software program running on at least one hardware device and performing network management functions to control the elements. The elements can be at least one of a hardware device or a combination of hardware devices and software modules. The UE may include respective processors, communication units, and storage units (e.g., memory). The communication units may perform functions for transmitting and receiving signals. The storage units may include executable instructions that, when executed by the corresponding processors, cause the corresponding UE to perform the functions as described above with reference to Figure 2-Figure 8.
[0123] While specific language has been used to describe the disclosure, any limitations arising on account of the same are not intended. As would be apparent to a person in the art,various working modifications may be made to the method in order to implement the inventive concept as taught herein.
[0124] The drawings and the forgoing description give examples of embodiments. Those skilled in the art will appreciate that one or more of the described elements may well be combined into a single functional element. Alternatively, certain elements may be split into multiple functional elements. Elements from one embodiment may be added to another embodiment. For example, orders of processes described herein may be changed and are not limited to the manner described herein.
[0125] Moreover, the actions of any flow diagram need not be implemented in the order shown; nor do all of the acts necessarily need to be performed. Also, those acts that are not dependent on other acts may be performed in parallel with the other acts. The scope of embodiments is by no means limited by these specific examples. Numerous variations, whether explicitly given in the specification or not. such as differences in structure, dimension, and use of material, are possible. The scope of embodiments is at least as broad as given by the following claims.
[0126] Benefits, other advantages, and solutions to problems have been described above with regard to specific embodiments. However, the benefits, advantages, solutions to problems, and any component(s) that may cause any benefit, advantage, or solution to occur or become more pronounced are not to be construed as a critical, required, or essential feature or component of any or all the claims.
[0127] The foregoing description of the specific embodiments will so fully reveal the general nature of the embodiments herein that others can, by applying current knowledge, readily modify and / or adapt for various applications such specific embodiments without departing fromthe generic concept, and, therefore, such adaptations and modifications should and are intended to be comprehended within the meaning and range of equivalents of the disclosed embodiments. It is to be understood that the phraseology or terminology employed herein is for the purpose of description and not of limitation. Therefore, while the embodiments herein have been described in terms of at least one embodiment, those skilled in the art will recognize that the embodiments herein can be practiced with modification within the spirit and scope of the embodiments as described herein.
Claims
WE CLAIM:
1. A method comprising:obtaining threat-related information from at least one data source using data retrieval techniques;correlating a set of threat attributes in the obtained threat-related information with one or more asset elements, wherein the one or more asset elements indicate uniquely identifiable entities within an organization retrieved from an asset management platform, wherein the set of threat attributes indicates features having syntax patterns, semantic relationships, entity correlations, and statistical anomalies associated with cybersecurity threats;determining a relevancy score based on the correlation, wherein the relevancy score indicates an impact of the set of threat attributes on the one or more asset elements;triggering a real-time notification in response to the relevancy score exceeding a predefined threshold: andgenerating a threat intelligence report based on the correlation and the set of threat attributes, wherein the threat intelligence report indicates an assessment of the cybersecurity threats from the set of threat attributes and an impact on the correlated one or more asset elements.
2. The method as claimed in claim 1, wherein obtaining the threat-related information comprises:extracting metadata from the threat-related information, wherein the metadata indicates representational attributes for identification, categorization, and extraction of the threat-related information; andobtaining the threat-related information based on the metadata and contextual relevance. wherein the threat-related information indicates structured and unstructured data indicative of the cybersecurity threats.
3. The method as claimed in claim 1, wherein prior to correlating, the method comprises:generating, using a natural language processing (NLP) model, a summarized representation of content in the obtained threat-related information, wherein the NLP model comprises named entity recognition (NER) to extract key entities indicating organization names, internet protocol addresses, malware names, and vulnerability identifiers from the obtained threat-related information; andidentifying the set of threat attributes in the content using the NLP model.
4. The method as claimed in claim 3, wherein the NLP model is a large language model (LLM) tuned for threat intelligence and trained to recognize terminology and patterns associated with the cybersecurity threats.
5. The method as claimed in claim 1, wherein determining the relevancy score comprises:obtaining asset data associated with each of the one or more asset elements from the asset management platform;mapping the correlated set of threat attributes to the corresponding one or more asset elements using predefined association rules and contextual dependencies; anddetermining the relevancy score based on the mapping, wherein the relevancy score is derived from a combination of logical reasoning, contextual analysis, and historical threat impact data associated with the one or more asset elements and the set of threat attributes.
6. The method as claimed in claim 5, comprising:categorizing the obtained threat-related information into one of a plurality of threat levels based on the relevancy score, wherein the categorization indicates assigning the obtained threat-related information into one of a high, medium, or low threat levels;storing indicators of compromise (loC) from among the set of threat attributes via API in a structured data repository’ accessible by a data analytics platform and a corresponding obtained threat-related information; andgenerating an alarm notification based on the categorization of the obtained threat-related information and the storage of loC.
7. The method as claimed in claim 6, wherein the structured data repository' comprises historical loC records along with associated timestamps, enabling time-series analysis of emerging cybersecurity' threats.
8. The method as claimed in claim 1, comprising:disseminating the threat intelligence report through at least one of an electronic mail, an internal portal, or an online messaging platform.
