IoT Threat Correlation Using Risk Levels for Faster Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems take time to analyze new cyber threats in vehicles and IoT devices due to the lack of efficient methods to associate and present threat information related to updated functions, leading to delayed countermeasures against cyberattacks.

Innovation Solution

A threat analysis apparatus that includes an update manager, threat information manager, risk level manager, and related threat information manager to associate and output threat information related to updated functions, allowing for efficient analysis and reduced response time to cyberattacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If traditional threat analysis methods are used, then comprehensive threat information can be collected, but the analysis time is extended and response is delayed

Engineering Contradiction:
Improvethreat analysis timeVSAvoidthreat analysis efficiency
Core Design Contradiction:
Loss of timeVSProductivity

Solution Approach 1:

The system performs preliminary actions by pre-collecting and organizing threat information in structured databases (threat information manager, related threat information manager) before actual attacks occur. When a new threat is detected, the analysis apparatus can immediately query pre-organized threat patterns and risk levels, eliminating the need for time-consuming analysis from scratch and significantly reducing response time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces intermediary components including a risk level manager that mediates between raw threat data and analysis results, and a related threat information manager that serves as an intermediary database storing pre-analyzed threat patterns. These intermediaries enable rapid threat assessment by providing structured, pre-processed information rather than requiring direct analysis of raw attack data

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If threat information is stored and managed comprehensively, then analysis accuracy improves, but system complexity increases

Engineering Contradiction:
Improvethreat analysis accuracyVSAvoidinformation management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments threat information management into distinct functional modules: threat information manager for storing attack patterns, related threat information manager for storing risk assessments, and risk level manager for evaluating threats. Each manager handles specific aspects of threat data, enabling comprehensive coverage while maintaining manageable complexity through clear separation of concerns

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates universal management structures that handle multiple types of threat information through standardized interfaces. The threat information manager and related threat information manager serve multiple functions including storage, retrieval, and correlation of diverse threat data types, reducing overall system complexity by consolidating multiple specialized components into multi-functional managers

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12568097B2Threat analysis apparatus, threat analysis method, and recording medium
Publication Date: 2026.03.03 PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
  • US12568097B2 patent drawing
  • US12568097B2 patent drawing
  • US12568097B2 patent drawing

AI summary

A threat information analysis server includes: an update manager that manages update information indicating that function addition to an IoT device is performed; a threat information manager that stores threat information of a cyberattack; a risk level manager that manages risk level information defining a risk level of the IoT device; a related threat information manager that manages the threat information and related threat information associating the IoT device with the risk level; a risk level updater that associates the threat information and the risk level of the IoT device with each other and updates the related threat information, based on the update information; and an outputter that outputs the related threat information managed by the related threat information manager.