Custom Threat Score Generation via ML-Enhanced NLP

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber threat intelligence systems rely heavily on human analysts to extract relevance from vast amounts of data, leading to inefficiencies and uncertainty in resource allocation for defending against cyber-attacks, as they lack customizable data on cyber-attack parameters.

Innovation Solution

The system employs machine learning models and Natural Language Processing (NLP) with Named Entity Recognition (NER) to identify and correlate threat actors with cyber-attack parameters, generating custom threat scores and visual representations for improved resource allocation and real-time assessments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If human analysts manually extract relevance from cyber threat data, then customization and contextual understanding are improved, but productivity and efficiency deteriorate

Engineering Contradiction:
Improvecustomization of threat intelligenceVSAvoiddata processing efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system enables automated self-service through machine learning models that independently process cyber threat data, extract parameters, identify threat actors, and generate threat scores without requiring manual human intervention for each data processing task

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual analysis process with automated computational systems including NLP engines, machine learning models, and correlation algorithms that process threat intelligence data through electronic computation rather than human cognitive processes

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If vast amounts of cyber threat data are collected and analyzed, then measurement precision and threat detection accuracy are improved, but loss of time and processing complexity worsen

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-processing and structuring cyber threat data before analysis, using NLP engines to extract and classify parameters in advance, and maintaining updated databases of threat actors and their characteristics ready for rapid correlation with new threat intelligence

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces time-consuming manual analysis with automated machine learning models that rapidly process large volumes of threat data through electronic computation, correlating parameters and identifying threat actors in seconds rather than hours or days of human analysis

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If manual analysis methods are used for threat intelligence, then ease of operation is maintained, but reliability and consistency of threat assessments worsen

Engineering Contradiction:
Improvesystem usabilityVSAvoidthreat assessment consistency
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces variable human judgment with consistent automated machine learning models that apply the same algorithms and correlation logic uniformly across all threat intelligence data, eliminating human bias and inconsistency while maintaining ease of operation through automated workflows

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system incorporates feedback mechanisms where threat intelligence data is continuously processed, correlated with existing knowledge bases, and used to update and refine threat assessments, creating a self-improving system that maintains reliability through iterative learning and consistent application of analysis criteria

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP4394634A1Systems and methods for using machine learning models for improved and customized cyber threat intelligence
Publication Date: 2024.07.03 COGNYTE TECH ISRAEL LTD
  • EP4394634A1 patent drawingFigure 1
  • EP4394634A1 patent drawingFigure 2
  • EP4394634A1 patent drawingFigure 3

AI summary

The present disclosure provides a method and system to produce a custom threat actor score. Generic cyber threat intelligence (CTI) is received by the system and analyzed by a natural language processor to generate cyber-attack parameters. A generic score is calculated based on the cyber-attack parameters. New Data of Interest (NDI) is collected from an enterprise and processed through a machine learning model to generate analyzed NDI data terms. An NLP is updated with the analyzed NDI data terms to create an enhanced NLP engine. The enhanced NLP engine generates custom cyber-attack parameters from CTI sources. A custom threat score is calculated based on the cyber-attack parameters combined with the custom cyber-attack parameters.