Cyber Threat Data Warehouse for Collaborative Network Defense
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity measures are inadequate in effectively detecting and responding to cyberattacks due to limited technical information sharing across enterprises, unreliable and delayed Cyber Threat Intelligence (CTI), and a lack of integration with actionable tools.
Innovation Solution
A data warehouse is maintained and used to share and analyze cyber threat data across industry participants, enabling enhanced detection and response to cyberattacks through collaborative analytics and automated security controls.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cybersecurity information is shared across enterprises, then detection capability and response effectiveness are improved, but information security and competitive sensitivity are worsened
Solution Approach 1:
The patent introduces a data warehouse as an intermediary system that receives, stores, and processes cybersecurity information from multiple enterprises. This mediator enables information sharing while maintaining appropriate isolation and control mechanisms, allowing organizations to benefit from collective intelligence without directly exposing their internal systems to external entities.
Solution Approach 2:
The system segments information into different levels of aggregation and sensitivity. Raw cybersecurity data is segmented into standardized indicators that can be shared, while preserving the ability to access more detailed information only when authorized. This segmentation allows partial information sharing that improves detection without compromising sensitive competitive data.
2Reliability
If cybersecurity information is shared across enterprises, then detection capability is improved, but system complexity is worsened
Solution Approach 1:
The data warehouse is designed as a universal platform that handles multiple functions: data collection from diverse sources, standardization of various information formats, storage of different types of cybersecurity indicators, and distribution of alerts to multiple organizations. This multi-functional design consolidates what would otherwise require separate systems at each enterprise.
Solution Approach 2:
The centralized data warehouse acts as an intermediary that manages the complexity of information sharing, absorbing the burden of data standardization, validation, and distribution. Individual enterprises connect to this mediator rather than directly to each other, which simplifies their systems while enabling comprehensive multi-enterprise collaboration.
3Speed
If real-time cybersecurity monitoring is implemented, then response speed is improved, but resource consumption is worsened
Solution Approach 1:
The system performs preliminary actions by continuously collecting and pre-processing cybersecurity data in the data warehouse, maintaining it in ready-to-analyze formats. When threats are detected, the analysis work has already been partially completed, enabling faster response without requiring intensive real-time computation at each enterprise's systems.
Solution Approach 2:
The patent merges computational resources by consolidating data storage and analysis functions in a centralized data warehouse rather than requiring each enterprise to maintain separate real-time monitoring infrastructure. This combination reduces redundant resource consumption while maintaining collective detection capabilities.
Data Source
AI summary
This disclosure describes techniques for maintaining and using a warehouse of data about potential or actual cyberattack threats for an industry. In one example, this disclosure describes a method that includes outputting, by a computing system operated by a first entity and to a data warehouse, information about activity within a first network operated by the first entity; receiving, by the computing system and from the data warehouse, information about attributes of a peer attack directed to a second network operated by a second entity, wherein the first entity and the second entity may be marketplace competitors; applying, by the computing system, a model to identify a network asset included within the first network that is vulnerable to an attack having the attributes of the peer attack; and outputting, by the computing system and to the network asset, a control signal to modify the operation of the network asset.


