At-Risk System Identification with CPE-Guided Hacker Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for identifying at-risk systems rely heavily on the CVSS score and CVE-mentioned discussions, failing to account for hacker discussions without CVE numbers and lacking precision in identifying vulnerable systems of interest to threat actors.

Innovation Solution

A hybrid reasoning framework combining DeLP with machine learning classifiers, using threat intelligence from darkweb forums and marketplaces to analyze hacker discussions, constraining machine learning models with defeasible argumentation to reduce label choices and provide explainable results.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If keyword based queries are used to identify threats from hacker interactions, then the system can extract products mentioned in descriptions, but it fails to identify targeted systems not explicitly stated in forum discussions

Engineering Contradiction:
Improveinformation about targeted systemsVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent introduces CPE (Common Platform Enumeration) hierarchy as an intermediary knowledge base that connects hacker forum discussions to targeted systems. The system uses the CPE hierarchy structure (platform→vendor→product) as a mediator to infer targeted systems from discussion content, even when systems are not explicitly mentioned. This resolves the contradiction by adding a structured intermediate layer that bridges the gap between unstructured forum text and specific system identification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces simple keyword-based extraction with a machine learning-based classification system that leverages the CPE hierarchy. Instead of relying on explicit keyword matches, the system uses trained classifiers to infer targeted systems from discussion context, substituting mechanical keyword searching with intelligent pattern recognition and classification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If CVE number mentions are required to identify at-risk systems, then the system can leverage existing vulnerability databases, but it misses discussions without vulnerability identifiers that are of interest to threat actors

Engineering Contradiction:
Improveaccuracy of vulnerability identificationVSAvoidthreat intelligence from uncve discussions
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent performs preliminary action by pre-building the CPE hierarchy knowledge base and training machine learning classifiers on available data before analyzing hacker forum discussions. This preparation enables the system to handle both CVE-mentioned and non-CVE discussions effectively, as the classification models are already trained to recognize patterns and map discussions to CPE identifiers without requiring explicit CVE numbers in the input text.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If machine learning models are used to identify at-risk systems, then the system can handle large volumes of data, but it produces misclassifications especially for less-represented vendors and products

Engineering Contradiction:
Improveprocessing capacityVSAvoididentification accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The CPE hierarchy acts as a mediator that structures the output space of machine learning classifiers. By organizing vendors and products in a hierarchical framework (platform→vendor→product), the system provides structured guidance to classifiers, reducing misclassifications for less-represented entities. The hierarchy serves as a constraint and guide for predictions, improving precision while maintaining high processing capacity.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Loss of information

If the system analyzes all hacker discussions without constraints, then it can capture comprehensive threat intelligence, but it generates excessive false positives and reduces analyst efficiency

Engineering Contradiction:
Improvecompleteness of threat intelligenceVSAvoidanalyst review time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent applies local quality by differentiating the processing and attention given to different types of discussions based on their characteristics. The system uses the CPE hierarchy and machine learning classifiers to identify and prioritize high-risk discussions, applying more rigorous analysis locally to suspicious cases while filtering out low-risk content. This selective approach maintains comprehensive threat intelligence capture while reducing false positives that would consume analyst time.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12380221B2Systems and methods for an at-risk system identification via analysis of online hacker community discussions
Publication Date: 2025.08.05 SECURIN INC
  • US12380221B2 patent drawing
  • US12380221B2 patent drawing
  • US12380221B2 patent drawing

AI summary

Various embodiments of systems and methods for an at-risk system identification via analysis of discussions from various online hacker communities are disclosed herein.