Patent attributes
Embodiments are disclosed for a method for a security model. The method includes identifying a plurality of primary semantic relationships between a plurality of initial incident artifacts for a security domain based on a plurality of historical incidents. The method further includes identifying a plurality of parsed incident artifacts from a security encyclopedia based on the initial incident artifacts. Additionally, the method includes determining a plurality of secondary semantic relationships between the parsed incident artifacts based on a natural language processing of the security encyclopedia. Also, the method includes determining a plurality of influence directions corresponding to the secondary semantic relationships based on the secondary semantic relationships and the historical incidents. Further, the method includes generating an influence network based on the initial incident artifacts, the primary semantic relationships, the historical incidents, the parsed incident artifacts, and the secondary semantic relationships.