IP Library Granted Patent US 10,673,903
Granted Patent B2
US 10,673,903 · App. 16/179,216 · Granted Jun 2, 2020

Classification of security rules

Inventors: Avi Chesla (Brookline, MA); Shlomi Medalion (Lod, IL)
Assignee: Empow Cyber Security Ltd.
H04L63/20G06F16/24575G06F16/285G06F16/9535G06F21/554G06F21/604H04L63/0227H04L63/105H04L63/1416H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,673,903
App. No.
16/179,216
Granted
Jun 2, 2020
Kind
B2
Abstract

A system and method for method for generating a security rule classification model comprises receiving at least one security rule from at least one attack database of a first security product of a plurality of different security products; normalizing each of the at least one security rule; generating a vector for each of the least one normalized security rule; classifying each generated vector to a security engine within a security service using a classification sub-model to generate a preliminary classification model, wherein the classification sub-model is provided from previous classification of security rules for a security product of the plurality of different security products that is different than the first security product; determining a score for the preliminary classification model; and validating the preliminary classification model as the security rule classification model, when the score is over a predefined threshold.

Claims (35)

1. A method for generating a security rule classification model, comprising:

receiving at least one security rule from at least one attack database of a first security product of a plurality of different security products;

normalizing each of the at least one security rule;

generating a vector for each of the least one normalized security rule;

classifying each generated vector to a security engine within a security service using a classification sub-model to generate a preliminary classification model, wherein the classification sub-model is provided from previous classification of security rules for a security product of the plurality of different security products that is different than the first security product;

determining a score for the preliminary classification model; and

validating the preliminary classification model as the security rule classification model, when the score is over a predefined threshold.

2. The method of claim 1 , wherein the preliminary classification model includes: a row vector in which each row element is a score that characterizes a level of association of the at least one security rule to a security engine.

3. The method of claim 1 , wherein the vector for each of the at least one security rule is a binary string.

4. The method of claim 1 , wherein classifying each generated vector further comprises: mapping the generated vector to a security engine within a security service.

5. The method of claim 1 , wherein the mapping is at least one type of: statistical, deterministic, and heuristic-based.

6. The method of claim 1 , wherein the score indicates an accuracy of the classification.

7. The method of claim 1 , wherein the score indicates a probability that the at least one security rule is correctly mapped to the security engine.

8. The method of claim 1 , wherein the classification sub-model includes a list of k security rules, k>1, and for each security rule of the of k security rules an indication whether the rule is classified to a specific security service and engine or is not so classified.

9. The method of claim 1 , further comprising:

training the sub-model using an initial seed, wherein the initial seed includes at least one of: a limited set of security rules associated with a security service and engine within the service and a limited set of rules that are not associated with a security engine.

10. The method of claim 1 , wherein the score is an F-score.

11. A system for generating a security rule classification model, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

receive at least one security rule from at least one attack database of a first security product of a plurality of different security products;

normalize each of the at least one security rule;

generate a vector for each of the least one normalized security rule;

classify each generated vector to a security engine within a security service using a classification sub-model to generate a preliminary classification model, wherein the classification sub-model is provided from previous classification of security rules for a security product of the plurality of different security products that is different than the first security product;

determine a score for the preliminary classification model; and

validate the preliminary classification model as the security rule classification model, when the score is over a predefined threshold.

12. The system of claim 11 , wherein the preliminary classification model includes: a row vector in which each row element is a score that characterizes a level of association of the at least one security rule to a security engine.

13. The system of claim 11 , wherein the vector for each of the at least one security rule is a binary string.

14. The system of claim 11 , wherein the system is further configured to: map the generated vector to a security engine within a security service.

15. The system of claim 11 , wherein the mapping is at least one type: statistical, deterministic, and heuristic-based.

16. The system of claim 11 , wherein the score indicates an accuracy of the classification.

17. The system of claim 11 , wherein the score indicates a probability that the at least one security rule is correctly mapped to the security engine.

18. The system of claim 11 , wherein the classification sub-model includes a list of k security rules, k>11, and for each security rule of the of k security rules an indication whether the rule is classified to a specific security service and engine or is not so classified.

19. The system of claim 11 , wherein the classification sub-model is trained using an initial seed, wherein the initial seed includes at least one of: a limited set of security rules associated with a security service and engine within the service and a limited set of rules that are not associated with a security engine.

20. The system of claim 11 , wherein the score is an F-score.

Assignments (6)
SECURITY INTEREST Recorded Apr 7, 2026
From: CYBEREASON INC.; ALERT LOGIC, LLC
To: AT&T ENTERPRISES, LLC
Reel/Frame 075377/0304 →
RELEASE OF SECURITY INTEREST (REEL/FRAME 059732/0513) Recorded Nov 26, 2025
From: JPMORGAN CHASE BANK, N.A.
To: CYBEREASON INC.
Reel/Frame 073781/0892 →
RELEASE OF SECURITY INTEREST Recorded Jun 26, 2023
From: SOFTBANK CORP.
To: CYBEREASON INC.
Reel/Frame 064108/0725 →
SECURITY INTEREST Recorded May 5, 2023
From: CYBEREASON INC.
To: SOFTBANK CORP.
Reel/Frame 063550/0415 →
SECURITY INTEREST Recorded Apr 26, 2022
From: CYBEREASON INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 059732/0513 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2021
From: EMPOW CYBER SECURITY LTD.; EMPOW CYBER SECURITY INC.
To: CYBEREASON INC.
Reel/Frame 056792/0042 →
Cited By (2)
US 12,197,585 US 12,621,321