IP Library Granted Patent US 12,621,321
Granted Patent B2
US 12,621,321 · App. 18/194,263 · Granted May 5, 2026

Automatic generation of cause and effect attack predictions models via threat intelligence data

Inventors: Avi Chesla (Tel Aviv, IL); Sergei Edelstein (Herzelia, IL)
Assignee: Cybereason Inc.
H04L63/1425H04L41/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,621,321
App. No.
18/194,263
Granted
May 5, 2026
Kind
B2
Abstract

A method for predicting a future stage of an attack on a computer system. The method comprises performing, by the computer system, linguistic analysis on threat intelligence reports, where the threat intelligence reports comprise known stages of the attack. The method also comprises processing, by the computer system, the linguistic analysis with a transition matrix to determine probabilities of cause-and-effect relationships between the known stages of the attack, updating, by the computer system, a probability model based on the probabilities determined by the transition matrix, and predicting, by the computer system, the future stage of the attack based on the probability model and attack classifications.

Claims (52)

1 . A method for predicting a future stage of an attack on a computer system, comprising:

performing, by the computer system, linguistic analysis on threat intelligence reports, the threat intelligence reports comprising known stages of the attack;

processing, by the computer system, the linguistic analysis with a transition matrix that represents probabilities of transitions between multiple attack stages to determine probabilities of cause-and-effect relationships between the known stages of the attack;

updating, by the computer system, a probability model based on the probabilities determined by the transition matrix using new threat intelligence data processed through the transition matrix; and

predicting, by the computer system, a probabilistic sequence of multiple future stages in the attack based on the probability model and a plurality of attack classifications.

2 . The method of claim 1 , further comprising:

choosing, by the computer system, the probability model from a plurality of probability models.

3 . The method of claim 1 , further comprising:

setting, by the computer system, the plurality of attack classifications based on an evidence data set including logs that are collected from at least one of security tools, network devices, identity management systems, cloud workspace applications, and endpoint operating system.

4 . The method of claim 1 , further comprising:

performing, by the computer system, the linguistic analysis initially using a pre-trained natural language processing (NLP) model configured to predict missing textual terms.

5 . The method of claim 4 , further comprising:

performing, by the computer system, the NLP model using a Bidirectional Encoder Representations from Transformers (BERT) Machine Learning algorithm for creating NLP predictive models based on textual data in an unsupervised manner.

6 . The method of claim 1 , further comprising:

predicting, by the computer system, the future stage in the attack based on a plurality of probability models and combining the predictions from the plurality of probability models as a combined prediction of the future stage in the attack.

7 . The method of claim 6 , wherein the plurality of probability models includes a Quasi-Linear prediction model and a Bayesian Belief Network prediction model.

8 . The method of claim 1 , further comprising:

predicting, by the computer system, the future stage in the attack by specifying at least one of attack tactics, attack techniques, attack sub-techniques and attack software identity.

9 . The method of claim 1 , further comprising:

generating, by the computer system, the probability model by:

performing matrix decomposition of the transition matrix using a plurality of matrix decomposition methods,

scoring the decomposition for each of the plurality of matrix decomposition methods,

selecting one of the matrix decompositions based on the scoring, and

generating the probability model using the selected one of the matrix decompositions.

10 . The method of claim 9 , further comprising:

performing, by the computer system, the matrix decomposition as a main matrix including non-cyclic transitions of the known stages of the attack and supplement matrix including cyclic transitions of the known stages of the attack.

11 . A non-transitory computer readable medium comprising one or more sequences of instructions, which, when executed by a processor, causes a computer system to predict a future stage of an attack on another computer system by performing operations comprising:

performing, by the computer system, linguistic analysis on threat intelligence reports, the threat intelligence reports comprising known stages of the attack;

processing, by the computer system, the linguistic analysis with a transition matrix that represents probabilities of transitions between multiple attack stages to determine probabilities of cause-and-effect relationships between the known stages of the attack;

updating, by the computer system, a probability model based on the probabilities determined by the transition matrix using new threat intelligence data processed through the transition matrix; and

predicting, by the computer system, a probabilistic sequence of multiple future stages in the attack based on the probability model and a plurality of attack classifications.

12 . The non-transitory computer readable medium of claim 11 , further comprising:

choosing, by the computer system, the probability model from a plurality of probability models.

13 . The non-transitory computer readable medium of claim 11 , further comprising:

setting, by the computer system, the plurality of attack classifications based on an evidence data set including logs that are collected from at least one of security tools, network devices, identity management systems, cloud workspace applications, and endpoint operating system.

14 . The non-transitory computer readable medium of claim 11 , further comprising:

performing, by the computer system, the linguistic analysis initially using a pre-trained natural language processing (NLP) model configured to predict missing textual terms.

15 . The non-transitory computer readable medium of claim 14 , further comprising:

performing, by the computer system, the NLP model using a Bidirectional Encoder Representations from Transformers (BERT) Machine Learning algorithm for creating NLP predictive models based on textual data in an unsupervised manner.

16 . The non-transitory computer readable medium of claim 11 , further comprising:

predicting, by the computer system, the future stage in the attack based on a plurality of probability models and combining the predictions from the plurality of probability models as a combined prediction of the future stage in the attack.

17 . The non-transitory computer readable medium of claim 16 , wherein the plurality of probability models includes a Quasi-Linear prediction model and a Bayesian Belief Network prediction model.

18 . The non-transitory computer readable medium of claim 11 , further comprising:

predicting, by the computer system, the future stage in the attack by specifying at least one of attack tactics, attack techniques, attack sub-techniques and attack software identity.

