Cyber Credential Clustering for Proactive Exposure Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems struggle to effectively protect digital assets that are rapidly changing and accessible through both private and public networks, often failing to identify potential exposures due to the pace of asset changes and reliance on internal information.

Innovation Solution

A method for clustering cyber credentials using similarity scores, digital tagging, and generating data structures to identify and manage cybersecurity exposures, employing AI-based predictive techniques to proactively detect and respond to potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional access restrictions and internal digital information are used to protect digital assets, then implementation is straightforward, but detection precision and response effectiveness deteriorate due to rapid asset changes and limited scope

Engineering Contradiction:
Improveexposure detection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges multiple data sources including internal digital information, leaked credential datasets, and external exposure information into a unified credential clustering system. This combination enables comprehensive exposure detection across diverse asset types while maintaining manageable complexity through automated processing pipelines.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary clustering of cyber credentials using similarity scores before actual security incidents occur. By pre-organizing credentials into clusters and identifying potential exposures in advance, the system enables proactive security responses rather than reactive measures after breaches.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive credential analysis is performed on all digital assets, then exposure detection capability improves, but processing time and computational resources increase

Engineering Contradiction:
Improvesecurity protection reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the credential analysis process into distinct phases: initial clustering using similarity scores, supplemental credential generation, secondary clustering, and exposure identification. This segmentation allows the system to process credentials efficiently in manageable stages rather than analyzing all assets simultaneously, reducing overall processing time while maintaining comprehensive coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs partial analysis by focusing computational resources on credential clusters that show higher similarity scores or potential exposure indicators. Rather than uniformly analyzing all credentials with equal depth, the system applies varying levels of analysis based on risk indicators, optimizing the balance between reliability and processing efficiency.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If manual security management approaches are used, then system complexity is low, but productivity and response speed to cyber threats deteriorate

Engineering Contradiction:
Improvesecurity response productivityVSAvoidautomation level
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The credential clustering system operates autonomously, automatically gathering credentials from multiple sources, computing similarity scores, forming clusters, generating supplemental credentials, and identifying exposures without continuous manual intervention. This self-service automation dramatically improves security productivity by continuously monitoring and responding to threats without requiring constant human oversight.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback loops where clustering results and exposure identifications feed back into refined credential analysis. The automated system uses identified exposures to adjust clustering parameters and focus subsequent analysis on high-risk areas, continuously improving detection accuracy and response effectiveness through iterative automated processes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12423406B1Techniques, machine intelligence, and mechanisms for suspicious entity clustering using credential information
Publication Date: 2025.09.23 MALANTAI LTD
  • US12423406B1 patent drawing
  • US12423406B1 patent drawing
  • US12423406B1 patent drawing

AI summary

Disclosed herein are techniques for clustering cyber credential information. Techniques include aggregating a plurality of cyber credentials; computing similarity scores for pairs of the cyber credentials; clustering at least a subset of the cyber credentials into a plurality of cyber credential clusters based on the computed similarity scores; digitally tagging the cyber credential clusters with suspicious entity information; and generating a data structure of the digitally tagged cyber credential clusters.