Banking document extraction and analysis system
An embodiment of the present invention is directed to an extraction and analysis system that comprises a network sensor configured to capture network traffic, a source document processor configured to extract text from source documents in the captured network traffic, an artificial intelligence (AI) inference engine configured to extract structured banking information from the extracted text, and an interface to a security information and event management (SIEM) system configured to receive the extracted structured banking information and generate alerts based on the extracted structured banking information. The system enables automated extraction and analysis of banking details from various document types within network traffic for enhanced security monitoring and threat detection.
1 . A computer-implemented system, comprising:
at least one network sensor configured to capture network traffic;
a source document processor configured to extract data from a plurality of source documents in multiple disparate formats from the captured network traffic wherein the captured network traffic identifies a protocol session from each of the plurality of source documents;
an artificial intelligence (AI) inference engine integrated with the source document processor and configured to generate structured banking information in a predetermined format from the extracted data from the plurality of source documents and the AI inference engine is configured to receive contextual information about a source document along with the extracted data when the source document is textual in type, and when the source document is not textual in type, the source document is processed to extract text prior to being passed to the AI inference engine;
an interface configured to communicate with one or more of: a security information and event management (SIEM) system configured to receive the extracted structured banking information and generate alerts based on the extracted structured banking information; an indicator of compromise (IOC) engine configured to generate alerts based on the extracted structured banking information matching known malicious banking details; or a regression testing processor configured to support one or more AI model, configuration or prompt change; and
a database that stores the structured banking information with corresponding cybersecurity observables to enable one or more of: queries, aggregations, or analysis of historical data, wherein the database further stores message details and file analysis results to facilitate clustering and identify relationships between transaction events to allow for identification of patterns and connections indicative of fraudulent activity.
2 . The computer-implemented system of claim 1 , wherein the multiple disparate formats comprise a combination of: email messages, PDF documents, or image files.
3 . The computer-implemented system of claim 1 , further comprising an optical character recognition (OCR) processor configured to extract text from the plurality of source documents.
4 . The computer-implemented system of claim 1 , wherein the AI inference engine is configured to receive contextual information about the plurality of source documents along with the extracted data.
5 . The computer-implemented system of claim 4 , wherein the contextual information includes an indication of a source document type.
6 . The computer-implemented system of claim 1 , wherein the AI inference engine is configured to output the structured banking information in a JSON format.
7 . The computer-implemented system of claim 1 , wherein the database comprises a key-value database configured to store summarized observation data related to the extracted structured banking information.
8 . The computer-implemented system of claim 1 , wherein one or more protocol sessions to the AI inference engine is conditionally processed.
9 . The computer-implemented system of claim 1 , wherein the protocol session comprises at least one of: SMTP, HTTP, SMB or FTP and the data comprises at least one of: text, image or document.
10 . A computer-implemented method, comprising the steps of:
capturing network traffic using at least one network sensor;
extracting, via a source document processor, data from a plurality of source documents in the captured network traffic in multiple disparate formats from the captured network traffic wherein the captured network traffic identifies a protocol session from each of the plurality of source documents;
generating, via an artificial intelligence (AI) inference engine integrated with the source document processor, structured banking information in a predetermined format from the extracted data from the plurality of source documents and wherein the AI inference engine receives contextual information about a source document along with the extracted data when the source document is textual in type, and when the source document is not textual in type, the source document is processed to extract text prior to being passed to the AI inference engine;
providing the extracted structured banking information to a security information and event management (STEM) system; and
communicating, via an interface, with one or more of: the security information and event management (SIEM) system configured to generate alerts based on the extracted structured banking information; an indicator of compromise (IOC) engine configured to generate alerts based on the extracted structured banking information matching known malicious banking details; or a regression testing processor configured to support one or more AI model, configuration or prompt change; and
storing, in a database, the structured banking information with corresponding cybersecurity observables to enable one or more of: queries, aggregations, or analysis of historical data, wherein the database stores message details and file analysis results to facilitate clustering and identify relationships between transaction events to allow for identification of patterns and connections indicative of fraudulent activity.
11 . The computer-implemented method of claim 10 , wherein the multiple disparate formats comprise a combination of: email messages, PDF documents, or image files.
12 . The computer-implemented method of claim 10 , wherein the source document processor comprises an optical character recognition (OCR) processor configured to extract text from the plurality of source documents.
13 . The computer-implemented method of claim 10 , wherein the AI inference engine is configured to receive contextual information about the plurality of source documents along with the extracted data.
14 . The computer-implemented method of claim 13 , wherein the contextual information includes an indication of a source document type.
15 . The computer-implemented method of claim 10 , wherein the AI inference engine is configured to output the structured banking information in a JSON format.
16 . The computer-implemented method of claim 10 , wherein the database comprises a key-value database configured to store summarized observation data related to the extracted structured banking information.
17 . The computer-implemented method of claim 10 , wherein one or more protocol sessions to the AI inference engine is conditionally processed.
18 . The computer-implemented method of claim 10 , wherein the protocol session comprises at least one of: SMTP, HTTP, SMB or FTP and the data comprises at least one of: text, image or document.