Cyber Incident Log Mapping for Real-Time Report Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The creation of cyber incident reports is time-consuming and difficult due to the large volume of logs and lack of standardized training data, leading to inefficiencies in automating the process with artificial intelligence solutions.
Innovation Solution
A system that generates cyber incident reports by using a cyber incident log map that combines static and dynamic data to link logs to existing knowledge sources, allowing for real-time adaptation and standardization across different log formats and types.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual generation of cyber incident reports by subject matter experts is used, then report quality and accuracy are improved, but time consumption and cost increase significantly
Solution Approach 1:
The patent introduces an intermediary system comprising a log map generator and a report generator that acts as a mediator between raw cyber incident logs and final reports. The log map generator creates structured representations of logs with extracted characteristics, and the report generator uses these structured maps to automatically generate reports, thereby reducing manual intervention while maintaining quality through systematic processing
Solution Approach 2:
The patent applies preliminary action by pre-processing cyber incident logs into structured log maps before report generation. The system extracts characteristics, identifies patterns, and organizes log data into standardized formats in advance, creating ready-to-use structured representations that accelerate the subsequent report generation process while ensuring consistency
2Productivity
If artificial intelligence models are trained to generate cyber incident reports automatically, then productivity is improved, but the lack of standardized training data and large volume of logs create technical challenges
Solution Approach 1:
The patent segments the complex task of report generation into distinct components: log parsing, characteristic extraction, log map generation, and report synthesis. By dividing the large volume of logs into manageable segments and processing them through specialized modules, the system reduces overall complexity while maintaining high productivity through automated AI models
Solution Approach 2:
The patent transforms unstructured log data into structured representations by changing parameters such as extracting key characteristics, converting raw logs into standardized log maps with defined attributes, and transforming data formats. This parameter transformation simplifies the input for AI models, reducing processing complexity while enabling efficient automated report generation
3Measurement precision
If individual cyber incident reports are created manually for each log, then report accuracy is improved, but the large volume of logs makes the process expensive and time-consuming
Solution Approach 1:
The patent uses copying by creating standardized log map templates that can be reused across multiple logs. Once a log map structure is established for a particular type of cyber incident, it can be copied and adapted for similar logs, ensuring consistent accuracy through standardized processing while dramatically increasing productivity through template reuse rather than creating each report from scratch
Solution Approach 2:
The patent implements universality by designing a multi-functional report generation system that can handle various types of cyber incident logs through a single standardized framework. The log map generator and report generator are designed to process different log formats and types universally, maintaining accuracy through consistent processing rules while improving productivity by eliminating the need for separate manual processes for each log type
Data Source
AI summary
Systems and methods for the creation of human-readable cyber incident reports from cyber incident logs, in which the cyber incident reports may link cyber incidents recorded in a cyber incident log to the existing knowledge sources. To do so, the systems and methods overcome the technical problems of conventional systems as well as the technical problems inherent in adapting artificial intelligence solutions to the creation of cyber incident reports.


