AI Cyber Threat Analyst for Real-Time Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber threat detection systems face challenges in real-time monitoring and overwhelming data volumes, leading to delayed detection of suspicious activities and cyber threats, which can cause significant harm before being identified.

Innovation Solution

An AI-based cyber threat analyst system that utilizes machine learning models to analyze network traffic, identify abnormal behavior, and generate hypotheses about potential threats, incorporating data analysis processes like JA3 hash analysis and Ngram classification to detect malicious agents and data exfiltration, without decrypting encrypted traffic, and presenting findings in a formalized report.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If human analysts examine suspicious activities and abnormal behavior in real-time, then detection accuracy is improved, but the system cannot keep up with the overwhelming volume of data and real-time attack speed

Engineering Contradiction:
Improvedetection accuracyVSAvoiddata processing capacity
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent introduces an AI-based cyber threat analyst as an intermediary between the overwhelming data volume and human analysts. This AI system processes and analyzes suspicious activities and abnormal behavior, presenting filtered and prioritized findings to human analysts. The AI analyst acts as a mediator that handles the data processing burden while maintaining detection accuracy through machine learning models trained on security patterns.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The AI-based cyber threat analyst performs self-service by autonomously examining suspicious activities, investigating abnormal behavior, and generating threat assessments without requiring direct human intervention for each analysis. The system uses machine learning models to independently process data, form hypotheses, and provide actionable intelligence, freeing human analysts from manual data examination while maintaining high detection accuracy.

Inventive Principle:
Principle #25Self-service

2Reliability

If AI models are trained on normal pattern of life to identify abnormal behavior, then detection capability is improved, but the system complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by training AI models on the normal pattern of life parameters of the system, establishing a baseline of expected behavior. The system detects threats by identifying deviations from these learned parameters. This approach improves detection capability by focusing on behavioral anomalies while managing complexity through parameter-based analysis rather than complex rule sets.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system performs preliminary action by pre-training AI models on normal system behavior patterns before deployment. This preliminary training establishes the baseline for detecting abnormal behavior, allowing the system to quickly identify threats without requiring complex real-time analysis rules. The pre-trained models provide a foundation that simplifies ongoing threat detection while maintaining high reliability.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the AI-based system conducts full investigations on all suspicious activities, then detection completeness is improved, but the time for investigations increases

Engineering Contradiction:
Improvedetection completenessVSAvoidinvestigation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The AI-based cyber threat analyst applies partial action by conducting focused investigations on the most suspicious activities rather than exhaustive analysis of all suspicious events. The system prioritizes investigations based on threat severity and confidence levels, performing full investigations on high-priority cases while using quicker assessment methods for lower-priority events. This approach maintains detection completeness for critical threats while reducing overall investigation time.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11463457B2Artificial intelligence (AI) based cyber threat analyst to support a cyber security appliance
Publication Date: 2022.10.04 DARKTRACE HLDG LTD
  • US11463457B2 patent drawing
  • US11463457B2 patent drawing
  • US11463457B2 patent drawing

AI summary

An Artificial Intelligence AI-based cyber threat analyst protects a system from cyber threats. A cyber threat analyst module uses i) one or more AI models, ii) a set of scripts, and iii) any combination of both, to form and investigate hypotheses on what are a possible set of cyber threats that include abnormal behavior and/or a suspicious activity. An analyzer module uses one or more data analysis processes including i) an agent analyzer data analysis process; ii) an Ngram data analysis process; iii) an exfiltration data analysis process; and iv) a network scan data analysis process; in order to obtain any of the abnormal behavior and the suspicious activity to start the investigation on the possible set of cyber threats hypotheses, as well as, to obtain the collection of system data points to either support or refute the possible cyber threat hypotheses.