IP Library Granted Patent US 10,122,762
Granted Patent B2
US 10,122,762 · App. 15/182,827 · Granted Nov 6, 2018

Classification of security rules

Inventors: Avi Chesla (Tel-Aviv, IL); Shlomi Medalion (Lod, IL)
Assignee: Empow Cyber Security Ltd.
H04L63/20G06F17/30528G06F17/30598G06F17/30867G06F21/554G06F21/604H04L63/0227H04L63/105H04L63/1416H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,122,762
App. No.
15/182,827
Granted
Nov 6, 2018
Kind
B2
Abstract

A system and method for classifying security rules of a plurality of different security products into a security decision engine in a service. The method comprises receiving at least one security rule from at least one attack database of a security product of the plurality of different security products; normalizing each of the at least one security rule; generating a vector for each of the least one normalized security rule, wherein each vector is generated based on a set of terms indicative of a cyber-solution; mapping each of the generated vector to a security service, wherein the security service represents a cyber-solution category, wherein the mapping is performed using a classification model; and associating each of the respective security rule with the security service, when an evaluation threshold is met.

Claims (58)

1. A method for using a plurality of different security products in a computer network by classifying security rules of the security products into a security decision engine in a service, comprising:

receiving at least one security rule from at least one attack database of each of at least two different ones of the security products;

normalizing each of the received security rules;

generating a vector for each of the least one normalized security rule, wherein each vector is generated based on a set of terms indicative of a cyber-solution;

mapping each of the generated vectors to one of a plurality of security services, wherein each of the security services represents a cyber-solution category, wherein the mapping is performed using a classification model; and

associating each of the security rules with the respective security service to which its corresponding vector was mapped, when an evaluation threshold is met.

2. The method of claim 1 , further comprising:

associating each of the security rules with a security engine operable by the security service.

3. The method of claim 2 , further comprising generating by the security engine a real-time event upon matching of the respective associated security rule to a network attribute.

4. The method of claim 1 , wherein each of the plurality of different security products belongs to the same cyber-solution category.

5. The method of claim 1 , wherein normalizing each of the received security rules further comprises:

converting all letters in fields of each of the received security rules into a single representation;

filtering out none-indicative stop-words from each of the received security rules; and

stemming words having the same root.

6. The method of claim 5 , further comprising:

retrieving only a set of most-indicative fields of each of the received security rules.

7. The method of claim 1 , wherein the classification model is developed in an off-line process.

8. The method of claim 2 , wherein the associating of security rules into the security service and security engine is performed in real-time.

9. The method of claim 8 , wherein generating the vector for each of the received security rules further comprises:

transforming a normalized string into a quantitative vector of values, wherein each vector is generated based on a set of terms indicative of a type of threat.

10. The method of claim 9 , wherein the values are determined based on an appearance level of each indicative terms in a respective security rule.

11. The method of claim 2 , wherein each classification model relates to a single security engine.

12. The method of claim 1 , wherein the mapping each of the generated vectors further comprises:

providing a prediction of how a security rule is mapped to a security engine.

13. The method of claim 1 , wherein security engine is configured to generated events based on the security rules as associated.

14. A system for using a plurality of different security products in a computer network by classifying security rules of the security products into a security decision engine in a service, comprising:

a processing system;

a memory communicatively connected to the processing system, wherein the memory contains instructions that, when executed by the processing element, configure the processing system to:

receive at least one security rule from at least one attack database of each of at least two different ones of the security products;

normalize each of the at least one security rule;

generate a vector for each of the least one normalized security rule, wherein each vector is generated based on a set of terms indicative of a cyber-solution;

map each of the generated vectors to one of a plurality of security services, wherein each of the security services represents a cyber-solution category, wherein the mapping is performed using a classification model; and

associate each of the security rules with the respective security service to which its corresponding vector was mapped, when an evaluation threshold is met.

15. The system of claim 14 , wherein the system is further configured to:

associate each of the security rules with a security engine operable by the security service.

16. The system of claim 15 , wherein the security engine is configured to generate a real-time event upon matching of the respective associated security rule to a network attribute.

17. The system of claim 14 , wherein each of the plurality of different security products belongs to the same cyber-solution category.

18. The system of claim 14 , wherein the system is further configured to:

convert all letters in fields of each of the received security rules into a single representation;

filter out none-indicative stop-words from each of the received security rules; and

stem words having the same root.

19. The system of claim 14 , wherein the system is further configured to:

retrieve only a set of most-indicative fields of each of the received security rules.

20. The system of claim 14 , wherein the classification model is developed in an off-line process.

21. The system of claim 15 , wherein the associating of security rules into the security service and security engine is performed in real-time.

22. The system of claim 21 , wherein the system is further configured to:

transform a normalized string into a quantitative vector of values, wherein each vector is generated based on a set of terms indicative of a type of threat.

23. The system of claim 22 , wherein the values are determined based on an appearance level of each indicative terms in a respective security rule.

24. The system of claim 15 , wherein each classification model relates to a single security engine.

25. The system of claim 14 , wherein the system is further configured to:

provide a prediction of how a security rule is mapped to a security engine.

26. The system of claim 14 , wherein security engine is configured to generated events based on the security rules as associated.

27. A non-transitory computer readable medium having stored thereon instructions for causing one or more processing units to execute a process for using a plurality of different security products in a computer network by classifying security rules of the security products into a security decision engine in a service comprising the steps of:

receiving at least one security rule from at least one attack database of each of at least two different ones of the security products;

normalizing each of the received security rules;

generating a vector for each of the least one normalized security rule, wherein each vector is generated based on a set of terms indicative of a cyber-solution;

mapping each of the generated vectors to one of a plurality of security services, wherein each of the security services represents a cyber-solution category, wherein the mapping is performed using a classification model; and

associating each of the security rules with the respective security service to which its corresponding vector was mapped, when an evaluation threshold is met.

Assignments (8)
SECURITY INTEREST Recorded Apr 9, 2026
From: CYBEREASON INC.; ALERT LOGIC, LLC
To: ANKURA TRUST COMPANY, LLC
Reel/Frame 075375/0297 →
SECURITY INTEREST Recorded Apr 7, 2026
From: CYBEREASON INC.; ALERT LOGIC, LLC
To: AT&T ENTERPRISES, LLC
Reel/Frame 075377/0304 →
RELEASE OF SECURITY INTEREST (REEL/FRAME 059732/0513) Recorded Nov 26, 2025
From: JPMORGAN CHASE BANK, N.A.
To: CYBEREASON INC.
Reel/Frame 073781/0892 →
RELEASE OF SECURITY INTEREST Recorded Jun 26, 2023
From: SOFTBANK CORP.
To: CYBEREASON INC.
Reel/Frame 064108/0725 →
SECURITY INTEREST Recorded May 5, 2023
From: CYBEREASON INC.
To: SOFTBANK CORP.
Reel/Frame 063550/0415 →
SECURITY INTEREST Recorded Apr 26, 2022
From: CYBEREASON INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 059732/0513 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2021
From: EMPOW CYBER SECURITY LTD.; EMPOW CYBER SECURITY INC.
To: CYBEREASON INC.
Reel/Frame 056792/0042 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2016
From: CHESLA, AVI; MEDALION, SHLOMI
To: EMPOW CYBER SECURITY LTD.
Reel/Frame 038917/0826 →
Continuity (1)
Related Publication 20170364576A1 · Dec 21, 2017