Threat Detection Content Platform Using Modular Rule Assembly

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems face challenges in developing high-quality detection content due to the lack of integrated content development, deployment, testing, and error handling, leading to inefficiencies and increased costs, as well as high false positive rates and alert volumes, which can result in delayed threat detection and analyst fatigue.

Innovation Solution

A centralized content development platform that provides a standardized framework for creating, testing, and deploying detection content, utilizing a user interface-driven experience for documenting, building, testing, modifying, reviewing, and assessing detection rules, while promoting collaboration and reusability, and integrating threat intelligence to reduce false positives and improve detection efficacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If detection rules are built using proprietary methods that differ from enterprise to enterprise, then each enterprise can customize detection content to its specific needs, but content development becomes difficult, poorly executed, and lacks reusability

Engineering Contradiction:
Improvecustomization capabilityVSAvoidcontent development difficulty
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent segments detection content into modular building blocks including detection rules, indicators of compromise (IOCs), tactics techniques and procedures (TTPs), and attack scenarios. These modular components can be independently developed, tested, and reused across different enterprises while maintaining customization capability through selective assembly of blocks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal standardized framework that enables detection content to be developed once and reused across multiple enterprises. The standardized building blocks and composition mechanisms allow the same detection rules and scenarios to be applied universally while adapting to different enterprise environments through parameter configuration rather than complete redevelopment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If each detection rule is built from the ground up without reusability, then detection content can be highly customized, but the cost of developing new rules becomes expensive in terms of time and skill required

Engineering Contradiction:
Improvedetection content customizationVSAvoidcontent development time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-building standardized detection rule templates, IOCs, TTPs, and attack scenario frameworks that can be directly applied or minimally customized. These pre-prepared building blocks eliminate the need to create detection rules from scratch, significantly reducing development time while maintaining the ability to adapt to specific enterprise needs through configuration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables copying and reusing of detection rules, IOCs, and attack scenarios across different enterprises and use cases. The standardized framework allows detection content to be copied from one context to another with minimal modification, reducing redundant development effort while preserving customization through selective adaptation of the copied content.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If there is no integrated platform for content development, deployment, testing, and assessment, then enterprises can use existing separate tools, but the lack of integration leads to inefficiencies and increased costs

Engineering Contradiction:
Improvetool flexibilityVSAvoidcontent development efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent merges previously separate functions into an integrated content development platform that combines content creation, modular building block assembly, testing, deployment, and efficacy assessment into a unified system. This integration enables seamless workflow between different stages of detection content lifecycle management, improving productivity by eliminating manual transfers and inconsistencies between separate tools while maintaining flexibility in tool selection through standardized interfaces.

Inventive Principle:
Principle #5Merging (Combining)

4Adaptability or versatility

If detection content lacks standardized framework and methodology, then enterprises can innovate freely, but the lack of standardization prevents industry sharing and collaboration

Engineering Contradiction:
Improvemethodology flexibilityVSAvoidindustry sharing capability
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent uses parameter changes to enable standardized frameworks that maintain flexibility. By defining standardized parameters, metadata schemas, and configuration options within the framework, enterprises can adjust detection content parameters to match their specific needs while maintaining compatibility with the standardized structure. This allows both innovation within parameters and standardization for sharing across the industry.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11290483B1Platform for developing high efficacy detection content
Publication Date: 2022.03.29 ANVILOGIC INC
  • US11290483B1 patent drawing
  • US11290483B1 patent drawing
  • US11290483B1 patent drawing

AI summary

Described are platforms, systems, and methods for providing a threat scenario rule to detect a specified threat scenario use case. In one aspect, a method comprises: receiving, from an interface, a set of threat detection parameters; determining a set of recommended threat identifier use cases from a plurality of threat identifier use cases based on the set of threat detection parameters; providing, to the interface, the set of recommended threat identifier use cases; receiving, from the interface, a threat scenario use case comprising a selection of the set of recommended threat identifier use cases; determining a threat scenario rule comprising logic to detect the threat scenario use case; and providing the threat scenario rule to the interface.