Central Security Device Normalizes Threat Data for Targeted Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security devices struggle to provide valuable threat assessments for client networks as they lack the ability to compare detected malicious activity levels to historical or global trends, leading to delayed or ineffective responses to malicious activity.
Innovation Solution
A central security device collects and normalizes usage and threat information from multiple client networks, allowing for comparison of malicious activity levels across networks to provide timely and informed threat assessments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If security devices detect malicious objects using traditional methods (URL reputations, blacklists, anti-virus scanning), then malicious objects can be identified, but the ability to compare detected malicious activity levels to historical or global trends is lacking, resulting in delayed or ineffective responses
Solution Approach 1:
The system collects threat information from multiple security devices across different networks and feeds this data back to a central security device. The central device analyzes the aggregated data to determine global threat trends and compares them against local network activity. This feedback mechanism enables timely identification of targeted attacks by comparing current local threat levels against historical and global patterns, allowing for faster and more accurate threat assessments.
Solution Approach 2:
The central security device performs multiple functions: collecting threat information from various client networks, normalizing the data across different networks, analyzing global threat trends, and providing comparative threat assessments. This multi-functional approach consolidates dispersed security data into a unified system that can accurately measure and respond to threats across multiple networks simultaneously.
2Adaptability or versatility
If security devices monitor malicious activity in client networks, then threat detection is enabled, but the lack of normalization and comparison capabilities across networks prevents effective identification of targeted attacks
Solution Approach 1:
The system transforms raw threat information from multiple client networks into normalized threat levels by adjusting parameters such as threat severity, frequency, and volume to a common scale. This parameter normalization allows direct comparison of threat activity across networks with different characteristics. The central security device then compares normalized local threat levels against normalized global trends to identify statistically significant deviations indicating targeted attacks.
Solution Approach 2:
The central security device acts as an intermediary between individual client networks and the broader security landscape. It collects threat data from multiple networks, normalizes the information to a common framework, and provides contextualized assessments that compare local activity against global patterns. This intermediary function restores lost context by establishing relationships between local and global threat levels.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A device may receive usage information, associated with a group of client networks, including particular usage information associated with a particular client network. The device may receive threat information, associated with the group of client networks, including particular threat information associated with the particular client network. The device may determine a baseline based on the usage information. The device may determine a normalization function, associated with the particular client network, based on the baseline and the particular usage information. The device may determine normalized threat information, associated with the particular client network, based on the normalization function and the particular threat information. The device may determine overall normalized threat information associated with the group of client networks. The device may compare the normalized threat information and the overall normalized threat information. The device may provide information associated with comparing the normalized threat information and the overall normalized threat information.