Systems and methods for using machine learning models for improved and customized cyber threat intelligence
The present disclosure provides a method and system to produce a custom threat actor score. Generic cyber threat intelligence (CTI) is received by the system and analyzed by a natural language processor to generate cyber-attack parameters. A generic score is calculated based on the cyber-attack parameters. New Data of Interest (NDI) is collected from an enterprise and processed through a machine learning model to generate analyzed NDI data terms. An NLP is updated with the analyzed NDI data terms to create an enhanced NLP engine. The enhanced NLP engine generates custom cyber-attack parameters from CTI sources. A custom threat score is calculated based on the cyber-attack parameters combined with the custom cyber-attack parameters.
1 . A method, comprising:
receiving, by a processor in an enterprise computing environment of an enterprise, enterprise specific new data of interest (NDI) from a user in the enterprise computing environment;
automatically identifying, by the processor and at least one machine learning model (ML), using automated processing of cyber threat intelligence data stored in computer-readable memory, a plurality of new threat actors based on the enterprise specific NDI;
classifying, by the processor and the at least one ML, using the automated processing, a plurality of custom cyber-attack parameters based on the enterprise specific NDI;
correlating, by the processor and the at least one ML, within the enterprise computing environment, the plurality of threat actors and the plurality of custom cyber-attack parameters;
calculating, by the processor, a custom threat score for each threat actor identified based on the correlation of the plurality of cyber-attack parameters to each of the threat actors;
causing, by the processor, to present, in real-time, a visual mapping of cyber-attack parameters representation including at least one correlated cyber-attack parameter and an associated likelihood value for each of the plurality of threat actors on a display device; and
automatically facilitating allocation of enterprise computing resources within the enterprise computing environment based on the custom threat score.
2 . The method of claim 1 , further comprising:
receiving, by the processor, generic cyber threat intelligence (CTI) data stored in computer-readable memory and obtained from multiple cyber-related data sources;
classifying, by the processor and the at least one ML, using automated processing the CTI data into relevant CTI data and non-relevant CTI data, wherein relevant CTI data is data related to cyber threat vectors of the enterprise computing environment;
classifying, by the processor and the at least one ML, using automated processing the relevant CTI data into cyber-attack parameters;
identifying, by the processor and the at least one ML, through the automated processing of the relevant CTI data, a plurality of generic threat actors based on the relevant CTI data;
correlating, by the processor and the at least one ML, within the enterprise computing environment, the plurality of generic threat actors and the plurality of cyber-attack parameters;
calculating, by the processor and the at least one ML, using computer-implemented aggregation for the correlated cyber-attack parameters, a generic threat score for each of the plurality of generic threat actors identified based on the correlation of the plurality of cyber-attack parameters to each of the plurality of generic threat actors;
allocating or prioritizing enterprise computing resources based on the generic threat score; and
causing, by the processor, to present a visual cyber-attack parameters representation for each of the plurality of threat actor on a display device.
3 . The method of claim 2 , wherein a second custom threat score is calculated, by the processor, using automated computer-implemented processing based on the generic threat score and the custom threat score.
4 . The method of claim 2 , wherein the correlation between the plurality of threat actors and the plurality of cyber-attack parameters is a correlation between each of the plurality of threat actors with at least one of the plurality of cyber-attack parameters determined by the processor through automated processing of the CTI data.
5 . A method, comprising:
receiving, by a processor in an enterprise computing environment of an enterprise, enterprise specific new data of interest (NDI) from a user in the enterprise computing environment of an enterprise;
processing, by the processor and at least one machine learning model (ML), the enterprise specific NDI to generate enterprise specific NDI data terms;
updating, by the processor, a Natural Language Processing (NLP) engine with the enterprise specific NDI data terms to produce an enhanced NLP engine;
analyzing, by the processor and the enhanced NLP engine, generic cyber threat intelligence (CTI) data from multiple cyber-related data sources to determine a plurality of custom cyber-attack parameters and a plurality of custom threat actors;
correlating, by the processor, each of the plurality of custom threat actors and the plurality of custom cyber-attack parameters;
calculating, by the processor, a custom threat score for each of the plurality of custom threat actors based on the correlation of the plurality of custom cyber-attack parameters to each of the plurality of custom threat actors; and
transmitting, by the processor, the custom threat score to a display.
6 . The method of claim 5 , further including: generating, by the processor, a visual representation of the custom threat score.
7 . The method of claim 5 , wherein the NLP engine further comprises at least one Named Entity Recognition (NER) engine.
8 . The method of claim 5 , further comprising:
receiving, by the processor, the CTI data from multiple cyber-related data sources;
analyzing, by the processor and the NLP engine, the CTI data to identify a plurality of cyber-attack parameters;
classifying, by the processor, the plurality of identified cyber-attack parameters;
identifying, by the processor, a plurality of generic threat actors;
correlating, by the processor, each of the plurality of generic threat actors and the plurality of cyber-attack parameters;
calculating, by the processor, a generic threat score for each of the generic threat actors identified based on the correlation of the plurality of cyber-attack parameters to each of the plurality of the generic threat actors;
calculating, by the processor, a new custom threat score based on the generic threat score and the custom threat score; and
transmitting, by the processor, the new custom threat score to a display.
9 . The method of claim 8 , further comprising: generating, by the processor, a visual representation of the new custom threat score.
10 . A system for determining a custom threat score for an enterprise computing environment of an enterprise, comprising:
a display;
a processor;
at least one machine learning model (ML);
a memory communicatively coupled to the processor, wherein the memory stores processor-executable instructions, which, on execution, cause the processor to:
receive enterprise specific new data of interest (NDI) from a user in the enterprise computing environment of the enterprise;
process, with the at least one ML, the enterprise specific NDI to generate enterprise specific NDI data terms;
update a Natural Language Processing (NLP) engine with the enterprise specific NDI data terms to produce an enhanced NLP engine;
analyze, with the enhanced NLP engine, generic cyber threat intelligence (CTI) data from multiple cyber-related data sources to determine a plurality of custom cyber-attack parameters and a plurality of custom threat actors;
correlate each of the plurality of custom threat actors and the plurality of custom cyber-attack parameters;
calculate a custom threat score for each of the plurality of custom threat actors based on the correlation of the plurality of custom cyber-attack parameters to each of the plurality of custom threat actors; and
transmit the custom threat score to a display.
11 . The system of claim 10 , wherein the processor generates a visual representation of the custom threat score.
12 . The system of claim 10 , wherein the NLP engine further comprises at least one Named Entity Recognition (NER) engine.
13 . The system of claim 10 , wherein the processor is further configured to:
receive the CTI data from multiple cyber-related data sources;
analyze, with the NLP engine, the CTI data to identify a plurality of cyber-attack parameters;
classify the plurality of identified cyber-attack parameters;
identify a plurality of generic threat actors;
correlate each of the plurality of generic threat actors and the plurality of cyber-attack parameters;
calculate a generic threat score for each of the generic threat actors identified based on the correlation of the plurality of cyber-attack parameters to each of the plurality of the generic threat actors;
calculate a new custom threat score based on the generic threat score and the custom threat score; and
transmit the new custom threat score to a display.
14 . The system of claim 13 , wherein the processor generates a visual representation of the custom threat score.
15 . The system of claim 13 , wherein the NLP engine further comprises at least one Named Entity Recognition (NER) engine.