Automated Cyber Threat Detection Using Indicator Contextualization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise-level information technology networks face challenges in rapidly and accurately identifying malicious cyberactivity from indicators of compromise, as such indicators often require extensive investigation and may include false positives or innocent activity.
Innovation Solution
A computer-implemented system and method that processes information representing indicators of compromise for automatic cyberthreat assessment and remediation. This involves identifying a subset of indicators, generating requests for contextual information, receiving structured data records, determining malicious cyberthreats, and taking remedial action.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual analysis of indicators of compromise is performed, then accuracy of cyberthreat identification is improved, but time required for analysis increases
Solution Approach 1:
The system performs self-service by automatically analyzing indicators of compromise and generating contextual information without requiring manual intervention. The processor automatically queries databases, retrieves structured data records, and identifies malicious cyberactivity, eliminating the need for human analysts to manually investigate each indicator while maintaining high accuracy through automated pattern recognition and contextualization.
Solution Approach 2:
The patent replaces the mechanical manual analysis process with an automated electronic system. Instead of human analysts manually reviewing indicators, the system uses processors to automatically query databases, retrieve contextual information from multiple sources, and identify threats through programmed algorithms, substituting human cognitive processing with automated computational mechanisms.
2Reliability
If extensive investigation of indicators of compromise is conducted, then reliability of cyberthreat determination is improved, but productivity of security operations decreases
Solution Approach 1:
The system performs preliminary action by pre-querying databases and retrieving structured data records before final threat determination. Contextual information is gathered in advance from multiple data sources, allowing the system to make reliable determinations about malicious cyberactivity without requiring extensive real-time investigation, thus maintaining both reliability and productivity.
Solution Approach 2:
The patent introduces an intermediary system that bridges the gap between raw indicators of compromise and final threat determinations. This intermediary layer automatically queries databases, retrieves contextual information, and processes data from multiple sources, enabling reliable threat determination without requiring direct extensive human investigation of each indicator.
3Measurement precision
If contextual information is retrieved from multiple data sources, then accuracy of cyberactivity assessment is improved, but device complexity increases
Solution Approach 1:
The system achieves universality by using a single integrated processor that performs multiple functions: querying databases, retrieving contextual information from multiple data sources, processing structured data records, and identifying malicious cyberactivity. This multi-functional approach consolidates what would otherwise require multiple separate systems into one unified platform, maintaining high assessment accuracy while managing complexity through functional integration.
Data Source
AI summary
A computer-implemented system and method are provided for processing information representing indicators of compromise for automatic cyberthreat assessment and remediation. Processor(s) automatically access information representing indicators of compromise and can further identify a subset of at least some of the information representing the indicators of compromise. The processor(s) generate, using the identified subset, a request for contextual information and, thereafter, transmit the request. The processor(s) further receive, from the database in response to the request, a plurality of structured data records including the contextual information. The processor(s) can determine that at least one of the structured data records includes contextual information associated with a malicious cyberthreat. The processor(s) can output information representing the contextual information included in the structured data record(s) and the indicators of compromise associated with the at least some of the data records, as well as take remedial action using the output information.


