Automated Threat Contextualization Framework

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security analysis tools provide highly-specific alerts but lack higher-level context, requiring security analysts to spend significant time piecing together disparate information, which is repetitive, time-consuming, and error-prone due to the scope of information and adversaries' rapidly changing tactics.

Innovation Solution

A modular and extensible automation framework that contextualizes alerts in an automated manner, using a situation tracking object to record data associated with threats, and a security knowledge graph to evolve understanding of the network, allowing for arbitrary creation of automated 'skills' to decide on further analysis and resource allocation based on threat relevance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security analysts manually piece together disparate information from multiple security products, then they can validate and contextualize threats, but the process becomes repetitive, time-consuming, and error-prone

Engineering Contradiction:
Improvethreat validation accuracyVSAvoidanalyst time spent on manual correlation
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables automated self-service through machine learning models that automatically correlate, contextualize, and validate security alerts without human intervention. The ML models continuously learn from security data and autonomously perform the repetitive task of piecing together disparate information from multiple security products, freeing analysts from manual correlation work while maintaining high validation accuracy

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces machine learning models as an intermediary layer between raw security alerts and analyst review. These ML models act as mediators that automatically process, correlate, and prioritize alerts from multiple security products before presenting refined information to analysts, significantly reducing the time required for manual information gathering while improving validation reliability through consistent automated analysis

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If security products provide highly-specific alerts, then detection precision is improved, but context and higher-level understanding are lost

Engineering Contradiction:
Improvealert detection precisionVSAvoidcontextual information
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The system merges multiple specific alerts from different security products with contextual information from various sources into a unified view. The machine learning models combine precise detection data with broader contextual patterns, merging granular alert details with higher-level threat narratives to provide both precision and context simultaneously in a consolidated presentation for analysts

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent adds a contextual dimension to precise alerts by using ML models to enrich specific detection data with broader threat context, attack patterns, and behavioral information. This dimensional enhancement transforms one-dimensional specific alerts into multi-dimensional threat assessments that include both precise detection data and contextual understanding without losing the original alert precision

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If analysts cross-check information from multiple sources to validate threats, then detection reliability improves, but productivity decreases due to the scope of information coverage

Engineering Contradiction:
Improvethreat detection reliabilityVSAvoidanalyst throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs automated self-service validation by deploying machine learning models that independently cross-check and validate threats against multiple data sources and contextual patterns. This automated self-validation process maintains high detection reliability through comprehensive multi-source verification while dramatically increasing analyst productivity by eliminating manual cross-checking requirements

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements preliminary validation actions through ML models that pre-cross-check and pre-validate alerts against multiple information sources before presenting them to analysts. This preliminary action performs the time-consuming cross-verification work in advance, ensuring high detection reliability is achieved through thorough validation while analysts only need to review pre-validated findings, thereby increasing overall productivity

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12069074B2Threat representation and automated tracking and analysis
Publication Date: 2024.08.20 ARISTA NETWORKS INC
  • US12069074B2 patent drawing
  • US12069074B2 patent drawing
  • US12069074B2 patent drawing

AI summary

An automated framework provides security monitoring and analysis in a network by autonomously detecting actual and potential threats to the network. In response to detection of a threat, the framework instantiates a Situation to provide directed monitoring of the threat. The Situation invokes specific skills based on the state of the Situation to monitor network traffic for activity specific to the threat that instantiated the Situation. As data is collected, additional skills may be invoked based on the additional data to collect new data, and previously invoked skills may be terminated depending on the additional data to avoid collecting information that is no-longer relevant.