Malicious Indicator Rule Generation Across Multi-Vendor Threat Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems face challenges in analyzing the collective decision-making of multiple vendors due to differing naming conventions and classification schemes for threat detection, leading to threat analysis fatigue and increased computational complexity.

Innovation Solution

Implementing a method that tokenizes threat detections based on historical data, using self-generated rules to cluster threats across multiple vendors, with a lead detection and accuracy detections to reduce computational complexity and improve threat identification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple vendors implement their own threat detection engines with different naming conventions and classification schemes, then each vendor can detect threats independently, but it becomes difficult to analyze collective decision-making and increases computational complexity

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex multi-vendor threat detection problem into distinct components: individual vendor detection engines maintain their own naming conventions and classification schemes independently, while a separate normalization layer handles the mapping to common indicators. This segmentation allows each vendor to operate autonomously without being burdened by the complexity of reconciling multiple classification schemes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary normalization layer that acts as a mediator between multiple vendor-specific threat detection engines and the collective analysis system. This intermediary component translates and harmonizes different naming conventions and classification schemes into unified indicators, enabling efficient collective decision-making without requiring direct integration between all vendor systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If traditional threat detection methods are used without automated rule generation, then manual analysis can be performed, but it leads to threat analysis fatigue and reduced productivity

Engineering Contradiction:
Improvethreat identification accuracyVSAvoidanalysis throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements self-service through automated rule generation that enables the system to automatically create detection rules from historical threat data without requiring continuous manual intervention. The system learns from past threats and autonomously generates rules for identifying similar patterns, reducing analyst fatigue while maintaining high identification accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-processing and analyzing historical threat data to generate detection rules in advance. This preliminary analysis creates a foundation of learned patterns that accelerates future threat detection, allowing the system to quickly identify new threats by comparing them against pre-generated rules rather than requiring manual analysis from scratch.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive threat analysis is performed on all vendor data, then complete threat coverage is achieved, but processing power requirements increase significantly

Engineering Contradiction:
Improvethreat detection coverageVSAvoidprocessing power consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies partial action by selectively analyzing only the most relevant vendor data using automated rule-based filtering. Rather than comprehensively processing all vendor data, the system uses generated rules to identify and focus analysis on high-priority threats, achieving sufficient detection coverage while significantly reducing processing power consumption.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent changes the parameter of data analysis from comprehensive to targeted by dynamically adjusting which vendor data receives full analysis based on rule-based prioritization. The system transforms the processing approach by applying different levels of analysis depth to different data sets, maintaining reliable threat detection coverage while optimizing processing power utilization.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12627692B2Automatic rule generation for malicious indicators based on historical data
Publication Date: 2026.05.12 CROWDSTRIKE
  • US12627692B2 patent drawing
  • US12627692B2 patent drawing
  • US12627692B2 patent drawing

AI summary

Malicious indicators rule generation using historical data is provided. A method includes receiving, from threat detection engines of a plurality of vendor systems, a plurality of threat detection indications for a dataset. Each threat detection indication of the plurality of threat detection indications receives a vendor-specific tokenization based on historical data associated with the plurality of vendor systems. The method further includes identifying, from the plurality of threat detection indications, a lead detection from a first vendor system of the plurality of vendor systems and an accuracy detection from at least one second vendor system of the plurality of vendor systems. The lead detection and the accuracy detection have overlapping data from the dataset. The method further includes generating, by a processing device, a malicious behavior detection procedure based on the lead detection, the accuracy detection, and the vendor-specific tokenization being used to detect a malicious behavior in dataset.