Browser Extension for Cyber Threat Intelligence Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional SIEM systems require network security analysts to manually investigate security alerts, which can be time-consuming and inefficient, especially in the face of growing cybersecurity threats and limited analyst resources.

Innovation Solution

A cloud-based enrichment and analysis system that allows network security analysts to quickly gather information on indicators of compromise, query threat data, and determine the reputation of observables, with the ability to automate responses through orchestrated playbooks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional SIEM systems are used to generate security alerts, then security threats can be identified, but the response time is slowed due to manual investigation requirements

Engineering Contradiction:
Improvesecurity threat identificationVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system segments the manual investigation process into automated components by integrating threat intelligence data, enrichment services, and automated response capabilities directly into the SIEM workflow, allowing different aspects of alert analysis to be handled by specialized automated functions

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by pre-gathering threat intelligence data, enrichment information, and contextual data before security analysts need to investigate alerts, so that when analysts do review alerts, the necessary information is already prepared and available

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If manual investigation of security alerts is performed, then thorough analysis can be conducted, but analyst resources are overwhelmed due to limited staff

Engineering Contradiction:
Improvealert analysis thoroughnessVSAvoidanalyst capacity
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system introduces intermediary automated components including threat intelligence platforms, enrichment services, and orchestration engines that mediate between raw security alerts and analyst review, performing preliminary analysis, data gathering, and context provision to reduce the burden on analysts

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by allowing the SIEM to automatically gather threat intelligence data, enrich alert information, and even execute automated responses without requiring constant analyst intervention, making the system serve itself for routine analytical tasks

Inventive Principle:
Principle #25Self-service

3Loss of information

If external threat intelligence data is gathered from multiple sources, then comprehensive security information can be obtained, but system complexity increases

Engineering Contradiction:
Improvethreat intelligence completenessVSAvoiddata integration complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system applies universality by implementing a centralized threat intelligence platform that serves multiple functions: gathering data from various sources, normalizing different data formats, enriching alerts, and providing contextual information, thereby reducing the need for separate specialized systems for each function

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250190543A1Browser extension for cybersecurity threat intelligence and response
Publication Date: 2025.06.12 THREATCONNECT INC
  • US20250190543A1 patent drawing
  • US20250190543A1 patent drawing
  • US20250190543A1 patent drawing

AI summary

Techniques are disclosed relate to systems, methods, and non-transitory computer readable media for implementing a browser extension for cyber threat intelligence and response. One system to perform operations comprising: scanning, in a sandbox of a browser by a browser extension, at least part of a web page to produce a set of items of interests; transmitting the set of items of interests to a cloud-based enrichment and analysis of cybersecurity threat intelligence system to request information on the set of items; receiving a response from the cloud-based enrichment and analysis of cybersecurity threat intelligence system, the response including a scan result based on the transmitted set of items of interests, and the scan result including at least one of an indicator of compromise of the at least scanned part of the web page; and displaying the scan results including the at least one of an indicator of compromise.