Time-Series Cyber Threat Analysis Using API Event Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity technologies struggle to effectively detect and respond to new or evolving cyber threats due to their reliance on pre-defined patterns, leading to delayed analysis and inadequate response times, especially in the face of sophisticated malware and zero-day attacks.

Innovation Solution

A method for detecting and analyzing time-series data using a cyber threat framework that involves determining target API events, mapping them to threat behavior types, creating threat scenarios, calculating risk grades, and providing security enhancement, system recovery, and instructional prompts based on predicted threat behaviors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If pre-defined pattern matching is used for threat detection, then detection speed is improved for known threats, but detection capability deteriorates for new or evolving threats

Engineering Contradiction:
Improvedetection speedVSAvoiddetection capability for new threats
Core Design Contradiction:
SpeedVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by pre-defining pattern libraries for known threats and pre-establishing response playbooks. When threats are detected, pre-configured response actions are automatically executed, enabling rapid response to known threat types while maintaining the ability to adapt to new threats through continuous pattern updates.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adapts by continuously updating threat patterns and playbook configurations based on emerging threats. The pattern library and response playbooks are not static but evolve over time, allowing the system to maintain fast detection speeds for known threats while progressively improving detection capability for new threat variants.

Inventive Principle:
Principle #15Dynamics

2Measurement precision

If complex multi-dimensional analysis is performed to respond to sophisticated threats, then detection accuracy is improved, but response time deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system segments the threat detection and response process into distinct modular components: pattern matching modules for different threat types, analysis modules for various dimensions of threat assessment, and response modules with pre-configured playbooks. This segmentation allows parallel processing of multiple analysis dimensions simultaneously, maintaining high detection accuracy while reducing overall response time.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Complex response actions are pre-configured as playbooks with defined sequences of operations. When a threat is detected, the system retrieves and executes the appropriate pre-configured playbook, eliminating the need to perform complex analysis and decision-making in real-time, thus reducing response time while maintaining accurate threat assessment.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If manual analysis and response configuration is performed, then response accuracy is improved for specific threats, but productivity deteriorates due to time-consuming manual processes

Engineering Contradiction:
Improveresponse accuracyVSAvoidresponse efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system enables self-service by automatically performing threat detection, analysis, and response execution without requiring manual intervention for each incident. The automated pattern matching and playbook execution systems handle routine threat responses independently, significantly improving productivity while maintaining accurate response actions through pre-configured playbooks developed by security experts.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12407703B2Method for detecting and analyzing time-series data based on cyber threat framework
Publication Date: 2025.09.02 INITECH
  • US12407703B2 patent drawing
  • US12407703B2 patent drawing
  • US12407703B2 patent drawing

AI summary

This disclosure details a method for detecting and analyzing time-series data with a cyber threat framework. It involves determining target API events, mapping these to threat behaviors, creating threat scenarios, assessing matching degree and risk, predicting threat behaviors based on risk grades, and providing solutions.