Threat Analysis System Using Rough Sets for Automated Triage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current threat analysis methods are inefficient in processing large volumes of threat information and require manual triage, which can lead to missed critical events or disrupted operations due to high noise levels and variability in threat data.

Innovation Solution

A threat analysis system utilizing rough sets analysis to learn decision rules from training data, automating the analysis process by identifying discrimination results and explanatory variables, thereby prioritizing threat information for analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual triage is used to analyze threat information, then analysts can make sensible assessments based on experience, but the process is highly dependent on analyst ability and critical events may be missed due to high noise levels

Engineering Contradiction:
Improveaccuracy of threat discriminationVSAvoiddependence on analyst ability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables automated self-service threat analysis by having the computer automatically perform triage operations that previously required human analysts. The rough sets analysis algorithm autonomously processes threat information, extracts features, and generates decision rules without human intervention, thereby eliminating dependence on analyst ability while maintaining reliable discrimination accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical human analyst's cognitive process with an automated computational system. The rough sets analysis mechanism substitutes the analyst's experience-based judgment with algorithmic feature extraction and decision rule generation, transforming subjective manual triage into objective automated analysis that consistently identifies critical threats without being affected by noise.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If all threat information is analyzed manually, then comprehensive coverage is achieved, but the huge number of observed threats makes manual screening difficult and time-consuming

Engineering Contradiction:
Improvecompleteness of threat detectionVSAvoidanalysis speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system extracts only the most relevant features from threat information using rough sets analysis. Instead of manually analyzing all aspects of every threat, the algorithm automatically identifies and extracts key discriminative features, then applies decision rules to quickly determine which threats require attention. This extraction approach maintains comprehensive detection coverage while dramatically increasing analysis speed by focusing only on critical attributes.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The analysis process is segmented into distinct automated stages: feature extraction, decision rule generation, and threat classification. This segmentation allows the system to process huge volumes of threat information efficiently by breaking down the complex analysis task into manageable computational steps, achieving both completeness in detection and high productivity in processing speed.

Inventive Principle:
Principle #1Segmentation

3Quantity of substance

If traditional analysis methods are used, then some threat information can be processed, but it is difficult to narrow down the number of specimens to be analyzed when the number is large

Engineering Contradiction:
Improvenumber of threats processedVSAvoidtime to identify critical threats
Core Design Contradiction:
Quantity of substanceVSLoss of time

Solution Approach 1:

The system performs preliminary automated triage before full analysis by generating decision rules from rough sets analysis of historical threat data. These pre-established rules enable rapid filtering and prioritization of new threats, allowing the system to quickly narrow down large volumes of threat information to a manageable subset of critical cases that require detailed examination, thereby reducing the time loss associated with processing large quantities of threats.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12169558B2Threat analysis system, threat analysis device, threat analysis method and threat analysis program
Publication Date: 2024.12.17 NEC CORP
  • US12169558B2 patent drawing
  • US12169558B2 patent drawing
  • US12169558B2 patent drawing

AI summary

The rule learning unit 81 performs rough sets analysis using training data that includes threat information including a plurality of explanatory variables representing a threat event and a discrimination result of discriminating the threat information, to learn a decision rule specifying the discrimination result depending on a combination of the explanatory variables. The input unit 82 inputs the threat information to be analyzed. The analysis unit 83 applies the input threat information to the decision rule to identify the discrimination result of the threat information, and the explanatory variable as a basis for the discrimination result.