Blockchain Threat Intelligence Dissemination
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The dissemination of cybersecurity threat intelligence among organizations is slow due to varying frequencies and delays in receiving threat intelligence reports from different sources, hindering timely mitigation measures.
Innovation Solution
A blockchain-based system for real-time or near real-time dissemination of threat intelligence using decentralized, peer-to-peer technologies, allowing organizations to post and consume threat intelligence reports and mitigation effectiveness on public or private blockchains, ensuring timely updates to IT infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If traditional centralized threat intelligence sharing methods are used, then information can be disseminated among organizations, but the dissemination speed is slow due to varying frequencies and delays from different sources
Solution Approach 1:
The patent introduces a blockchain-based intermediary system that acts as a neutral mediator between threat intelligence sources and consuming organizations. This blockchain intermediary standardizes the ingestion, validation, and distribution of threat intelligence feeds, eliminating the variability and delays associated with direct organization-to-organization sharing. The blockchain ledger provides a centralized coordination point that synchronizes threat intelligence dissemination across all participants in real-time.
Solution Approach 2:
The patent replaces the traditional mechanical system of manual threat intelligence collection and distribution with an automated electronic blockchain-based system. Smart contracts automatically ingest threat feeds from multiple sources, validate them against predefined criteria, and distribute updated intelligence to all authorized organizations simultaneously. This substitution of automated electronic processes for manual mechanical processes eliminates human response delays and standardizes the timing of intelligence dissemination.
2Adaptability or versatility
If multiple threat intelligence sources are used, then comprehensive threat coverage is achieved, but coordination and standardization among different sources become complex
Solution Approach 1:
The patent creates a universal blockchain-based platform that can ingest and standardize multiple different types of threat intelligence feeds from diverse sources. The system uses a common data model and standardized schemas that can accommodate various feed formats and sources. This universal approach allows the system to handle email-based feeds, API-based feeds, and file-based feeds from different organizations through a single coordinated mechanism, reducing the complexity of managing multiple separate integration systems.
Solution Approach 2:
The patent transforms heterogeneous threat intelligence data from multiple sources into a standardized format by changing the parameters and structure of the incoming data. The blockchain system applies consistent validation rules, timestamp formats, and data schemas to all incoming threat intelligence regardless of its source. This parameter standardization allows diverse threat feeds to be processed uniformly, simplifying the coordination complexity while maintaining the ability to ingest from multiple diverse sources.
3Speed
If real-time threat intelligence sharing is implemented, then rapid response to security threats is enabled, but ensuring data accuracy and reliability becomes more challenging
Solution Approach 1:
The patent implements feedback mechanisms through smart contracts that automatically validate incoming threat intelligence against predefined criteria and organizational policies before adding it to the blockchain ledger. The system provides feedback to contributing organizations about the status of their submitted intelligence, indicating whether it was accepted, rejected, or requires modification. This automated feedback loop ensures that only validated, accurate threat intelligence is disseminated in real-time, maintaining reliability while preserving speed.
Solution Approach 2:
The patent performs preliminary validation and verification of threat intelligence data before it is added to the blockchain and made available to consuming organizations. Smart contracts execute preliminary checks on data format, source authorization, and content validity before the intelligence is committed to the ledger. This preliminary action ensures that inaccurate or malformed data is filtered out before dissemination, maintaining high reliability in the real-time sharing system.
Data Source
AI summary
Disclosed are various embodiments for providing blockchain-based threat intelligence. First, a computer determines that a request for a remedial action has been recorded to a blockchain by a smart contract. Then, the computer evaluates the request for the remedial action to determine the remedial action to be performed. Subsequently, the computer causes the remedial action to be performed by a security service.


