Collaborative Security Lists Using Community Voting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Inaccurate and outdated security lists can inadvertently block benign security indicators or allow malicious ones, leading to security threats.

Innovation Solution

A collaborative security list system that allows users to suggest and vote on candidate entries, incorporating confidence scores and context information to improve the accuracy and timeliness of security lists, enabling community-level whitelists and blacklists.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security lists are maintained centrally by a single authority, then consistency and control are improved, but accuracy and timeliness deteriorate due to inability to incorporate real-time community knowledge

Engineering Contradiction:
Improveaccuracy of security listsVSAvoidcomplexity of security list management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges individual user security lists into a collaborative community security list by combining multiple security indicators from different users. The system collects security indicators from multiple users, aggregates them, and maintains a unified community security list that leverages collective knowledge while maintaining data consistency through centralized management.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements feedback mechanisms where users can vote on security indicators, report false positives, and provide context information. This feedback loop allows the system to continuously improve accuracy by incorporating real-time community knowledge and correcting errors, while maintaining controlled updates through the centralized platform.

Inventive Principle:
Principle #23Feedback

2Reliability

If security lists are updated frequently to improve timeliness, then threat detection speed is improved, but false positives increase due to insufficient verification

Engineering Contradiction:
Improvetimeliness of security list updatesVSAvoidfalse positives in security lists
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by collecting and aggregating security indicators from multiple users before adding them to the community security list. This preliminary aggregation and verification process allows rapid updates while reducing false positives through collective validation before an indicator is officially added to the list.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Users can provide feedback through voting mechanisms and false positive reports. This feedback allows the system to verify security indicators rapidly while maintaining accuracy through community validation. The feedback loop enables quick updates with built-in verification to filter out false positives.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If individual users maintain their own security lists, then customization and relevance are improved, but coverage and collective intelligence deteriorate

Engineering Contradiction:
Improvecustomization of security listsVSAvoidcoverage of security threats
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system merges individual user security lists with the community security list. Users can maintain their own customized lists while also contributing to and benefiting from the aggregated community list. This merging approach provides both personalized relevance through individual customization and comprehensive coverage through collective intelligence.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The community security list serves multiple functions: it provides individualized security protection for each user, aggregates collective knowledge for broader coverage, and enables users to contribute their own security indicators. This multi-functionality allows the system to simultaneously provide customization and comprehensive threat coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10715534B2Collaborative security lists
Publication Date: 2020.07.14 MICRO FOCUS LLC
  • US10715534B2 patent drawing
  • US10715534B2 patent drawing
  • US10715534B2 patent drawing

AI summary

Examples relate to collaborative security lists. The examples disclosed herein enable obtaining a first candidate entry suggested by a first user of a community to be included in a collaborative security list. The collaborative security list may comprise a list of entries known to be secure or a list of entries known to be insecure. The examples disclosed herein further enable providing a candidate security list comprising at least the first candidate entry to the community and obtaining, from a second user of the community, a first score indicating how confident the second user is that the first candidate entry is secure. The examples disclosed herein further enable determining whether to include the first candidate entry in the collaborative security list based on the first score.