Anonymized Security Attack Data Sharing System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity measures lack an efficient mechanism for sharing and analyzing security attack data across entities, leading to delayed and ineffective responses to security threats, as they often rely on manual sharing and lack proactive detection strategies.

Innovation Solution

A system and method for sharing security information among entities, which includes generating and sharing attack data units and rulesets that are configured to recognize security attacks, with the ability to redact sensitive information and adapt to different entities' systems, enabling proactive defense strategies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If security attack data is shared manually across entities, then information exchange occurs, but the response time is delayed and efficiency is reduced

Engineering Contradiction:
Improvesecurity response efficiencyVSAvoidresponse time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by proactively detecting security attacks and generating attack data units before threats spread across multiple entities. The attack data units are prepared in advance with embedded rulesets, enabling immediate deployment when threats are identified, thus eliminating manual sharing delays and significantly reducing response time.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security attack data is shared across entities, then collective defense capability is improved, but sensitive information exposure risk increases

Engineering Contradiction:
Improvecollective defense capabilityVSAvoidsensitive information exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system extracts and removes sensitive information from attack data before sharing it across entities. The attack data units contain only the necessary security threat information and rulesets for defense, while sensitive details such as specific victim identifiers and confidential system information are excluded, thus enabling collective defense without exposing sensitive data.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system introduces attack data units as an intermediary mechanism that mediates between the need for information sharing and the need for privacy protection. These units act as standardized containers that transform raw attack data into protected, shareable formats, enabling secure information exchange across entities while maintaining confidentiality of sensitive information.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If comprehensive security attack data is collected from multiple entities, then analysis accuracy is improved, but data processing complexity increases

Engineering Contradiction:
Improveattack detection accuracyVSAvoiddata processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments comprehensive security attack data into standardized attack data units, each containing specific attack information and associated rulesets. This segmentation organizes large volumes of heterogeneous data from multiple entities into uniform, manageable units that can be processed efficiently, reducing data processing complexity while maintaining the ability to perform accurate collective analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the parameters of attack data by transforming raw security information into standardized formats with consistent structures, fields, and validation rules. This parameter standardization enables automated processing and analysis of data from multiple entities without requiring complex custom processing logic for each data source, thus improving analysis accuracy while reducing processing complexity.

Inventive Principle:
Principle #35Parameter changes

4Measurement precision

If security rulesets are customized for each entity, then detection precision is improved, but system adaptability decreases

Engineering Contradiction:
Improveattack recognition precisionVSAvoidsystem adaptability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system implements universal rulesets within attack data units that can be applied across multiple entities with different security requirements. These rulesets are designed to be entity-agnostic and can detect various attack types regardless of the specific entity context, thereby maintaining high detection precision while ensuring system adaptability across diverse organizational environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system makes rulesets dynamic by enabling them to adapt to different entity contexts while maintaining their core detection logic. The rulesets can be selectively applied, activated, or modified based on entity-specific configurations, allowing the system to maintain both precision through customized application and adaptability through flexible deployment across different security environments.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11637867B2Cyber security sharing and identification system
Publication Date: 2023.04.25 PALANTIR TECHNOLOGIES INC
  • US11637867B2 patent drawing
  • US11637867B2 patent drawing
  • US11637867B2 patent drawing

AI summary

Systems and techniques for sharing security data are described herein. Security rules and/or attack data may be automatically shared, investigated, enabled, and/or used by entities. A security rule may be enabled on different entities comprising different computing systems to combat similar security threats and/or attacks. Security rules and/or attack data may be modified to redact sensitive information and/or configured through access controls for sharing.