Cybersecurity Campaign Artifact Discovery via Telemetry Summarization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity systems struggle to detect targeted cyberattacks, such as Business Email Compromise (BEC) attacks, which are not widely and indiscriminately directed, making it difficult for external threat intelligence feeds to provide early warning signs.

Innovation Solution

A system and method that utilize enterprise telemetry to monitor and analyze incoming emails, a summarization module to summarize potential indicators of compromise, a campaign database comprising a graph database and a key-value database to store data from enterprise telemetry and external threat intelligence feeds, and a campaign engine to identify new indicators of compromise.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If external threat intelligence feeds are used as the sole source of cybersecurity monitoring, then the system can detect widely-directed cyberattacks, but it fails to detect targeted attacks like BEC that are directed at a single specific enterprise

Engineering Contradiction:
Improvedetection capabilityVSAvoidcoverage of attack types
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent combines external threat intelligence feeds with internal enterprise telemetry data into a unified monitoring system. This merging allows the system to leverage both the broad coverage of external feeds and the targeted insights from internal enterprise-specific data, enabling detection of both widely-directed and targeted attacks like BEC

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system segments threat detection into two complementary components: external threat intelligence feeds for broad attack patterns and internal enterprise telemetry for targeted attack detection. By dividing the monitoring approach, the system can address different attack types effectively without relying on a single source

Inventive Principle:
Principle #1Segmentation

2Reliability

If the system monitors and analyzes all incoming enterprise telemetry data in real-time, then it can identify targeted attacks, but the complexity and computational resources required increase significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary summarization of enterprise telemetry data before detailed analysis. By pre-processing and summarizing potential indicators of compromise, the system reduces the volume of data requiring complex analysis while maintaining detection accuracy for targeted attacks

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a summarization module as an intermediary between raw enterprise telemetry data and the campaign analysis engine. This intermediary processes and condenses telemetry data into meaningful summaries, reducing computational complexity while preserving critical security information

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12301622B1System for cybersecurity campaign artifact discovery and tasking
Publication Date: 2025.05.13 MORGAN STANLEY SERVICES GROUP INC
  • US12301622B1 patent drawing
  • US12301622B1 patent drawing
  • US12301622B1 patent drawing

AI summary

A system and method for detecting cyberattacks involves monitoring and analyzing incoming email received over the internet using enterprise telemetry; extracting observations from an enterprise telemetry data feeds and transmitting to a summarization module for summarizing a potential indicator of compromise pertaining to the email monitored and analyzed by the network telemetry; storing the observation summarization data in a graph database; querying over the internet an external cybersecurity threat intelligence provider, upon identification of a true-positive network threat, for enriching information and artifacts contained within the true-positive network threat, receiving over the internet enriching information and artifacts from the external cybersecurity threat intelligence provider, and storing the received enriching information and artifacts in the graph database; and identifying a new indicator of compromise using data stored in the graph database.