Cyber Threat Scoring Engine for Automated Severity Adjustment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity analytics systems face challenges in efficiently identifying and prioritizing cyber threats, particularly unknown threats, due to reliance on rule-based mechanisms and manual analysis, which can lead to increased workload and error-prone decision-making, especially when dealing with large volumes of data and diverse cyber threats.

Innovation Solution

A network-accessible cyber-threat security analytics service that characterizes and responds to cyber threat assessments by querying multiple security knowledge bases, adjusting severity scores based on sightings and relative weightings, and taking action based on computed priorities, including investigative workflow adjustments, notifications, and external computing commands.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If rule-based mechanisms and manual analysis are used to identify cyber threats, then threat detection capability is improved, but analyst workload and time consumption increase significantly

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidanalyst workload
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service by automatically scoring and prioritizing threats using machine learning models that analyze security events, IoCs, and threat intelligence data. This automation allows the system to independently identify and rank threats without requiring manual analyst intervention for each event, thereby maintaining reliable threat detection while significantly reducing analyst workload.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical analysis processes with automated computational systems. Machine learning models and algorithms substitute for human analysts in evaluating security events, calculating threat scores, and determining priority rankings. This substitution maintains detection capability while eliminating the time-consuming manual analysis component.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If comprehensive threat analysis is performed on all security events, then threat identification accuracy is improved, but processing load and system resource consumption increase

Engineering Contradiction:
Improvethreat identification accuracyVSAvoidprocessing load
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system applies local quality by differentiating the level of analysis applied to different security events based on their characteristics and risk profiles. High-priority events with multiple matching IoCs and threat indicators receive comprehensive multi-factor analysis, while lower-priority events receive streamlined processing. This selective approach maintains high identification accuracy for critical threats while reducing overall processing load.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes parameters dynamically by adjusting the depth and scope of analysis based on initial scoring results. Events that score above certain thresholds trigger more intensive multi-factor analysis involving multiple data sources and machine learning models, while events below thresholds receive lighter processing. This parameter adjustment maintains accuracy for significant threats while optimizing resource consumption.

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If multiple data sources and intelligence feeds are integrated, then threat intelligence completeness is improved, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improvethreat intelligence completenessVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system achieves universality by designing a unified multi-factor scoring framework that can accommodate multiple data sources, intelligence feeds, and analysis methods through a single standardized interface. The machine learning models and scoring algorithms are configured to process diverse inputs (security events, IoCs, threat intelligence) using the same computational framework, thereby achieving complete threat intelligence integration without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Measurement precision

If automated hypothesis testing is performed exhaustively, then root cause identification is improved, but query load on data archival systems increases

Engineering Contradiction:
Improveroot cause identificationVSAvoidquery load
Core Design Contradiction:
Measurement precisionVSPower

Solution Approach 1:

The system performs preliminary action by conducting automated hypothesis testing and scoring before security analysts begin their investigations. Machine learning models pre-analyze security events, generate initial root cause hypotheses, and rank them by probability. This preliminary processing reduces the need for exhaustive querying during analyst investigations, as the most likely root causes are already identified and prioritized, thereby maintaining high root cause identification accuracy while reducing query load on archival systems.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11194905B2Affectedness scoring engine for cyber threat intelligence services
Publication Date: 2021.12.07 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11194905B2 patent drawing
  • US11194905B2 patent drawing
  • US11194905B2 patent drawing

AI summary

A network-accessible cyber-threat security analytics service is configured to characterize and respond to a description that includes threat indicators (e.g., IOCs), and an initial severity. Enterprises register with the service by providing identifying information, such as industry, geographies, and the like. For each threat indicator, a query is sent to each of a set of one or more security knowledge bases, and at least some of the queries are scoped by the enterprise industry/geo information specified. The knowledge bases may vary but typically include: a managed security service, a cyber threat intelligence service, and a federated search engine that searches across one or more enterprise-connected data sources. Responses to the queries are collected. A response provides an indication whether the threat indicator identified in the query has been sighted in the knowledge base and the frequency. The system then adjusts the initial severity to reflect the indications returned from querying the security knowledge bases.