9. The method as claim 1, wherein triggering the real-time notification comprises: transmitting using an application programming interface (API), the real-time notification to an online messaging platform.
10. The method as claimed in claim 1, wherein the set of threat attributes comprises at least one of a malware, one or more threat actors, one or more vulnerabilities, or one or more indicators of compromise (loC).
11. The method as claimed in claim 1, wherein the one or more asset elements comprises uniquely identifiable entities that possess critical significance to an organization and are susceptible to the cybersecurity’ threats.
12. The method as claimed in claim 1, wherein the threat intelligence report comprises at least one interactive visualization, selected from:a malware dashboard displaying identified malware families and associated attributes; a threat actor profile section listing detected adversarial entities and associated activities;an loC summary panel comprising identified loC; anda vulnerability tracker displaying detected identification markers corresponding to common vulnerabilities and exposures and associated risk levels.
13. A system configured to:obtain threat-related information from at least one data source using data retrieval techniques;correlate a set of threat attributes in the obtained threat-related infonnation with one or more asset elements, wherein the one or more asset elements indicate uniquely identifiable entities within an organization retrieved from an asset management platform, wherein the set of threat attributes indicates features having syntax patterns, semantic relationships, entity correlations, and statistical anomalies associated with the cybersecurity threats;determine a relevancy score based on the correlation, wherein the relevancy score indicates an impact of the set of threat attributes for the one or more asset elements; trigger a real-time notification in response to the relevancy score exceeding a predefined threshold; andgenerate a threat intelligence report based on the correlation and the set of threat attributes, wherein the threat intelligence report indicates an assessment of the cybersecurity threats from the identified set of threat attributes and an impact on the correlated one or more asset elements.
14. The system as claimed in claim 13, wherein to obtain the threat-related information, the system is configured to:extract metadata from the threat-related information, wherein the metadata indicates representational attributes for identification, categorization, and extraction of the threat-related information; andobtain the threat-related information based on the metadata and contextual relevance, wherein the obtained threat-related information indicates structured and unstructured data indicative of the cybersecurity threats.
15. The system as claimed in claim 13, wherein prior to correlating, the system is configured to:generate, using a natural language processing (NLP) model, a summarized representation of content in the obtained threat-related information, wherein the NLP model is a large language model (LLM) tuned for threat intelligence and trained to recognize terminology and patterns associated with the cybersecurity threats, the NLP model comprises named entity recognition (NER) to extract key entities indicating organization names, internet protocol addresses, malware names, and vulnerability identifiers from the obtained threat-related information; andidentifying the set of threat attributes in the content using the NLP model.
16. The system as claimed in claim 13, wherein to determine the relevancy score, the system is configured to:obtain asset data associated with each of the one or more asset elements from the asset management platform;map the correlated set of threat attributes to the corresponding one or more asset elements using predefined association rules and contextual dependencies; anddetennine the relevancy score based on the mapping, wherein the relevancy score is derived from a combination of logical reasoning, contextual analysis, and historical threat impact data associated with the one or more asset elements and the set of threat attributes.
17. The system as claimed in claim 16, wherein the system is configured to:categorize the obtained threat-related information into one of a plurality of threat levels based on the relevancy score, wherein the categorization indicates assigning the obtained threat-related information into one of a high, medium, or low threat levels;store indicators of compromise (loC) from among the set of threat attributes via API in a structured data repository accessible by a data analytics platform and a corresponding obtained threat-related information, wherein the structured data repository comprises historical loC records along with associated timestamps, enabling time-series analysis of emerging cybersecurity threats; andgenerate an alarm notification based on the categorization of the obtained threat-related information and the storage of loC.
18. The system as claimed in claim 13, wherein the system is configured to:disseminate the threat intelligence report through at least one of an electronic mail, an internal portal, or an online messaging platform, wherein the threat intelligence report comprises at least one interactive visualization, selected from:a malware dashboard displaying identified malware families and associated attributes;a threat actor profile section listing detected adversarial entities and associated activities;an loC summary panel comprising identified loC ; anda vulnerability7tracker displaying detected identification markers corresponding to common vulnerabilities and exposures and associated risk levels.
19. The system as claimed in claim 13, wherein the set of threat attributes comprises at least one of a malware, one or more threat actors, one or more vulnerabilities, or one or more indicators of compromise (loC).
20. A non-transitory computer-readable medium storing instructions, the instructions comprising: one or more instructions that, when executed by one or more processors, cause the one or more processors to:obtain threat-related information from at least one data source using data retrieval techniques;correlate a set of threat attributes in the obtained threat-related information with one or more asset elements, wherein the one or more asset elements indicate uniquely identifiable entities within an organization retrieved from an asset management platform, wherein the set of threat attributes indicates features having syntax patterns, semantic relationships, entity correlations, and statistical anomalies associated with the cybersecurity threats;determine a relevancy score based on the correlation, wherein the relevancy score indicates an impact of the set of threat attributes of the one or more asset elements; triggering a real-time notification in response to the relevancy score exceeding a predefined threshold; andgenerate a threat intelligence report based on the correlation and the set of threat attributes, wherein the threat intelligence report indicates an assessment of the cybersecurity¬ threats from the identified set of threat attributes and an impact on the correlated one or more asset elements.