IOC Aggregation for Network Security Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security systems face challenges in detecting and eliminating advanced security threats due to lack of visibility and requiring manual analysis of individual findings from multiple security devices, leading to increased costs and decreased incident resolution efficiency.

Innovation Solution

A method and apparatus that aggregate indicators of compromise (IOCs) from multiple security devices, sorting them by time of occurrence, creating a representation of transitions, and generating a feature vector to identify malicious entities, enabling automatic classification and reconstruction of attack vectors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual analysis of individual findings from multiple security devices is performed, then detection accuracy is improved, but analysis cost and time consumption increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent combines multiple individual security device findings into a unified analysis by aggregating indicators of compromise (IOCs) from different sources. The system merges IOCs from multiple security devices, sorts them by time of occurrence, and creates a comprehensive representation that captures the complete attack vector, eliminating the need for separate manual analysis of each finding.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an intermediary aggregation system that processes IOCs from multiple security devices. This intermediary layer automatically sorts IOCs by time, creates transition representations, and generates feature vectors that feed into classification models, serving as a mediator between raw security data and final detection results.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If manual analysis of individual findings from multiple security devices is performed, then detection accuracy is improved, but operational complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidoperational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges the complex operational tasks of analyzing multiple security device findings into a single automated aggregation process. By combining IOCs from various sources and processing them through a unified sorting and representation framework, the system reduces operational complexity while maintaining comprehensive analysis capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements self-service automation where the system automatically aggregates, sorts, and processes IOCs without requiring manual intervention. The automated generation of transition representations and feature vectors, along with automatic classification, enables the system to serve itself, eliminating complex manual operational requirements.

Inventive Principle:
Principle #25Self-service

3Reliability

If comprehensive analysis of attack vectors is performed, then threat detection quality is improved, but processing cost increases

Engineering Contradiction:
Improvethreat detection qualityVSAvoidprocessing cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts only the essential features from comprehensive IOC data by generating condensed feature vectors that capture the critical characteristics of attack vectors. This extraction process maintains high detection quality by preserving important transition patterns while removing redundant information, thereby reducing processing costs.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transforms raw IOC data into different parameter representations through sorting by time of occurrence, creating transition representations, and generating feature vectors. These parameter changes enable more efficient processing while maintaining the ability to detect threats accurately, as the transformed data is better suited for classification algorithms.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9985982B1Method and apparatus for aggregating indicators of compromise for use in network security
Publication Date: 2018.05.29 CISCO TECHNOLOGY INC
  • US9985982B1 patent drawing
  • US9985982B1 patent drawing
  • US9985982B1 patent drawing

AI summary

In one embodiment, a method includes receiving at a security analysis device a plurality of indicators of compromise (IOCs) associated with an entity, sorting at the security analysis device, the IOCs based on a time of occurrence of each of the IOCs, creating a representation of transitions between the IOCs at the security analysis device, and generating at the security analysis device, a feature vector based on the representation of transitions. The feature vector is configured for use by a classifier in identifying malicious entities. An apparatus and logic are also disclosed herein.