Cognitive Security Rule Generation for Zero-Day Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Security Information and Event Management (SIEM) systems rely on manually created and static security rules that are not scalable and fail to detect unknown or 'Zero Day' threats, requiring constant tuning and are ineffective against emerging threats due to their reliance on known threat patterns.

Innovation Solution

A cognitive computing system that ingests natural language content and security event log data to identify attack characteristics, evaluates existing rules, and automatically generates new SIEM rules using machine learning and AI to adapt to emerging threats, dynamically updating and deploying them to monitored environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manually created static security rules are used in SIEM systems, then the system can detect known threat patterns, but the system cannot detect unknown or Zero Day threats and requires constant manual tuning

Engineering Contradiction:
Improvedetection capabilityVSAvoidadaptability to emerging threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transforms static security rules into dynamic rules that automatically adapt to emerging threats. The system continuously monitors security events, learns from new attack patterns, and automatically updates detection rules without manual intervention, enabling the system to evolve its detection capabilities over time while maintaining reliability for both known and unknown threats

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements self-service through automated rule generation and tuning mechanisms. The system autonomously analyzes security events, identifies new threat patterns, generates appropriate detection rules, and validates their effectiveness without requiring manual security analyst intervention, thereby improving adaptability while maintaining detection reliability

Inventive Principle:
Principle #25Self-service

2Ease of manufacture

If manual rule creation and management is performed, then security rules can be customized for specific requirements, but the process does not scale across different customer SIEM systems and requires constant upkeep

Engineering Contradiction:
Improverule customizationVSAvoidscalability
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The patent creates a universal rule management system that can automatically adapt to different customer SIEM systems regardless of industry, systems, log sources, or network topology. The automated rule generation engine produces universally applicable security rules that scale across diverse environments while maintaining the ability to customize for specific requirements through configuration parameters

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system eliminates the need for constant manual upkeep by implementing self-service automation. The rule management system automatically monitors effectiveness, tunes parameters, generates updates, and deploys rules across multiple customer environments without manual intervention, enabling scalability while preserving customization capabilities

Inventive Principle:
Principle #25Self-service

3Device complexity

If static security rules are used, then the rule life-cycle management is straightforward, but the rules are not valid or applicable to new threats and require constant review

Engineering Contradiction:
Improverule management complexityVSAvoidrule validity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent transforms the static rule life-cycle into a dynamic automated process. Rules are continuously validated against new security events, automatically tuned based on effectiveness metrics, and updated without manual review. This dynamic approach maintains rule validity for emerging threats while managing complexity through automation rather than increasing procedural complexity

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11012472B2Security rule generation based on cognitive and industry analysis
Publication Date: 2021.05.18 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11012472B2 patent drawing
  • US11012472B2 patent drawing
  • US11012472B2 patent drawing

AI summary

Security rules management mechanisms are provided. A cognitive computing system of the security rules management system ingests natural language content, from one or more corpora, describing features of security attacks, and ingests security event log data from a monitored computing environment. The cognitive computing system processes the natural language content from the one or more corpora and the security event log data to identify attack characteristics applicable to the security event log data. A security rule query engine evaluates existing security rules present in a security rules database to determine if any existing security rule addresses the attack characteristics. In response to the evaluation indicating that no existing security rule addresses the attack characteristics, a security rule generator automatically generates a new security rule based on the attack characteristics, which is then deployed to the monitored computing environment.