Browser Extension Automates Cyber Threat Intelligence Response
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional SIEM systems require network security analysts to manually gather and analyze cybersecurity threat intelligence, which is time-consuming and inefficient, especially with the growing number of cybersecurity events, leading to delayed responses that compromise network security.
Innovation Solution
A cloud-based enrichment and analysis system that processes threat models, integrates external data feeds, and provides a reputation score to automate responses to cybersecurity threats, allowing analysts to focus on higher-priority tasks and improving response times.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If conventional SIEM systems are used for cybersecurity threat analysis, then security alerts can be generated and stored, but network security analysts must manually investigate and gather threat intelligence data, leading to delayed response times
Solution Approach 1:
The system enables automated threat intelligence gathering and analysis through AI/ML models that independently query multiple data sources, correlate indicators of compromise, and generate threat assessments without requiring manual analyst intervention for each alert investigation
Solution Approach 2:
An automated threat intelligence platform acts as an intermediary between SIEM systems and multiple external data sources, consolidating and analyzing threat data from various sources and presenting unified threat intelligence to analysts, thereby reducing manual investigation burden
2Productivity
If manual threat intelligence gathering is performed by analysts, then context and relevance can be obtained, but the process is time-consuming and inefficient given the growing number of cybersecurity events
Solution Approach 1:
Manual mechanical processes of threat intelligence gathering are replaced with automated electronic systems that use AI/ML algorithms to query, correlate, and analyze threat data from multiple sources simultaneously, dramatically improving productivity and reducing time requirements
Solution Approach 2:
The system performs preliminary threat intelligence gathering and analysis automatically in the background before analysts need to review alerts, pre-processing and consolidating data from multiple sources so that analysts receive ready-to-analyze intelligence rather than raw data
3Reliability
If analysts interrupt current tasks to log into SIEM systems for information gathering, then security decisions can be made, but response speed to potential threats is reduced
Solution Approach 1:
The threat intelligence platform provides multiple functions including data gathering, correlation, analysis, and presentation in a single unified system that can be accessed from various interfaces, eliminating the need for analysts to switch between multiple systems and tasks while maintaining comprehensive threat intelligence capabilities
Data Source
AI summary
Techniques are disclosed relate to systems, methods, and non-transitory computer readable media for implementing a browser extension for cyber threat intelligence and response. One system to perform operations comprising: receiving, in a sandbox of a browser by a browser extension, a selection of at least one particular indicator of compromise of the at least one of the indicator of compromise of at least scanned part of a web page; displaying one or more orchestrated responses; receiving a selection of at least one particular orchestrated response of the one or more orchestrated responses; transmitting the selected at least one particular orchestrated response to the cloud-based enrichment and analysis of cybersecurity threat intelligence system; receiving a response including a result of the at least one particular orchestrated response; and displaying the result of the at least one particular orchestrated response.


