Temporal Inference for Cybersecurity Events
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity systems face challenges in accurately inferring temporal information from unstructured threat intelligence data, such as natural language reports, which is crucial for timely and effective security incident management due to the volatility of cybersecurity threats and the inability to automatically process unstructured data.
Innovation Solution
A method that uses natural language processing (NLP) to extract and infer temporal information from unstructured security content, such as news articles or threat reports, by identifying time expressions and correlating them with external structured data sources to assign a relevant time marker to cybersecurity events, thereby enhancing the accuracy and speed of security event management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual curation of threat feeds by security professionals is used, then accuracy of threat intelligence data is improved, but productivity and speed of processing are worsened
Solution Approach 1:
The system enables automated self-service processing of threat intelligence data by using NLP to automatically extract temporal information from unstructured text, eliminating the need for manual curation while maintaining accuracy through machine learning algorithms that learn from structured data sources
Solution Approach 2:
The patent replaces the mechanical manual process of security professionals reading and extracting temporal information with an automated computational system using natural language processing and machine learning to perform the same function at scale and speed
2Productivity
If automated NLP extraction of temporal information is used, then productivity is improved, but measurement precision is worsened
Solution Approach 1:
The system performs preliminary action by first extracting and analyzing the structure of temporal information from curated structured data sources to establish patterns and rules, which are then applied in subsequent automated processing of unstructured threat intelligence data to ensure accuracy
Solution Approach 2:
The patent uses structured data sources as an intermediary to bridge the gap between automated processing and accurate temporal inference, leveraging the known structure and reliability of these sources to train and validate the NLP system before applying it to unstructured data
3Ease of operation
If only structured data sources are used, then ease of automated processing is improved, but loss of information is worsened
Solution Approach 1:
The system merges structured and unstructured data sources by combining the automated processing capabilities applied to structured data with NLP techniques that extract temporal information from unstructured text, creating a unified approach that leverages the strengths of both data types
Solution Approach 2:
The patent creates a universal processing system that can handle both structured and unstructured threat intelligence data through the same NLP-based temporal extraction framework, enabling multi-functional capability across different data formats and sources
4Ease of operation
If temporal information is not accurately inferred, then ease of operation is improved, but reliability of security incident response is worsened
Solution Approach 1:
The system implements feedback by continuously validating extracted temporal information against known patterns from structured data sources and refining the NLP extraction process based on discrepancies, ensuring that automated operations maintain high reliability through iterative improvement
Data Source
AI summary
A cognitive security analytics platform is enhanced by providing a technique for automatically inferring temporal relationship data for cybersecurity events. In operation, a description of a security event is received, typically as unstructured security content or data. Information such as temporal data or cues, are extracted from the description, along with security entity and relationship data. Extracted temporal information is processing according to a set of temporal markers (heuristics) to determine a time value marker (i.e., an established time) of the security event. This processing typically involves retrieval of information from one or more structured data sources. The established time is linked to the security entities and relationships. The resulting security event, as augmented with the identified temporal data, is then subjected to a management operation.


