Methods, systems, and devices for recommending mitigation of internet of things (IoT) cyber threats using generative artificial intelligence
Aspects of the subject disclosure may include, for example, obtaining a group of threat research reports, obtaining a group of indicators of compromise (IOCs), and monitoring a network of Internet of Things (IoT) devices. Further embodiments can include determining a group of possible malware on the network based on the monitoring of the network and generating a network security recommendation based on the group of threat research reports, the group of IOCs, and the group of possible malware. Other embodiments are disclosed.
1 . A device, comprising:
a processing system including a processor; and
a memory that stores executable instructions that, when executed by the processing system, facilitate performance of operations, the operations comprising:
obtaining a group of threat research reports comprising unstructured data;
extracting cyber threat properties from the group of threat research reports using a generative artificial intelligence (AI) threat classifier;
obtaining a group of indicators of compromise (IOCs);
monitoring, based on the group of IOCs, a network of Internet of Things (IoT) devices associated with one or more IoT environments;
determining a group of possible malware on the network based on the monitoring of the network;
generating an IoT environment classification that associates a respective relevance of each of a plurality of cyber threat characteristics in relation to the one or more IoT environments; and
generating a network security recommendation based on the cyber threat properties, the group of possible malware, and the IoT environment classification.
2 . The device of claim 1 , wherein the operations further comprise implementing the network security recommendation.
3 . The device of claim 1 , wherein the generating of the network security recommendation comprises generating the network security recommendation utilizing generative artificial intelligence.
4 . The device of claim 1 , wherein the IoT environment classification includes the relevance or severity of one or more cyber threat characteristics in relation to properties of the IoT environment.
5 . The device of claim 4 , wherein the IoT environment classification includes automotive, healthcare, retail, utilities, government, malware type, operating system, initial access technique, campaign type, geographical region, or a combination thereof.
6 . The device of claim 4 , wherein the IoT environment classification includes malware type, operating system, initial access technique, campaign type, geographical region, or a combination thereof.
7 . The device of claim 4 , wherein the generating of the network security recommendation comprises generating the network security recommendation based on a generative artificial intelligence threat classification.
8 . The device of claim 7 , wherein the generative artificial intelligence threat classification comprises malware names, tool names for initial access, threat group names, threat names, or a combination thereof.
9 . The device of claim 7 , wherein the generative artificial intelligence threat classification comprises malware type, operating system, initial access technique, campaign type, geographical region, or a combination thereof.
10 . A non-transitory machine-readable medium, comprising executable instructions that, when executed by a processing system including a processor, facilitate performance of operations, the operations comprising:
obtaining a group of threat research reports;
extracting cyber threat properties from the group of threat research reports using a generative artificial intelligence (AI) threat classifier, wherein the cyber threat properties comprise threat names and synonyms thereof;
obtaining a group of indicators of compromise (IOCs);
monitoring, based on the group of IOCs, a network of Internet of Things (IoT) devices associated with one or more IoT environments;
determining a group of possible malware on the network based on the monitoring of the network;
generating an IoT environment classification that associates a respective relevance of each of a plurality of cyber threat characteristics in relation to the one or more IoT environments; and
generating a network security recommendation based on the cyber threat properties, the group of possible malware, and the IoT environment classification, wherein the network security recommendation comprises a determination that at least one possible malware among the group of possible malware is irrelevant and should be ignored.
11 . The non-transitory machine-readable medium of claim 10 , wherein the generating of the network security recommendation comprises generating the network security recommendation based on the group of IOCs.
12 . The non-transitory machine-readable medium of claim 10 , wherein the operations further comprise implementing the network security recommendation.
13 . The non-transitory machine-readable medium of claim 10 , wherein the generating of the network security recommendation comprises generating the network security recommendation utilizing generative artificial intelligence.
14 . The non-transitory machine-readable medium of claim 10 , wherein the IoT environment classification includes the relevance or severity of one or more cyber threat characteristics in relation to properties of the IoT environment.
15 . The non-transitory machine-readable medium of claim 10 , wherein the generating of the network security recommendation comprises generating the network security recommendation based on a generative artificial intelligence threat classification.
16 . A method, comprising:
obtaining, by a processing system including a processor, a group of threat research reports comprising unstructured data;
extracting, by the processing system, cyber threat properties from the group of threat research reports using a generative artificial intelligence (AI) threat classifier;
obtaining, by the processing system, a group of indicators of compromise (IOCs);
monitoring, by the processing system and based on the group of IOCs, a network of Internet of Things (IoT) devices associated with one or more IoT environments;
determining, by the processing system, a group of possible malware on the network based on the monitoring of the network;
generating, by the processing system, an IoT environment classification that associates a respective relevance of each of a plurality of cyber threat characteristics in relation to the one or more IoT environments; and
generating, by the processing system, a network security recommendation based on the cyber threat properties, the group of possible malware, and the IoT environment classification, wherein the network security recommendation comprises a determination that at least one possible malware among the group of possible malware is irrelevant and should be ignored.
17 . The method of claim 16 , wherein the generating of the network security recommendation comprises generating, by the processing system, the network security recommendation based on the group of threat research reports.
18 . The method of claim 16 , further comprising implementing the network security recommendation.
19 . The method of claim 16 , wherein the generating of the network security recommendation comprises generating, by the processing system, the network security recommendation utilizing generative artificial intelligence.
20 . The method of claim 16 , wherein the IoT environment classification includes the relevance or severity of one or more cyber threat characteristics in relation to properties of the IoT environment.