Security Rule Tagging for Faster New Threat Coverage Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
SIEM and XDR systems struggle to adapt quickly to newly-identified threats, requiring manual and often outdated documentation review to update detection rules, lacking traceability and context for effective threat response.
Innovation Solution
A rules-based security system that uses a supervised Natural Language Processing (NLP) multi-label classifier to automatically generate and categorize rules with tags, determining existing rule coverage for new threats and recommending adjustments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If manual review of documentation and rules is performed to assess threat coverage, then traceability and context can be obtained, but time consumption and operational complexity increase significantly
Solution Approach 1:
The patent replaces manual mechanical review processes with an automated natural language processing system. The NLP-based classifier automatically analyzes rule documentation, extracts traceability information, and assesses threat coverage without human intervention, thereby eliminating time loss while preserving information quality.
Solution Approach 2:
The system enables self-service automation where the security operations team can independently assess new threats against existing rules through automated NLP analysis. The system serves itself by automatically generating coverage assessments, traceability chains, and context information without requiring manual documentation review.
2Measurement precision
If comprehensive manual analysis of rules and documentation is conducted, then accurate threat coverage assessment is achieved, but system complexity and resource requirements increase
Solution Approach 1:
The patent substitutes complex manual analysis systems with an automated NLP-based classifier. This artificial intelligence system achieves comprehensive rule analysis and accurate threat coverage assessment without increasing operational system complexity, as the AI handles the analytical burden automatically.
Solution Approach 2:
The NLP-based classifier acts as an intermediary between the security rules documentation and the threat assessment process. It automatically extracts and analyzes relevant information, providing precise coverage assessments while shielding the overall system from the complexity of manual rule analysis.
3Stability of the object's composition
If existing rule sets are used without updates, then system stability is maintained, but detection capability for new threats decreases
Solution Approach 1:
The patent implements a feedback mechanism where the NLP-based classifier continuously assesses new threats against existing rules and provides automated recommendations for rule updates. This feedback loop maintains system stability by preserving working rules while enabling adaptation when coverage gaps are identified, allowing the system to evolve without disruption.
Solution Approach 2:
The system transitions from static rule sets to dynamic, adaptive rules. The automated classification and assessment enable rules to be updated based on emerging threats while maintaining stability for proven effective rules, creating a dynamic balance between stability and adaptability in the security rule set.
Data Source
AI summary
A technique for classifying and handling threat data in a rules-based security system. For each rule in the set, a set of one or more first tags are generated. The tags categorize the rule according to a hierarchical scheme. In response to receipt of a new threat, the system automatically determines whether the existing set of rules provide an acceptable coverage for the new threat. This determination is made by generating a set of one or more second tags that categorize the new threat, and then comparing the set of one or more second tags with the set of one or more first tags according to given match criteria. Upon a determination that the set of rules do not provide an adequate coverage for the new threat, a recommendation is output from the system. The rules-based security system is then adjusted according to the recommendation for subsequent handling of the new threat.


