Generative Security Deficiency Tagging for Unstructured Threat Text

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Extended Detection and Response (XDR) systems face challenges in effectively tagging security deficiencies for automated and expedited response and remediation due to the lack of efficient methods for correlating unstructured threat data with standardized labels.

Innovation Solution

Utilizing a generative machine learning model to process unstructured text data associated with security deficiencies, such as CVE identifiers, to generate and validate tags like stride categories, attack techniques, and vulnerabilities, enabling rapid adaptation to new threats without retraining.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If traditional methods are used to tag security deficiencies, then the process is manual and error-prone, but the system lacks speed and automation capability

Engineering Contradiction:
Improveautomation of tagging processVSAvoidtime for threat response
Core Design Contradiction:
Extent of automationVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical tagging processes with an automated machine learning system that uses natural language processing to extract and assign security deficiency tags. The ML model automatically processes threat intelligence data, vulnerability descriptions, and security events to generate tags without human intervention, eliminating the manual mechanical system while maintaining accuracy and significantly reducing time loss.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If standardized tagging methods are implemented, then automated response is enabled, but the system cannot adapt to new and emerging threats

Engineering Contradiction:
Improveadaptability to new threatsVSAvoidaccuracy of threat classification
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a dynamic tagging system where the machine learning model continuously learns from new threat intelligence data, vulnerability patterns, and security events. The system adapts its tagging criteria and classifications based on emerging threat patterns while maintaining standardized tag structures. This dynamic adaptation allows the system to handle new threats reliably without sacrificing classification accuracy, as the model is retrained and fine-tuned on current threat landscapes.

Inventive Principle:
Principle #15Dynamics

3Productivity

If manual tagging processes are used, then flexibility in handling diverse threat data is maintained, but productivity and response speed are reduced

Engineering Contradiction:
Improvespeed of threat detection and responseVSAvoidcomplexity of tagging system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent creates a universal machine learning-based tagging system that handles multiple types of threat data (vulnerability descriptions, threat intelligence reports, security logs, exploit code) through a single automated platform. The system uses natural language processing and pattern recognition to universally process diverse data formats and assign appropriate tags, eliminating the need for separate manual processes for different data types while maintaining flexibility through configurable tag schemas and continuous learning capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12554861B2Text-based tagging of security deficiencies using generative machine learning models
Publication Date: 2026.02.17 CISCO TECHNOLOGY INC
  • US12554861B2 patent drawing
  • US12554861B2 patent drawing
  • US12554861B2 patent drawing

AI summary

Techniques for determining a tag for a security deficiency (e.g., a security vulnerability and/or exposure) using a generative machine learning model. In examples, a system may perform the following operations: (i) identifying a deficiency identifier associated with the security deficiency, (ii) retrieving one or more texts that correspond to the deficiency identifier, (iii) generating a prompt for a generative model to process the text(s) to detect a tag, (iv) providing the prompt to the generative machine learning model, (v) receiving the output of the machine learning model, (vi) determine whether the output satisfies one or more output constraints (e.g., one or more output constraints specified by format and/or content requirements specified in the prompt), and (vii) if the output satisfies the output constraint(s), determine the tag based on the validated output.