19 . The non-transitory computer readable medium of claim 11 , further comprising:

generating, by the computer system, the probability model by:

performing matrix decomposition of the transition matrix using a plurality of matrix decomposition methods,

scoring the decomposition for each of the plurality of matrix decomposition methods,

selecting one of the matrix decompositions based on the scoring, and

generating the probability model using the selected one of the matrix decompositions.

20 . The non-transitory computer readable medium of claim 19 , further comprising:

performing, by the computer system, the matrix decomposition as a main matrix including non-cyclic transitions of the known stages of the attack and supplement matrix including cyclic transitions of the known stages of the attack.

Assignments (2)
SECURITY INTEREST Recorded Apr 7, 2026
From: CYBEREASON INC.; ALERT LOGIC, LLC
To: AT&T ENTERPRISES, LLC
Reel/Frame 075377/0304 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 29, 2023
From: CHESLA, AVI; EDELSTEIN, SERGEI
To: CYBEREASON INC.
Reel/Frame 065978/0008 →
Continuity (2)
Provisional Application 63362286 · Mar 31, 2022
Related Publication 20230319089A1 · Oct 5, 2023
References Cited (49)
US 7933989B1 · Barker et al. · 2011 [cited by applicant]
US 8150783B2 · Gonsalves et al. · 2012 [cited by applicant]
US 8572750B2 · Patel et al. · 2013 [cited by applicant]
US 8800045B2 · Curtis et al. · 2014 [cited by applicant]
US 9680846B2 · Haugsnes · 2017 [cited by applicant]
US 9716721B2 · Hovor · 2017 [cited by examiner]
US 9747446B1 · Pidathala et al. · 2017 [cited by applicant]
US 10650150B1 · Rajasooriya · 2020 [cited by examiner]
US 10659488B1 · Rajasooriya · 2020 [cited by examiner]
US 10673903B2 · Chesla et al. · 2020 [cited by applicant]
US 10848515B1 · Pokhrel · 2020 [cited by examiner]
US 11228610B2 · Medalion et al. · 2022 [cited by applicant]
US 20030217033A1 · Sandler et al. · 2003 [cited by applicant]
US 20040114519A1 · MacIsaac · 2004 [cited by applicant]
US 20040143756A1 · Manson et al. · 2004 [cited by applicant]
US 20050049990A1 · Milenova et al. · 2005 [cited by applicant]
US 20120096549A1 · Amini et al. · 2012 [cited by applicant]
US 20120263376A1 · Wang et al. · 2012 [cited by applicant]
US 20120304007A1 · Hanks et al. · 2012 [cited by applicant]
US 20130097706A1 · Titonis et al. · 2013 [cited by applicant]
US 20130198840A1 · Drissi et al. · 2013 [cited by applicant]
US 20130276122A1 · Sowder · 2013 [cited by applicant]
US 20140201836A1 · Amsler · 2014 [cited by examiner]
US 20140208426A1 · Natarajan et al. · 2014 [cited by applicant]
US 20140215618A1 · Amit · 2014 [cited by applicant]
US 20140280166A1 · Bryars et al. · 2014 [cited by applicant]
US 20140283026A1 · Amit et al. · 2014 [cited by applicant]
US 20140283050A1 · Amit · 2014 [cited by applicant]
US 20140337974A1 · Joshi et al. · 2014 [cited by applicant]
US 20160212166A1 · Henry et al. · 2016 [cited by applicant]
US 20160212167A1 · Dotan et al. · 2016 [cited by applicant]
US 20160335435A1 · Schmidter et al. · 2016 [cited by applicant]
US 20170018075A1 · Middlebrooks et al. · 2017 [cited by applicant]
US 20170091673A1 · Gupta et al. · 2017 [cited by applicant]
US 20170116544A1 · Johnson et al. · 2017 [cited by applicant]
US 20180027006A1 · Zimmermann et al. · 2018 [cited by applicant]
US 20210367961A1 · Kuppa · 2021 [cited by examiner]
US 20220131887A1 · Ngweta · 2022 [cited by examiner]
US 20230038196A1 · Labreche · 2023 [cited by examiner]
US 20230224324A1 · Karabey · 2023 [cited by examiner]
US 20230252158A1 · Bishop, III · 2023 [cited by examiner]
Yang, et al., “Optimized very fast decision tree with balanced classification accuracy and compact tree size,” The 3rd international conference on data mining and intelligent information technology applications, IEEE, 2… [cited by applicant]
The International Search Report and the Written Opinion of the International Searching Authority for PCT/US2015/039664, ISA/RU, Moscow, Russia, Oct. 15, 2015. [cited by applicant]
The International Search Report and the Written Opinion of the International Searching Authority for PCT/US2015/060109, ISA/RU, Moscow, Russia, Mar. 10, 2016. [cited by applicant]
Devlin, et al., “Bert: Pre-training of deep bidirectional transformers for language understanding,” arXiv preprint arXiv:1810.04805, 2018, 16 pages. [cited by applicant]
Eberts, et al.,. “Span-based joint entity and relation extraction with transformer pre-training,” arXiv preprint arXiv:1909.07755, 2019, 8 pages. [cited by applicant]
Soares, et al., “Matching the blanks: Distributional similarity for relation learning,” arXiv preprint arXiv:1906.03158 2019, 10 pages. [cited by applicant]
He, et al., “Deberta: Decoding-enhanced bert with disentangled attention,” arXiv preprint arXiv:2006.03654, 2020, 23 pages. [cited by applicant]
Wang, et al., “Must-read papers on pretrained language models (plms),” GitHib, Inc., https://github.com/thunlp/PLMpapers, Jun. 16, 2021. [cited by applicant]