Encrypted Derivation Schema for Secure Threat Model Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current threat intelligence communities face challenges in rapidly detecting and responding to malicious actors due to the increasing complexity and covert nature of threats, as well as the risk of tactical advantages being gained by attackers who compromise community information and analytics.

Innovation Solution

A security platform that enables the sharing of analytical models, such as statistical or probabilistic models, across various software and hardware platforms using open formats, allowing for secure updates and modifications without recreating the models, and utilizing encryption for secure transmission, thereby enhancing threat detection and response efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If threat intelligence communities share analytical models and security data openly, then threat detection capability and response speed are improved, but security risk increases as attackers can compromise community information and tactics

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an intermediary encryption layer between the shared analytical model and the raw security data. The derivation data schema acts as a mediator that transforms data into encrypted form, allowing community members to share models while preventing direct exposure of sensitive information to attackers. This intermediary mechanism enables threat detection capability to improve through sharing while maintaining security by ensuring that even if attackers compromise the community, they cannot access the underlying raw data or model logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies parameter changes by transforming the data representation from raw form to encrypted form through the derivation data schema. The encryption key and algorithm parameters are managed separately, allowing the model to be shared and updated while the actual data parameters remain secured. This parameter transformation enables the system to maintain both openness for collaboration and security for protection.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If analytical models are frequently updated to address new threats, then detection accuracy improves, but model complexity and time to implement updates increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidmodel complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the analytical model into distinct components: the derivation data schema (which can be updated) and the raw security data (which remains stored securely). This segmentation allows the schema to be frequently updated to address new threats without requiring recreation of the entire model. The fixed input component and derivation component can be separated, enabling independent updates to the derivation logic while maintaining the integrity of the stored data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamics by allowing the derivation data schema to be dynamically updated while maintaining a stable interface with the raw data. The schema can evolve to incorporate new threat patterns and detection methods, while the system maintains backward compatibility with existing data structures. This dynamic capability enables continuous improvement of detection accuracy without the complexity of complete model recreation.

Inventive Principle:
Principle #15Dynamics

3Productivity

If raw security data is shared across the community for analysis, then collaborative detection improves, but information security deteriorates as attackers can gain tactical advantages from compromised information

Engineering Contradiction:
Improvecollaborative detectionVSAvoidinformation security
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent applies copying by creating an encrypted copy of the derivation data schema that can be shared and processed without exposing the original raw data. Instead of sharing the actual sensitive information, the system shares encrypted representations that can be decrypted and processed by community members. This copying mechanism enables collaborative detection to improve through data sharing while preventing information security losses, as the original raw data never leaves its secure location.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The encryption layer serves as an intermediary between the raw security data and the community members who need to analyze it. The derivation data schema acts as a mediator that enables processing and collaboration while protecting the underlying information. This intermediary ensures that collaborative detection can proceed with shared data analysis while information security is maintained through the protective encryption barrier.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10594713B2Systems and methods for secure propagation of statistical models within threat intelligence communities
Publication Date: 2020.03.17 SECUREWORKS CORP
  • US10594713B2 patent drawing
  • US10594713B2 patent drawing
  • US10594713B2 patent drawing

AI summary

Systems/method of securely propagating analytical models for detection of security threats and/or malicious actions among a threat intelligence community can be provided. Attributes of security data accessed members of the threat intelligence community can be determined and encoded. Analytical model(s) can be developed for detection of potential malicious actions using the encoded attributes of the security data and a derivation data schema, and this derivation data schema can be encrypted. The model(s) can be translated into common exchange formats for sharing the model with community members. The encrypted derivation data schema can be transmitted to the community members. After receipt, the derivation data schema can be decoded by the community members, and the derivation data schema can be applied to security data to determine if the encoded attributes are found. If the encoded attributes are derived, remedial or mitigating action can be taken.