Temporal Inference for Cybersecurity Events

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems face challenges in accurately inferring temporal information from unstructured threat intelligence data, such as natural language reports, which is crucial for timely and effective security incident management due to the volatility of cybersecurity threats and the inability to automatically process unstructured data.

Innovation Solution

A method that uses natural language processing (NLP) to extract and infer temporal information from unstructured security content, such as news articles or threat reports, by identifying time expressions and correlating them with external structured data sources to assign a relevant time marker to cybersecurity events, thereby enhancing the accuracy and speed of security event management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual curation of threat feeds by security professionals is used, then accuracy of threat intelligence data is improved, but productivity and speed of processing are worsened

Engineering Contradiction:
Improveaccuracy of temporal informationVSAvoidspeed of processing threat data
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system enables automated self-service processing of threat intelligence data by using NLP to automatically extract temporal information from unstructured text, eliminating the need for manual curation while maintaining accuracy through machine learning algorithms that learn from structured data sources

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual process of security professionals reading and extracting temporal information with an automated computational system using natural language processing and machine learning to perform the same function at scale and speed

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If automated NLP extraction of temporal information is used, then productivity is improved, but measurement precision is worsened

Engineering Contradiction:
Improveautomation speedVSAvoidaccuracy of time inference
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system performs preliminary action by first extracting and analyzing the structure of temporal information from curated structured data sources to establish patterns and rules, which are then applied in subsequent automated processing of unstructured threat intelligence data to ensure accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses structured data sources as an intermediary to bridge the gap between automated processing and accurate temporal inference, leveraging the known structure and reliability of these sources to train and validate the NLP system before applying it to unstructured data

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If only structured data sources are used, then ease of automated processing is improved, but loss of information is worsened

Engineering Contradiction:
Improveautomated processing capabilityVSAvoidcontextual information from unstructured data
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The system merges structured and unstructured data sources by combining the automated processing capabilities applied to structured data with NLP techniques that extract temporal information from unstructured text, creating a unified approach that leverages the strengths of both data types

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal processing system that can handle both structured and unstructured threat intelligence data through the same NLP-based temporal extraction framework, enabling multi-functional capability across different data formats and sources

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of operation

If temporal information is not accurately inferred, then ease of operation is improved, but reliability of security incident response is worsened

Engineering Contradiction:
Improvesimplicity of event managementVSAvoidaccuracy of security response
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements feedback by continuously validating extracted temporal information against known patterns from structured data sources and refining the NLP extraction process based on discrepancies, ensuring that automated operations maintain high reliability through iterative improvement

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11082434B2Inferring temporal relationships for cybersecurity events
Publication Date: 2021.08.03 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11082434B2 patent drawing
  • US11082434B2 patent drawing
  • US11082434B2 patent drawing

AI summary

A cognitive security analytics platform is enhanced by providing a technique for automatically inferring temporal relationship data for cybersecurity events. In operation, a description of a security event is received, typically as unstructured security content or data. Information such as temporal data or cues, are extracted from the description, along with security entity and relationship data. Extracted temporal information is processing according to a set of temporal markers (heuristics) to determine a time value marker (i.e., an established time) of the security event. This processing typically involves retrieval of information from one or more structured data sources. The established time is linked to the security entities and relationships. The resulting security event, as augmented with the identified temporal data, is then subjected to a management operation.