Threat Actor Severity Scoring Using Public Data and Machine Learning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cybersecurity threat monitoring techniques are resource-intensive and lack data-driven, intuitive approaches for identifying and prioritizing key threats, failing to provide full traceability and efficient decision-making support for enterprises.
Innovation Solution
Implementing machine learning models to analyze cybersecurity event information, generate threat actor scores, and provide a graphical user interface for simplified threat actor risk assessment, leveraging public data and internal security testing emulations to automate threat scoring and reduce analyst burden.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If machine learning models are used to analyze cybersecurity event information and generate threat actor scores, then threat assessment accuracy and decision-making efficiency are improved, but system complexity and computational resource requirements increase
Solution Approach 1:
The system segments the threat assessment process into distinct modules: data collection from multiple sources, data parsing and processing, machine learning model inference, and graphical visualization. Each module handles specific tasks independently, making the complex system more manageable and maintainable while improving overall accuracy through specialized processing at each stage.
Solution Approach 2:
The patent introduces an intermediary data processing layer that bridges raw cybersecurity event information and the machine learning models. This intermediary layer parses, cleans, and formats data before it reaches the models, and conversely translates model outputs into actionable insights, thereby reducing the complexity burden on individual components while maintaining high assessment accuracy.
2Productivity
If machine learning models are used to automate threat scoring, then productivity and resource efficiency are improved, but measurement precision and data quality control become more challenging
Solution Approach 1:
The system incorporates feedback mechanisms where the graphical user interface displays threat actor scores and rankings, allowing analysts to review and validate automated assessments. This feedback loop enables continuous improvement of data quality control while maintaining high productivity, as the system learns from analyst corrections and refines its scoring algorithms over time.
Solution Approach 2:
The patent performs preliminary data parsing, validation, and cleaning actions before the machine learning models process the information. By preparing and validating data in advance through structured processing steps, the system ensures data quality control is built into the workflow rather than added as a separate complex layer, thereby maintaining both productivity and measurement precision.
3Measurement precision
If comprehensive data collection from multiple sources is implemented, then measurement precision and assessment completeness are improved, but loss of time and processing resources increase
Solution Approach 1:
The system implements continuous data collection from multiple sources including cybersecurity events, threat actor information, and public data feeds. By maintaining continuous monitoring and processing rather than batch processing, the system ensures assessment completeness is always up-to-date while reducing overall time loss through parallel data gathering operations that occur concurrently rather than sequentially.
Solution Approach 2:
The patent selectively collects and processes only the necessary data portions relevant to threat actor assessment, rather than processing all available data. This partial action approach focuses computational resources on high-value data elements that directly impact threat scoring, thereby maintaining assessment completeness for critical factors while reducing unnecessary processing time and resource consumption.
Data Source
AI summary
A method for cybersecurity threat actor severity scoring, the method comprising: receiving public data that includes publicly available information obtained via monitoring of a data connection between one or more networks; parsing first data related to a cybersecurity event from the public data; associating the first data with a first threat actor; obtaining second data that includes information regarding one or more previous cybersecurity events associated with the first threat actor; determining a first threat actor score based on the first data and the second data; receiving a second threat actor score for a second threat actor; causing a graphical user interface to display a graphical depiction of a ranking of the first threat actor and the second threat actor based on the first threat actor score and the second threat actor score.


