Narrative Cyber Threat Display for Security Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cyber threat data in serialized formats lacks context, making it difficult for security teams to understand the relationships between objects and assess the severity and scope of security incidents, leading to inefficient decision-making and potential human errors.
Innovation Solution
A method and system for displaying cyber threat data in a narrative format using a hierarchical structure, which generates a user interface to present relationships between parent and child objects with context information, reducing the need for manual analysis and improving data understanding.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If cyber threat data is presented in serialized format, then data storage efficiency is improved, but data understanding and analysis efficiency deteriorate
Solution Approach 1:
The patent introduces an intermediary processing layer that converts serialized threat data into a narrative format with contextual relationships. This intermediary transformation enables analysts to understand threat data without sacrificing storage efficiency, as the narrative representation is generated on-demand from the compact serialized source.
Solution Approach 2:
The patent segments threat data into hierarchical objects with defined relationships (parent-child structures). By organizing data into discrete, relationship-defined segments rather than flat serialized streams, the system maintains storage efficiency while enabling efficient contextual analysis through the structured object model.
2Loss of information
If cyber threat data is enriched with context information, then threat intelligence quality is improved, but data complexity increases
Solution Approach 1:
The patent adds a dimensional layer of contextual relationships to threat data by introducing parent-child object relationships. This dimensional enrichment provides threat context without creating unmanageable complexity, as the relationships are structured in a hierarchical framework that maintains organizational clarity.
Solution Approach 2:
The patent changes the structural parameters of threat data from flat serialized format to hierarchical object format with contextual attributes. This parameter transformation enables rich threat intelligence while managing complexity through standardized object definitions and relationship types.
3Adaptability or versatility
If manual analysis of serialized threat data is performed, then data processing flexibility is maintained, but analyst productivity decreases
Solution Approach 1:
The patent performs preliminary organization of threat data into hierarchical objects with defined relationships before presentation to analysts. This preliminary structuring maintains analytical flexibility while dramatically improving productivity, as the data is pre-organized into meaningful contexts that reduce manual parsing requirements.
Solution Approach 2:
The patent creates a narrative format copy of the serialized threat data that preserves the original information while adding contextual relationships. This copied representation enables efficient analysis without losing the flexibility to query and analyze the original serialized data structure when needed.
Data Source
AI summary
A mechanism is provided in a data processing system for displaying cyber threat data in a narrative format. The mechanism receives a cyber threat information file that comprises cyber threat data in a serialized format. The mechanism generates a user interface presenting the cyber threat data in a narrative format. The user interface presents objects in the cyber threat data in a hierarchical format indicative of relationships between parent objects and child objects and presents context information for each object. The mechanism presents the user interface to an analyst.


