Semantic Cybersecurity Database for Threat Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in responding to cyber threats due to the overwhelming number of alerts, lack of cybersecurity knowledge, and the complexity of accessing and comprehending cybersecurity-related data stored in databases.

Innovation Solution

A semantic cybersecurity database is used, where user inputs are converted into command utterances, and through a Security Orchestration Automation and Response (SOAR) module, command nodes are resolved to action nodes, which are further resolved to parameter nodes, allowing users to execute actions with required parameter values to mitigate cyber threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If cybersecurity data are stored in traditional databases, then data storage capacity is sufficient, but data accessibility and comprehensibility deteriorate

Engineering Contradiction:
Improvecybersecurity data storage capacityVSAvoiddata accessibility and comprehensibility
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

A semantic cybersecurity database is introduced as an intermediary between traditional cybersecurity databases and users. This semantic database layer transforms and structures raw cybersecurity data into meaningful, easily accessible formats while preserving the full data capacity of underlying databases. The semantic database acts as a mediator that translates complex database contents into comprehensible information for end users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the number of cybersecurity alerts increases to cover more threats, then threat detection coverage is improved, but user response capability deteriorates due to alert overload

Engineering Contradiction:
Improvethreat detection coverageVSAvoiduser response capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system extracts and separates the complex task of alert analysis and response formulation from the user. By implementing an automated response system that processes alerts through a semantic cybersecurity database, the burden of analyzing overwhelming numbers of alerts is extracted from users and handled by the automated system, while users retain oversight and control.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The cybersecurity system enables self-service automation where the system automatically processes cybersecurity alerts, queries the semantic database for appropriate responses, and executes mitigation actions without requiring direct user intervention for each alert. This allows the system to handle high volumes of alerts autonomously while maintaining comprehensive threat detection.

Inventive Principle:
Principle #25Self-service

3Manufacturing precision

If cybersecurity products require detailed configuration knowledge, then mitigation precision is improved, but ease of use deteriorates for average users

Engineering Contradiction:
Improvemitigation precisionVSAvoidease of use
Core Design Contradiction:
Manufacturing precisionVSEase of operation

Solution Approach 1:

The semantic cybersecurity database pre-structures and pre-processes cybersecurity knowledge into organized semantic relationships before users need it. Configuration parameters, mitigation strategies, and response protocols are prepared in advance with proper semantic annotations, allowing the system to automatically assemble precise mitigation configurations without requiring users to manually configure complex security products.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11882148B1Automated mitigation of cyber threats using a semantic cybersecurity database
Publication Date: 2024.01.23 TREND MICRO INC
  • US11882148B1 patent drawing
  • US11882148B1 patent drawing
  • US11882148B1 patent drawing

AI summary

Systems and methods are presented for mitigating cyber threats. Cybersecurity-related data are stored in a semantic cybersecurity database. A user interface converts a user input to a command utterance. A command node that corresponds to the command utterance is identified in the cybersecurity database. The command node is resolved to one or more action nodes that are connected to the command node, and each action node is resolved to one or more parameter nodes that are connected to the action node. The command node has a command that implements actions indicated in the action nodes. Each action can have one or more required parameters indicated in the parameter nodes. The values of the required parameters are obtained from the command utterance, prompted from the user, or obtained from the cybersecurity database. Actions with their parameter values are executed to mitigate a cyber threat in accordance with the user input.