Attack Tactic Probability Scoring for Breach Text Triage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cybersecurity measures face challenges in efficiently determining which incidents require further investigation due to the high volume of data breaches, making it difficult for security operations analysts to prioritize and address potential threats effectively.

Innovation Solution

A system and method using machine learning algorithms, particularly natural language processing, to analyze historical text documents associated with breach events, generate attack tactic probabilities, and categorize documents based on these probabilities, enabling prioritization of high-risk incidents.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security operations analysts manually review all breach events, then thorough investigation is achieved, but time consumption and operational efficiency deteriorate due to high incident volume

Engineering Contradiction:
Improveinvestigation thoroughnessVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

A machine learning-based natural language processing system serves as an intermediary between breach event data and analyst review. The system automatically analyzes text documents, extracts attack tactics, and generates probability scores, filtering and prioritizing incidents before they reach human analysts. This intermediary processing maintains investigation quality for high-priority cases while reducing overall time consumption through automated triage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all breach events are investigated equally, then comprehensive security coverage is maintained, but resource allocation efficiency deteriorates due to inability to prioritize high-risk incidents

Engineering Contradiction:
Improvesecurity coverageVSAvoidresource allocation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies different levels of analysis and attention to different breach events based on their characteristics. By analyzing text documents and generating attack tactic probabilities, it identifies high-risk incidents that require immediate analyst attention while automatically processing or deprioritizing lower-risk cases. This localized quality approach ensures comprehensive coverage while optimizing resource allocation to where it is most needed.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If manual analysis of text documents is performed, then accurate attack tactic identification is achieved, but processing speed deteriorates due to high volume of historical documents

Engineering Contradiction:
Improveattack tactic identification accuracyVSAvoidprocessing speed
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The patent replaces manual mechanical analysis of text documents with an automated machine learning-based natural language processing system. This system uses computational algorithms to analyze text, identify attack tactics, and generate probability scores automatically. The substitution maintains measurement precision through trained models while dramatically improving processing speed by handling large volumes of historical documents without human intervention.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12499221B2Systems and methods for generating attack tactic probabilities for historical text documents
Publication Date: 2025.12.16 CISCO TECHNOLOGY INC
  • US12499221B2 patent drawing
  • US12499221B2 patent drawing
  • US12499221B2 patent drawing

AI summary

In one embodiment, a method includes receiving a historical text document that is associated with a breach event. The method also includes searching for an attack tactic within the historical text document using a machine learning algorithm. The method further includes generating a probability that the attack tactic exists within the historical text document, comparing the probability to a predetermined probability threshold, and categorizing the historical text document based on the probability.