Cybersecurity Campaign Artifact Discovery via Telemetry Summarization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity systems struggle to detect targeted cyberattacks, such as Business Email Compromise (BEC) attacks, which are not widely and indiscriminately directed, making it difficult for external threat intelligence feeds to provide early warning signs.
Innovation Solution
A system and method that utilize enterprise telemetry to monitor and analyze incoming emails, a summarization module to summarize potential indicators of compromise, a campaign database comprising a graph database and a key-value database to store data from enterprise telemetry and external threat intelligence feeds, and a campaign engine to identify new indicators of compromise.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If external threat intelligence feeds are used as the sole source of cybersecurity monitoring, then the system can detect widely-directed cyberattacks, but it fails to detect targeted attacks like BEC that are directed at a single specific enterprise
Solution Approach 1:
The patent combines external threat intelligence feeds with internal enterprise telemetry data into a unified monitoring system. This merging allows the system to leverage both the broad coverage of external feeds and the targeted insights from internal enterprise-specific data, enabling detection of both widely-directed and targeted attacks like BEC
Solution Approach 2:
The system segments threat detection into two complementary components: external threat intelligence feeds for broad attack patterns and internal enterprise telemetry for targeted attack detection. By dividing the monitoring approach, the system can address different attack types effectively without relying on a single source
2Reliability
If the system monitors and analyzes all incoming enterprise telemetry data in real-time, then it can identify targeted attacks, but the complexity and computational resources required increase significantly
Solution Approach 1:
The system performs preliminary summarization of enterprise telemetry data before detailed analysis. By pre-processing and summarizing potential indicators of compromise, the system reduces the volume of data requiring complex analysis while maintaining detection accuracy for targeted attacks
Solution Approach 2:
The patent introduces a summarization module as an intermediary between raw enterprise telemetry data and the campaign analysis engine. This intermediary processes and condenses telemetry data into meaningful summaries, reducing computational complexity while preserving critical security information
Data Source
AI summary
A system and method for detecting cyberattacks involves monitoring and analyzing incoming email received over the internet using enterprise telemetry; extracting observations from an enterprise telemetry data feeds and transmitting to a summarization module for summarizing a potential indicator of compromise pertaining to the email monitored and analyzed by the network telemetry; storing the observation summarization data in a graph database; querying over the internet an external cybersecurity threat intelligence provider, upon identification of a true-positive network threat, for enriching information and artifacts contained within the true-positive network threat, receiving over the internet enriching information and artifacts from the external cybersecurity threat intelligence provider, and storing the received enriching information and artifacts in the graph database; and identifying a new indicator of compromise using data stored in the graph database.


