Security Rule Tagging for Faster New Threat Coverage Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

SIEM and XDR systems struggle to adapt quickly to newly-identified threats, requiring manual and often outdated documentation review to update detection rules, lacking traceability and context for effective threat response.

Innovation Solution

A rules-based security system that uses a supervised Natural Language Processing (NLP) multi-label classifier to automatically generate and categorize rules with tags, determining existing rule coverage for new threats and recommending adjustments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If manual review of documentation and rules is performed to assess threat coverage, then traceability and context can be obtained, but time consumption and operational complexity increase significantly

Engineering Contradiction:
Improvetraceability and contextVSAvoidtime to assess threat coverage
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical review processes with an automated natural language processing system. The NLP-based classifier automatically analyzes rule documentation, extracts traceability information, and assesses threat coverage without human intervention, thereby eliminating time loss while preserving information quality.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service automation where the security operations team can independently assess new threats against existing rules through automated NLP analysis. The system serves itself by automatically generating coverage assessments, traceability chains, and context information without requiring manual documentation review.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If comprehensive manual analysis of rules and documentation is conducted, then accurate threat coverage assessment is achieved, but system complexity and resource requirements increase

Engineering Contradiction:
Improvethreat coverage assessment accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent substitutes complex manual analysis systems with an automated NLP-based classifier. This artificial intelligence system achieves comprehensive rule analysis and accurate threat coverage assessment without increasing operational system complexity, as the AI handles the analytical burden automatically.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The NLP-based classifier acts as an intermediary between the security rules documentation and the threat assessment process. It automatically extracts and analyzes relevant information, providing precise coverage assessments while shielding the overall system from the complexity of manual rule analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Stability of the object's composition

If existing rule sets are used without updates, then system stability is maintained, but detection capability for new threats decreases

Engineering Contradiction:
Improverule set stabilityVSAvoidthreat detection capability
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The patent implements a feedback mechanism where the NLP-based classifier continuously assesses new threats against existing rules and provides automated recommendations for rule updates. This feedback loop maintains system stability by preserving working rules while enabling adaptation when coverage gaps are identified, allowing the system to evolve without disruption.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system transitions from static rule sets to dynamic, adaptive rules. The automated classification and assessment enable rules to be updated based on emerging threats while maintaining stability for proven effective rules, creating a dynamic balance between stability and adaptability in the security rule set.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12495075B2Using categorization tags for rule generation and update in a rules-based security system
Publication Date: 2025.12.09 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12495075B2 patent drawing
  • US12495075B2 patent drawing
  • US12495075B2 patent drawing

AI summary

A technique for classifying and handling threat data in a rules-based security system. For each rule in the set, a set of one or more first tags are generated. The tags categorize the rule according to a hierarchical scheme. In response to receipt of a new threat, the system automatically determines whether the existing set of rules provide an acceptable coverage for the new threat. This determination is made by generating a set of one or more second tags that categorize the new threat, and then comparing the set of one or more second tags with the set of one or more first tags according to given match criteria. Upon a determination that the set of rules do not provide an adequate coverage for the new threat, a recommendation is output from the system. The rules-based security system is then adjusted according to the recommendation for subsequent handling of the new threat.