Association Engine for Security Information Sharing Platforms
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security information sharing platforms face challenges in defining appropriate associations and relationships among various data records, making it time-consuming and technically difficult to maximize the richness of threat intelligence information.
Innovation Solution
A technique is provided to create associations among data records in a security information sharing platform using an association engine that links security indicators with data records based on user input, external data, threat intelligence feeds, and automated malware analysis, enabling interactive data traversal and tactical/strategic information retrieval.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual definition of associations among data records is used, then association accuracy can be controlled, but the process becomes time-consuming and technically difficult
Solution Approach 1:
The system automatically defines associations among data records by analyzing relationships between security indicators and data records, eliminating the need for manual association definition. The association engine autonomously processes data to create meaningful connections, saving time while maintaining accuracy through automated relationship detection.
Solution Approach 2:
The patent replaces manual mechanical processes of defining associations with an automated association engine that uses computational algorithms. This substitution transforms the manual, time-consuming task into an automated system that efficiently processes and defines relationships among data records through electronic processing.
2Productivity
If automated association engine is implemented, then productivity increases, but system complexity increases
Solution Approach 1:
The association engine is designed as a multi-functional component that handles various tasks including defining associations, processing security indicators, and analyzing data record relationships. By consolidating these functions into a single engine, the system achieves high productivity without proportionally increasing complexity, as the engine serves multiple purposes simultaneously.
3Loss of information
If rich threat intelligence information is maximized, then information quality improves, but the difficulty of detecting and measuring increases
Solution Approach 1:
The system incorporates feedback mechanisms where the association engine continuously analyzes relationships between security indicators and data records, refining associations based on detected patterns. This feedback loop enables the system to automatically adjust and improve association definitions, making the detection and measurement of complex relationships more manageable while maximizing information richness.
Data Source
AI summary
Examples disclosed herein relate to associations among data records in a security information sharing platform. Some examples may enable creating, in the security information sharing platform that enables sharing of security information among a plurality of users, an association between a first security indicator comprising a first observable and a first data record based on sightings of the first observable by at least one source entity associated with the first data record. Some examples may further enable obtaining a search query that specifies the first security indicator, and identifying a set of data records that satisfy the search query. The set of data records may include the first data record.


