STIX Analytics Engine for Automated Security Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IT infrastructures face challenges in securely analyzing externally downloaded data, which can pose security threats or incidents, requiring advanced data science expertise and resources to assess workflows and identify potential threats or incidents.

Innovation Solution

A method and system that utilizes Structured Threat Information eXpression (STIX) formatted data for automated analysis, converting it into Machine Learning (ML) or Artificial Intelligence (AI) readable formats, creating tasks for workflows, and executing them on various platforms to visualize security threat or incident analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manually analyzed downloaded data to assess security threats, then analysis accuracy is improved, but analysis time and resource requirements increase

Engineering Contradiction:
Improvesecurity threat detection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical analysis with automated machine learning algorithms and AI models that process security data. The system uses trained models to automatically assess downloaded data for security threats, eliminating the need for manual inspection while maintaining or improving detection accuracy and significantly reducing analysis time.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service security analysis where the automated platform independently processes and evaluates downloaded data without requiring expert intervention. The machine learning models automatically detect threats, classify risks, and generate security assessments, allowing the system to serve itself in performing security analysis functions.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If require data science expertise to analyze security workflows, then analysis quality is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity analysis qualityVSAvoidoperation simplicity
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent introduces an intermediary automated analysis platform that acts as a mediator between raw security data and decision-makers. This platform encapsulates complex data science expertise within machine learning models and automated workflows, presenting simplified results to users without requiring them to possess data science skills. The intermediary translates complex analytical processes into user-friendly outputs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system uses pre-trained machine learning models and templates that replicate expert security analysis capabilities. These models capture and reproduce the knowledge and expertise of data scientists in standardized, reusable formats that can be applied consistently without requiring original experts to perform each analysis manually.

Inventive Principle:
Principle #26Copying

3Productivity

If use automated ML/AI analysis for security data, then productivity is improved, but measurement precision may deteriorate

Engineering Contradiction:
Improveanalysis throughputVSAvoidthreat detection accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent applies preliminary actions by pre-training machine learning models on extensive security datasets before deployment. The models are prepared in advance with learned patterns and knowledge, enabling them to perform accurate threat detection during actual operations. This preliminary training ensures the automated system has the expertise needed to maintain precision while achieving high productivity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where analysis results are continuously evaluated and used to refine and retrain the machine learning models. This feedback loop allows the automated system to learn from its performance, correct errors, and improve accuracy over time while maintaining high processing throughput. The feedback ensures that productivity gains do not compromise detection precision.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11522880B2Analytics engine for data exploration and analytics
Publication Date: 2022.12.06 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11522880B2 patent drawing
  • US11522880B2 patent drawing
  • US11522880B2 patent drawing

AI summary

A method, system, and computer-usable medium for analyzing security data formatted in STIX™ format. Data related to actions performed by one or more users is captured. Individual tasks, such as analytics or extract, transform, load (ETL) tasks related to the captured data is created. Individual tasks are registered to a workflow for executing particular security threat or incident analysis. The workflow is executed and visualized to perform the security threat or incident analysis.