Cyber Attack Information Processing Apparatus
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cyber threat intelligence systems are not effectively shared between system-based and human-based systems, limiting the ability of users in human-based systems to access and utilize cyber threat intelligence for counteracting cyber attacks.
Innovation Solution
A cyber attack information processing apparatus that converts information between different data structures, allowing a system-based cyber threat intelligence management system to share and provide cyber threat intelligence with human-based systems, such as social networking platforms, by using standardized formats like STIX and maintaining access ranges for secure information dissemination.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If cyber threat intelligence is stored in system-based data structures, then the system-based system can effectively manage and process the intelligence, but human-based systems cannot access or utilize the intelligence
Solution Approach 1:
The patent introduces an intermediary conversion mechanism that translates cyber threat intelligence between system-based data structures (e.g., STIX format) and human-based data structures (e.g., social media post formats). This intermediary conversion layer enables both system-based and human-based systems to access and utilize the same intelligence without compromising the efficiency of either system.
Solution Approach 2:
The patent changes the data structure parameters of cyber threat intelligence to make it compatible with different system types. By converting between standardized formats (STIX) and human-readable formats, the system maintains the integrity and efficiency of system-based processing while enabling human-based systems to access and utilize the intelligence through familiar data structures.
2Adaptability or versatility
If cyber threat intelligence is converted to human-based data structures, then human-based systems can access the intelligence, but the system-based system cannot directly utilize it
Solution Approach 1:
The conversion mechanism serves as a bidirectional intermediary, allowing intelligence to be translated into human-based formats for accessibility while maintaining the ability to convert back to system-based formats for efficient processing. This intermediary approach ensures that human-based systems can access intelligence without preventing system-based systems from utilizing it effectively.
Solution Approach 2:
The patent creates a universal data exchange mechanism that enables cyber threat intelligence to serve multiple functions across different system types. The same intelligence can be utilized by system-based systems in their native format and by human-based systems through converted formats, making the intelligence universally applicable without sacrificing the specialized efficiency of either system type.
3Reliability
If cyber threat intelligence is shared across multiple systems, then the ability to counter cyber attacks is enhanced, but information security and access control become more complex
Solution Approach 1:
The patent applies parameter changes to data structures while maintaining standardized access control parameters. By converting between formats using standardized protocols, the system enables wide sharing of cyber threat intelligence to enhance attack countermeasures while keeping access control management relatively simple through standardized permission frameworks that work across different data formats.
Data Source
AI summary
A cyber attack information processing apparatus includes a memory and a processor configured to, when a first system obtains first information regarding a cyber attack from a first terminal, store the first information in a state that the first information is accessible to a second terminal that is capable of accessing the first system, convert the first information having a first data structure into second information having a second data structure usable by a second system wherein the second information is to be provided for the second system, when the second system obtains third information regarding another cyber attack, convert the third information having the second data structure into fourth information having the first data structure, and provide the second terminal with the fourth information.


