AI Cyber Threat Detection for Structured Documents

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy cyber security tools are inadequate in addressing evolving cyber threats as they rely on predefined rules and signatures, fail to detect subtle changes in attacks, and struggle to identify insider threats, leading to daily bypasses and insufficient protection in modern digital environments.

Innovation Solution

A cyber security system utilizing artificial intelligence and machine learning models to analyze structured documents like emails, classify their characteristics, and determine autonomous responses based on threat scores, enabling real-time detection and mitigation of potential threats without human intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional rule-based and signature-based tools are used for cyber threat detection, then the system is easy to operate and implement, but the detection precision and reliability are insufficient against evolving threats

Engineering Contradiction:
Improvethreat detection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces traditional mechanical rule-based and signature-based detection systems with an artificial intelligence-based system that uses machine learning models to automatically analyze and detect cyber threats. The AI system processes structured documents and extracts characteristics without relying on pre-defined rules, thereby improving detection precision while managing complexity through automation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the fundamental parameters of threat detection by transitioning from static rules and signatures to dynamic machine learning models that continuously learn from data. The system extracts multiple characteristics from structured documents and uses these parameters to classify threats, enabling adaptation to evolving threats while maintaining operational simplicity.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If AI-based analysis is implemented to improve threat detection capability, then the detection precision and adaptability improve, but the computational resources and processing time increase

Engineering Contradiction:
Improvethreat detection adaptabilityVSAvoidcomputational resource consumption
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the AI-based analysis process into distinct modules: characteristic extraction from structured documents, classification using trained machine learning models, and autonomous response determination. This segmentation allows the system to process threats in manageable stages, improving adaptability while optimizing computational resource usage by focusing analysis only on relevant characteristics.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-training machine learning models on historical threat data before deployment. The models are trained to recognize patterns and characteristics of various threat types in advance, enabling the system to quickly classify new threats without requiring extensive real-time computational resources, thus balancing adaptability with energy efficiency.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If manual analysis of security information is performed, then the system complexity is low, but the productivity and response speed are insufficient for vast amounts of security data

Engineering Contradiction:
Improvethreat analysis productivityVSAvoidautomation level
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The patent implements self-service by enabling the system to automatically perform threat analysis, classification, and response determination without human intervention. The machine learning models autonomously process structured documents, extract characteristics, classify threats, and trigger appropriate responses, dramatically improving productivity while managing automation complexity through a structured framework.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms where the system continuously learns from analyzed threats and adjusts its classification models accordingly. The autonomous response module uses feedback from threat classifications to improve future detection accuracy, enabling high productivity while maintaining controllable automation levels through iterative learning and improvement.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240275799A1Method and system for determining and acting on a structured document cyber threat risk
Publication Date: 2024.08.15 DARKTRACE HLDG LTD
  • US20240275799A1 patent drawing
  • US20240275799A1 patent drawing
  • US20240275799A1 patent drawing

AI summary

A cyber defense system using machine learning models trained on the classification of structured documents, such as emails, in order to identify a cyber threat risk of the incoming or outgoing structured document and to cause one or more autonomous actions to be taken in relation to the structured document based on a comparison of a category the structured document is classified with, a score associated with the classification and a threshold score. For incoming structured documents, the autonomous actions of the cyber defense system may act to contain a malign nature of identified incoming structured documents. For outgoing structured documents, the autonomous actions of the cyber defense system may act to prevent the structured document from being sent to an unintended recipient.