Cyber Threat Intelligence Infrastructure Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems face challenges in processing and leveraging large datasets to provide effective cyber threat intelligence across multiple organizations and individuals, requiring a scalable infrastructure to detect and mitigate potential security threats.

Innovation Solution

A cyber-threat intelligence infrastructure comprising network devices that collect and enrich network reporting information, processed by CTI servers to identify potential security vulnerabilities, utilizing message queues and threat analysis components to generate alerts and configure network devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network monitoring is performed within a single organization, then security threat detection is achieved, but the system lacks scalability to leverage intelligence across multiple organizations

Engineering Contradiction:
ImprovescalabilityVSAvoiddata volume
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The system segments the cyber threat intelligence infrastructure into multiple independent CTI servers that can process data from different organizations. Each server handles specific data streams and threat analysis tasks, allowing the system to scale horizontally by adding more segmented server units without requiring centralized processing of all data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces message queues as intermediary components between data sources and CTI servers, and between different processing stages. These intermediaries buffer and manage data flow, enabling multiple organizations to contribute data without overwhelming the processing system, thus facilitating scalable multi-organization intelligence sharing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If large volumes of network data are processed to provide comprehensive threat intelligence, then threat detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides complex threat analysis into separate processing stages handled by different CTI server instances. Each server focuses on specific analysis tasks (e.g., signature matching, anomaly detection, enrichment), reducing the complexity burden on individual components while maintaining comprehensive detection capability through coordinated operation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Message queues serve as intermediaries that manage the complexity of data flow between collection, processing, and analysis stages. They provide buffering, routing, and flow control mechanisms that simplify the interaction between components, allowing the system to handle large data volumes without proportionally increasing operational complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If network reporting information is enriched with additional data, then threat identification accuracy is improved, but processing time increases

Engineering Contradiction:
Improvethreat identification accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary enrichment of network reporting information by adding tags and metadata at the data collection stage before full analysis. Basic enrichment such as source/destination identification and initial categorization is completed upfront, allowing subsequent threat analysis to focus on critical evaluation rather than basic data preparation, thus reducing overall processing time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies selective enrichment based on the specific threat context and data type. Not all network data receives the same level of enrichment - the system applies appropriate enrichment depth based on preliminary assessment, performing full enrichment only when necessary for accurate threat identification, thereby balancing accuracy requirements with processing efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11888884B2Cyber threat intelligence system infrastructure
Publication Date: 2024.01.30 BCE
  • US11888884B2 patent drawing
  • US11888884B2 patent drawing
  • US11888884B2 patent drawing

AI summary

A cyber threat intelligence infrastructure allows processing of network data to enrich captured data with data from different sources to identify possible and/or actual cyber threats.