Malicious Indicator Rule Generation Across Multi-Vendor Threat Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security systems face challenges in analyzing the collective decision-making of multiple vendors due to differing naming conventions and classification schemes for threat detection, leading to threat analysis fatigue and increased computational complexity.
Innovation Solution
Implementing a method that tokenizes threat detections based on historical data, using self-generated rules to cluster threats across multiple vendors, with a lead detection and accuracy detections to reduce computational complexity and improve threat identification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple vendors implement their own threat detection engines with different naming conventions and classification schemes, then each vendor can detect threats independently, but it becomes difficult to analyze collective decision-making and increases computational complexity
Solution Approach 1:
The patent segments the complex multi-vendor threat detection problem into distinct components: individual vendor detection engines maintain their own naming conventions and classification schemes independently, while a separate normalization layer handles the mapping to common indicators. This segmentation allows each vendor to operate autonomously without being burdened by the complexity of reconciling multiple classification schemes.
Solution Approach 2:
The patent introduces an intermediary normalization layer that acts as a mediator between multiple vendor-specific threat detection engines and the collective analysis system. This intermediary component translates and harmonizes different naming conventions and classification schemes into unified indicators, enabling efficient collective decision-making without requiring direct integration between all vendor systems.
2Measurement precision
If traditional threat detection methods are used without automated rule generation, then manual analysis can be performed, but it leads to threat analysis fatigue and reduced productivity
Solution Approach 1:
The patent implements self-service through automated rule generation that enables the system to automatically create detection rules from historical threat data without requiring continuous manual intervention. The system learns from past threats and autonomously generates rules for identifying similar patterns, reducing analyst fatigue while maintaining high identification accuracy.
Solution Approach 2:
The patent applies preliminary action by pre-processing and analyzing historical threat data to generate detection rules in advance. This preliminary analysis creates a foundation of learned patterns that accelerates future threat detection, allowing the system to quickly identify new threats by comparing them against pre-generated rules rather than requiring manual analysis from scratch.
3Reliability
If comprehensive threat analysis is performed on all vendor data, then complete threat coverage is achieved, but processing power requirements increase significantly
Solution Approach 1:
The patent applies partial action by selectively analyzing only the most relevant vendor data using automated rule-based filtering. Rather than comprehensively processing all vendor data, the system uses generated rules to identify and focus analysis on high-priority threats, achieving sufficient detection coverage while significantly reducing processing power consumption.
Solution Approach 2:
The patent changes the parameter of data analysis from comprehensive to targeted by dynamically adjusting which vendor data receives full analysis based on rule-based prioritization. The system transforms the processing approach by applying different levels of analysis depth to different data sets, maintaining reliable threat detection coverage while optimizing processing power utilization.
Data Source
AI summary
Malicious indicators rule generation using historical data is provided. A method includes receiving, from threat detection engines of a plurality of vendor systems, a plurality of threat detection indications for a dataset. Each threat detection indication of the plurality of threat detection indications receives a vendor-specific tokenization based on historical data associated with the plurality of vendor systems. The method further includes identifying, from the plurality of threat detection indications, a lead detection from a first vendor system of the plurality of vendor systems and an accuracy detection from at least one second vendor system of the plurality of vendor systems. The lead detection and the accuracy detection have overlapping data from the dataset. The method further includes generating, by a processing device, a malicious behavior detection procedure based on the lead detection, the accuracy detection, and the vendor-specific tokenization being used to detect a malicious behavior in dataset.


