Blockchain Threat Intelligence Dissemination

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The dissemination of cybersecurity threat intelligence among organizations is slow due to varying frequencies and delays in receiving threat intelligence reports from different sources, hindering timely mitigation measures.

Innovation Solution

A blockchain-based system for real-time or near real-time dissemination of threat intelligence using decentralized, peer-to-peer technologies, allowing organizations to post and consume threat intelligence reports and mitigation effectiveness on public or private blockchains, ensuring timely updates to IT infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If traditional centralized threat intelligence sharing methods are used, then information can be disseminated among organizations, but the dissemination speed is slow due to varying frequencies and delays from different sources

Engineering Contradiction:
Improvethreat intelligence dissemination speedVSAvoidtime delay in receiving threat intelligence
Core Design Contradiction:
SpeedVSLoss of time

Solution Approach 1:

The patent introduces a blockchain-based intermediary system that acts as a neutral mediator between threat intelligence sources and consuming organizations. This blockchain intermediary standardizes the ingestion, validation, and distribution of threat intelligence feeds, eliminating the variability and delays associated with direct organization-to-organization sharing. The blockchain ledger provides a centralized coordination point that synchronizes threat intelligence dissemination across all participants in real-time.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the traditional mechanical system of manual threat intelligence collection and distribution with an automated electronic blockchain-based system. Smart contracts automatically ingest threat feeds from multiple sources, validate them against predefined criteria, and distribute updated intelligence to all authorized organizations simultaneously. This substitution of automated electronic processes for manual mechanical processes eliminates human response delays and standardizes the timing of intelligence dissemination.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If multiple threat intelligence sources are used, then comprehensive threat coverage is achieved, but coordination and standardization among different sources become complex

Engineering Contradiction:
Improvethreat intelligence source diversityVSAvoidsystem coordination complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal blockchain-based platform that can ingest and standardize multiple different types of threat intelligence feeds from diverse sources. The system uses a common data model and standardized schemas that can accommodate various feed formats and sources. This universal approach allows the system to handle email-based feeds, API-based feeds, and file-based feeds from different organizations through a single coordinated mechanism, reducing the complexity of managing multiple separate integration systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent transforms heterogeneous threat intelligence data from multiple sources into a standardized format by changing the parameters and structure of the incoming data. The blockchain system applies consistent validation rules, timestamp formats, and data schemas to all incoming threat intelligence regardless of its source. This parameter standardization allows diverse threat feeds to be processed uniformly, simplifying the coordination complexity while maintaining the ability to ingest from multiple diverse sources.

Inventive Principle:
Principle #35Parameter changes

3Speed

If real-time threat intelligence sharing is implemented, then rapid response to security threats is enabled, but ensuring data accuracy and reliability becomes more challenging

Engineering Contradiction:
Improvethreat intelligence sharing speedVSAvoidthreat intelligence accuracy
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent implements feedback mechanisms through smart contracts that automatically validate incoming threat intelligence against predefined criteria and organizational policies before adding it to the blockchain ledger. The system provides feedback to contributing organizations about the status of their submitted intelligence, indicating whether it was accepted, rejected, or requires modification. This automated feedback loop ensures that only validated, accurate threat intelligence is disseminated in real-time, maintaining reliability while preserving speed.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary validation and verification of threat intelligence data before it is added to the blockchain and made available to consuming organizations. Smart contracts execute preliminary checks on data format, source authorization, and content validity before the intelligence is committed to the ledger. This preliminary action ensures that inaccurate or malformed data is filtered out before dissemination, maintaining high reliability in the real-time sharing system.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240411866A1Blockchain-based threat intelligence
Publication Date: 2024.12.12 AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC
  • US20240411866A1 patent drawing
  • US20240411866A1 patent drawing
  • US20240411866A1 patent drawing

AI summary

Disclosed are various embodiments for providing blockchain-based threat intelligence. First, a computer determines that a request for a remedial action has been recorded to a blockchain by a smart contract. Then, the computer evaluates the request for the remedial action to determine the remedial action to be performed. Subsequently, the computer causes the remedial action to be performed by a security service.