Narrative Cyber Threat Display for Security Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cyber threat data in serialized formats lacks context, making it difficult for security teams to understand the relationships between objects and assess the severity and scope of security incidents, leading to inefficient decision-making and potential human errors.

Innovation Solution

A method and system for displaying cyber threat data in a narrative format using a hierarchical structure, which generates a user interface to present relationships between parent and child objects with context information, reducing the need for manual analysis and improving data understanding.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If cyber threat data is presented in serialized format, then data storage efficiency is improved, but data understanding and analysis efficiency deteriorate

Engineering Contradiction:
Improvedata storage efficiencyVSAvoiddata analysis time
Core Design Contradiction:
Quantity of substanceVSLoss of time

Solution Approach 1:

The patent introduces an intermediary processing layer that converts serialized threat data into a narrative format with contextual relationships. This intermediary transformation enables analysts to understand threat data without sacrificing storage efficiency, as the narrative representation is generated on-demand from the compact serialized source.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments threat data into hierarchical objects with defined relationships (parent-child structures). By organizing data into discrete, relationship-defined segments rather than flat serialized streams, the system maintains storage efficiency while enabling efficient contextual analysis through the structured object model.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If cyber threat data is enriched with context information, then threat intelligence quality is improved, but data complexity increases

Engineering Contradiction:
Improvethreat context informationVSAvoiddata structure complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent adds a dimensional layer of contextual relationships to threat data by introducing parent-child object relationships. This dimensional enrichment provides threat context without creating unmanageable complexity, as the relationships are structured in a hierarchical framework that maintains organizational clarity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent changes the structural parameters of threat data from flat serialized format to hierarchical object format with contextual attributes. This parameter transformation enables rich threat intelligence while managing complexity through standardized object definitions and relationship types.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If manual analysis of serialized threat data is performed, then data processing flexibility is maintained, but analyst productivity decreases

Engineering Contradiction:
Improveanalysis flexibilityVSAvoidanalyst productivity
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent performs preliminary organization of threat data into hierarchical objects with defined relationships before presentation to analysts. This preliminary structuring maintains analytical flexibility while dramatically improving productivity, as the data is pre-organized into meaningful contexts that reduce manual parsing requirements.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a narrative format copy of the serialized threat data that preserves the original information while adding contextual relationships. This copied representation enables efficient analysis without losing the flexibility to query and analyze the original serialized data structure when needed.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12086261B2Displaying cyber threat data in a narrative-like format
Publication Date: 2024.09.10 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12086261B2 patent drawing
  • US12086261B2 patent drawing
  • US12086261B2 patent drawing

AI summary

A mechanism is provided in a data processing system for displaying cyber threat data in a narrative format. The mechanism receives a cyber threat information file that comprises cyber threat data in a serialized format. The mechanism generates a user interface presenting the cyber threat data in a narrative format. The user interface presents objects in the cyber threat data in a hierarchical format indicative of relationships between parent objects and child objects and presents context information for each object. The mechanism presents the user interface to an analyst.