Cyber Threat Identification Analytics for Malware IOC Grouping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Incident responders face difficulties in identifying and managing cyber threats due to the vast number of malware variants, making it impractical to manually inspect each for potential threats, which delays response times and increases the risk of damage during cyber-security incidents.

Innovation Solution

The Cyber Threat Identification and Analytics (CTIA) system automatically identifies and compiles a list of relevant indicators of compromise (IOCs) by analyzing behavioral malware data, grouping statistically relevant IOCs without human intervention, allowing for quicker threat identification and remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual inspection of each malware variant is performed, then threat identification accuracy is improved, but response time increases and productivity decreases

Engineering Contradiction:
Improvethreat identification accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system creates a virtual copy of the malware analysis process by using behavioral malware data and indicators of compromise (IOCs) to represent actual malware threats. Instead of manually inspecting each malware variant, the system analyzes copied behavioral patterns and IOCs from previously detected malware, enabling rapid identification of new threats without direct manual inspection of each variant.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system introduces an intermediary layer of behavioral malware data and IOCs between the manual inspection process and the actual malware variants. This intermediary contains aggregated threat information that can be quickly analyzed to identify new malware, serving as a mediator that enables fast response while maintaining identification accuracy through comprehensive threat data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If manual inspection of each malware variant is performed, then threat identification accuracy is improved, but the workload and complexity increase

Engineering Contradiction:
Improvethreat identification accuracyVSAvoidworkload complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system extracts essential threat information from the complex malware variants by isolating behavioral patterns and IOCs. This extraction process removes unnecessary complexity while retaining the critical identification features, allowing analysts to focus only on the extracted IOCs rather than the full complexity of each malware variant.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system segments the malware analysis task into separate components: behavioral malware data collection, IOC extraction, and threat identification. This segmentation divides the complex workload into manageable segments that can be processed independently and automatically, reducing overall complexity while maintaining identification accuracy.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If comprehensive malware data is collected and analyzed, then threat identification accuracy is improved, but the time required for analysis increases

Engineering Contradiction:
Improvethreat identification accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-collecting and pre-processing behavioral malware data and extracting IOCs before actual threat identification is needed. This preliminary preparation creates a ready-to-use database of threat indicators that can be quickly queried and analyzed, eliminating the need for time-consuming real-time analysis of comprehensive malware data during incident response.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9584541B1Cyber threat identification and analytics apparatuses, methods and systems
Publication Date: 2017.02.28 LOOKINGGLASS CYBER SOLUTIONS LLC
  • US9584541B1 patent drawing
  • US9584541B1 patent drawing
  • US9584541B1 patent drawing

AI summary

The cyber threat identification and analytics (“CTIA”) apparatuses, methods and systems, for example, identify a list of relevant malware indicators of compromise (IOCs) during a cyber security incident. The CTIA system automatically groups relevant malware IOCs from all known samples of a particular threat, given either a threat or a specific IOC without knowing the threat. In this way, an incident responder can use the group of relevant malware IOCs to have the highest probability of locating infections of variations of malware of the particular threat.