Enterprise Cybersecurity AI Platform for Anomaly-Based Threat Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cybersecurity systems, particularly Security Operations Centers (SOCs), face challenges in efficiently identifying and responding to cyber threats due to high false positive rates, inability to evolve over time, and reliance on veteran analysts, leading to scalability issues and high storage costs.

Innovation Solution

An enterprise cybersecurity AI platform that aggregates and processes cyber-related data using machine learning models to identify anomalies, classify threats, and automate responses, reducing false positives and enabling scalable, long-term storage of relevant data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If conventional SIEM systems are used to identify cyber threats, then descriptive value in tabular form is provided, but it is challenging and time-intensive for security analysts to extract useful information

Engineering Contradiction:
Improveuseful information extractionVSAvoidtime-intensive analysis
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent introduces an AI-based intermediary system that sits between the SIEM system and security analysts. This intermediary automatically processes, correlates, and prioritizes security events using machine learning models, transforming raw SIEM data into actionable insights without requiring manual analysis of tabular data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by allowing the AI models to autonomously perform threat detection, classification, and prioritization tasks that previously required human analysts. The automated generation of security insights and recommended actions allows the system to serve its own analytical needs without constant human intervention.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If veteran analysts' knowledge is used to filter noise and pull valuable insights, then valuable insights are obtained, but enterprises are vulnerable due to lack of scalability and knowledge transfer requirements

Engineering Contradiction:
Improveinsight accuracyVSAvoidscalability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent captures and codifies veteran analysts' expertise into AI models that can be replicated and deployed across multiple systems and organizations. Instead of relying on individual human knowledge, the system creates digital copies of analytical expertise that can be scaled indefinitely without degradation of insight quality.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system transforms qualitative analyst knowledge into quantifiable parameters and features that machine learning models can process. By converting expert judgment into measurable data points and patterns, the system enables scalable deployment while maintaining the precision of veteran analyst insights.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If machine learning models are used to identify anomalies and classify threats, then threat detection accuracy is enhanced, but system complexity increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent divides the complex threat detection system into modular components: separate machine learning models for anomaly detection, classification models for threat categorization, and prioritization models for risk assessment. Each module performs a specific function with well-defined inputs and outputs, making the overall system more manageable and maintainable despite its complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12413608B2Enterprise cybersecurity AI platform
Publication Date: 2025.09.09 C3 AI INC
  • US12413608B2 patent drawing
  • US12413608B2 patent drawing
  • US12413608B2 patent drawing

AI summary

A method includes obtaining data associated with operation of a monitored system. The method also includes using one or more first machine learning models to identify anomalies in the monitored system based on the obtained data, where each anomaly identifies an anomalous behavior. The method further includes using one or more second machine learning models to classify each of at least some of the identified anomalies into one of multiple classifications. Different ones of the classifications are associated with different types of cyberthreats to the monitored system, and the identified anomalies are classified based on risk scores determined using the one or more second machine learning models. In addition, the method includes identifying, for each of at least some of the anomalies, one or more actions to be performed in order to counteract the cyberthreat associated with the anomaly.