Browser Extension for Cyber Threat Intelligence Response
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional SIEM systems require network security analysts to manually investigate security alerts, which can be time-consuming and inefficient, especially in the face of growing cybersecurity threats and limited analyst resources.
Innovation Solution
A cloud-based enrichment and analysis system that allows network security analysts to quickly gather information on indicators of compromise, query threat data, and determine the reputation of observables, with the ability to automate responses through orchestrated playbooks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional SIEM systems are used to generate security alerts, then security threats can be identified, but the response time is slowed due to manual investigation requirements
Solution Approach 1:
The system segments the manual investigation process into automated components by integrating threat intelligence data, enrichment services, and automated response capabilities directly into the SIEM workflow, allowing different aspects of alert analysis to be handled by specialized automated functions
Solution Approach 2:
The system performs preliminary actions by pre-gathering threat intelligence data, enrichment information, and contextual data before security analysts need to investigate alerts, so that when analysts do review alerts, the necessary information is already prepared and available
2Measurement precision
If manual investigation of security alerts is performed, then thorough analysis can be conducted, but analyst resources are overwhelmed due to limited staff
Solution Approach 1:
The system introduces intermediary automated components including threat intelligence platforms, enrichment services, and orchestration engines that mediate between raw security alerts and analyst review, performing preliminary analysis, data gathering, and context provision to reduce the burden on analysts
Solution Approach 2:
The system enables self-service by allowing the SIEM to automatically gather threat intelligence data, enrich alert information, and even execute automated responses without requiring constant analyst intervention, making the system serve itself for routine analytical tasks
3Loss of information
If external threat intelligence data is gathered from multiple sources, then comprehensive security information can be obtained, but system complexity increases
Solution Approach 1:
The system applies universality by implementing a centralized threat intelligence platform that serves multiple functions: gathering data from various sources, normalizing different data formats, enriching alerts, and providing contextual information, thereby reducing the need for separate specialized systems for each function
Data Source
AI summary
Techniques are disclosed relate to systems, methods, and non-transitory computer readable media for implementing a browser extension for cyber threat intelligence and response. One system to perform operations comprising: scanning, in a sandbox of a browser by a browser extension, at least part of a web page to produce a set of items of interests; transmitting the set of items of interests to a cloud-based enrichment and analysis of cybersecurity threat intelligence system to request information on the set of items; receiving a response from the cloud-based enrichment and analysis of cybersecurity threat intelligence system, the response including a scan result based on the transmitted set of items of interests, and the scan result including at least one of an indicator of compromise of the at least scanned part of the web page; and displaying the scan results including the at least one of an indicator of compromise.


