IOC Validation and Risk Prioritization for Security System Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for managing indicator of compromise (IOC) in network security systems are inefficient, often failing to timely add IOCs to security systems and prioritize them based on risk levels, leading to exposure to cybersecurity threats.

Innovation Solution

An automated system and method for validating and prioritizing IOCs using internal and external sources, determining appropriate security systems for addition, and continuously monitoring to mitigate threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual methods are used to manage IOCs, then system complexity is reduced, but IOC processing efficiency and timeliness deteriorate

Engineering Contradiction:
ImproveIOC processing efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system automatically validates IOCs against multiple external sources, determines appropriate security systems, and prioritizes IOCs based on risk indicators without requiring manual intervention. The system serves itself by autonomously completing the entire IOC management workflow from validation to prioritization to addition to security systems.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary validation of IOCs against external sources before adding them to security systems. It pre-determines which security systems should receive each IOC and pre-calculates risk-based priorities, ensuring that IOCs are ready for immediate deployment when threats emerge.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If IOCs are added to multiple security systems, then threat coverage is improved, but redundancy and resource waste increase

Engineering Contradiction:
Improvethreat coverageVSAvoidresource waste
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system assigns each IOC to specific security systems based on local characteristics of both the IOC and the security systems. It determines which security systems are most appropriate for each IOC type and adds IOCs only where they will be most effective, avoiding unnecessary duplication while maintaining comprehensive coverage.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If IOC validation is performed extensively, then accuracy of threat detection is improved, but processing time increases

Engineering Contradiction:
Improvevalidation accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs continuous validation of IOCs against multiple external sources simultaneously rather than sequentially. It maintains ongoing monitoring and validation processes that operate continuously, ensuring high accuracy without significant time delays by parallelizing the validation workflow.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS20260039631A1Automatic validations and prioritizations of indicators of compromise
Publication Date: 2026.02.05 THE TORONTO DOMINION BANK
  • US20260039631A1 patent drawing
  • US20260039631A1 patent drawing
  • US20260039631A1 patent drawing

AI summary

One example method includes receiving indicator of compromise (IOC) intelligence including an IOC. The IOC can then be validated. One or more security systems to add the IOC can then be determined based on one or more risk indicators of the IOC. The IOC can then be added to the one or more security systems.