Dynamic Cyber Event Analysis Using Machine Learning Linkages

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems for identifying and mitigating cyber threats are inefficient and time-consuming, as they rely solely on indicators of compromise (IOCs) without effectively evaluating linkages or predicting future threats, leading to delayed response times and increased risk.

Innovation Solution

A system utilizing machine learning to parse and evaluate IOC data, identify associated parameters, and dynamically generate blocks to prevent access to potentially harmful items, such as websites or IP addresses, by analyzing linkages in real-time or near real-time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional systems manually evaluate each IOC and associated parameters to identify related threats, then comprehensive threat identification is achieved, but the process becomes time consuming and inefficient

Engineering Contradiction:
Improvethreat identification accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical evaluation of IOC parameters with machine learning algorithms that automatically analyze and identify threat linkages. The ML system processes IOC data, evaluates parameters, and identifies related threats without human intervention, thereby maintaining comprehensive identification accuracy while dramatically reducing response time.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces machine learning models as an intermediary between raw IOC data and threat identification outcomes. The ML system acts as a mediator that automatically processes IOC parameters, identifies linkages, and generates threat assessments, eliminating the need for manual evaluation while preserving comprehensive analysis capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If conventional systems identify only basic IOCs without evaluating linkages, then processing speed is maintained, but the ability to identify related threats and predict future potential threats is insufficient

Engineering Contradiction:
Improveprocessing speedVSAvoidthreat identification completeness
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent applies preliminary action by using machine learning to pre-evaluate IOC parameters and identify potential linkages before threats fully manifest. The system proactively analyzes IOC data, predicts future potential threats based on identified patterns and linkages, and prepares responses in advance, thereby maintaining processing speed while enhancing threat identification completeness.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If manual evaluation methods are used to assess IOC parameters, then detailed analysis is possible, but the system becomes error prone and cannot provide fast enough response time

Engineering Contradiction:
Improveparameter evaluation accuracyVSAvoidsystem reliability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent replaces error-prone manual evaluation with automated machine learning systems that consistently assess IOC parameters without human errors. The ML models provide reliable, reproducible evaluations of IOC parameters and linkage identification, eliminating variability and errors associated with manual analysis while maintaining detailed analysis capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11012448B2Dynamic cyber event analysis and control
Publication Date: 2021.05.18 BANK OF AMERICA CORP
  • US11012448B2 patent drawing
  • US11012448B2 patent drawing
  • US11012448B2 patent drawing

AI summary

Systems for analyzing and controlling cyber events are provided. In some examples, indicator or compromise (IOC) data may be received. The system may parse the data to identify one or more IOC parameters within the IOC data. In some examples, the IOC parameters may be compared to known IOC parameters to determine whether the IOC parameters are known. If not, the newly identified IOC parameters may be stored in a database. The identified IOC parameters may be evaluated to identify one or more linkages associated with the IOC parameters. For instance, each IOC parameters may be evaluated to identify one or more other parameters associated with each parameter. Those linkages may indicate a threat or potential threat. Based on the evaluation, the system may generate, update and/or execute one or more blocks. For instance, access to one or more domain name, email address, or the like, may be locked based on the identified IOC parameters, linkages, and the like.