Ontology Mapping for Malware Analysis Standardization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cybersecurity systems face overwhelming amounts of threat analyses from diverse sources, making it difficult to identify semantically equivalent malware for effective mapping and analysis, leading to inefficiencies in threat detection and response.

Innovation Solution

An ontology mapping system that employs fuzzy string matching algorithms and reference dictionaries to evaluate and filter malware analyses, grouping similar threats and providing a standardized 'smart attribute' for improved threat intelligence sharing across organizations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security analysts manually analyze threat analyses from multiple sources, then threat detection accuracy may improve, but the workload and time required increase significantly

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidtime required for analysis
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical analysis with automated computational methods. The system uses fuzzy string matching algorithms and ontology mapping to automatically compare and group threat analyses from multiple sources, eliminating the need for manual review while maintaining detection accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs self-service by automatically ingesting, processing, and organizing threat analyses without human intervention. The automated ontology mapping system independently compares threats across sources, groups similar ones, and creates standardized outputs, freeing analysts from routine tasks.

Inventive Principle:
Principle #25Self-service

2Reliability

If security software processes large amounts of logs and events, then comprehensive security monitoring improves, but system usability deteriorates

Engineering Contradiction:
Improvesecurity monitoring coverageVSAvoidsoftware usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts meaningful patterns and groupings from the massive volume of logs and events. By using fuzzy string matching and ontology mapping, the system identifies and separates significant security events from noise, presenting only the relevant grouped information to users rather than overwhelming raw data.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system merges similar security events and threats from multiple sources into unified groups. This consolidation reduces the number of individual items users must review while maintaining comprehensive monitoring coverage, as related events are combined into single actionable intelligence items.

Inventive Principle:
Principle #5Merging (Combining)

3Quantity of substance

If threat analyses from multiple sources are collected, then threat intelligence comprehensiveness improves, but information organization difficulty increases

Engineering Contradiction:
Improvethreat intelligence volumeVSAvoidinformation organization complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent changes the organizational parameters of threat intelligence data by mapping all analyses to a standardized ontology structure. This transformation reorganizes the volume of information according to consistent categories and relationships, making the data manageable and queryable despite the increased quantity.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system creates a universal ontology framework that can organize threat intelligence from any source. This multi-functional mapping approach handles diverse data formats and sources through a single standardized structure, simplifying organization regardless of the volume or variety of incoming information.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If automated threat analysis systems are implemented, then processing speed improves, but accuracy in identifying semantically equivalent malware decreases

Engineering Contradiction:
Improveprocessing speedVSAvoidmalware identification accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent replaces simple automated string matching with sophisticated fuzzy string matching algorithms that account for semantic equivalence. This advanced computational method maintains high accuracy by understanding the meaning behind malware names and descriptions while processing at automated speeds.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system incorporates feedback mechanisms where the ontology mapping results are validated and refined. The fuzzy matching algorithm continuously learns from the context of threat analyses, improving its accuracy in identifying semantically equivalent malware over time while maintaining rapid processing.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20220141234A1Ontology Mapping System
Publication Date: 2022.05.05 SECURONIX INC
  • US20220141234A1 patent drawing
  • US20220141234A1 patent drawing
  • US20220141234A1 patent drawing

AI summary

An article of manufacture includes a non-transitory medium including machine-readable instructions. The instructions are to be read and executed by a processor. The instructions, when read and executed by the processor, to cause the processor to receive a malware analysis of a malware from a computer security source and receive other malware analyses. Each other malware analysis is of another malware from another computer security source. The instructions may further cause the processor to perform a fuzzy matching algorithm to quantify a similarity of the malware analyses, determine that the malware is a same malware as other malware based upon results of the fuzzy matching algorithm, and later take a same corrective action for malware based upon a receipt of the malware analysis.