IP Threat Prevention via Risk Intelligence Aggregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional firewalls and routers are inadequate in blocking high-risk IP addresses in real-time due to their limited capacity and inflexible blocking options, as they can only block a small percentage of IP addresses and require constant updates, while users need a more tailored approach to manage security risks effectively.

Innovation Solution

A system that acquires IP threat information from Internet Risk Intelligence Providers, maps risk category names for consistency, assigns weights to various characteristics, and uses mathematical transformations to adjust risk scores, allowing real-time blocking of high-risk IP connections while enabling users to set acceptable risk profiles based on aggregate risk scores.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional firewalls and routers are used to block IP addresses, then basic security protection is provided, but the system can only block a small percentage of IP addresses (10,000 to 100,000) and requires constant real-time updates

Engineering Contradiction:
Improvesecurity protectionVSAvoidblocking capacity
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the IP address blocking system into multiple components: conventional firewalls/routers handle basic blocking, while a separate risk intelligence platform handles advanced threat assessment. The system divides IP addresses into risk categories (high, medium, low) and processes them through different handling mechanisms, enabling the overall system to block millions of IP addresses beyond the limitations of individual firewall devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary risk intelligence platform that sits between the threat intelligence data sources and the firewall systems. This intermediary aggregates threat data from multiple sources, performs risk assessment and categorization, and provides structured blocking recommendations to firewalls. This mediator enables coordinated blocking across multiple devices, dramatically increasing the total blocking capacity from 10,000-100,000 to millions of IP addresses.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access rules are constantly updated in real-time to match changing threats, then security effectiveness is maintained, but the complexity of managing and updating rules increases significantly

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidrule management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The risk intelligence platform automates the entire rule generation and update process. It continuously monitors threat intelligence sources, automatically assesses risks, generates blocking rules, and pushes updates to firewall systems without human intervention. This self-service approach maintains real-time security effectiveness while eliminating the manual complexity of rule management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the parameters of risk assessment by introducing multiple threat intelligence sources, confidence scores, and risk categorization (high, medium, low). Instead of managing individual IP blocking rules, the system manages aggregated risk parameters and categories. This parameter transformation simplifies rule management while maintaining or improving security effectiveness through more nuanced risk-based decisions.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If only two blocking options (blocked or not blocked) are provided, then firewall configuration is simple, but adequate flexibility for assessing threats is not provided

Engineering Contradiction:
Improveconfiguration simplicityVSAvoidthreat assessment flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent transforms the static binary blocking decision into a dynamic multi-level risk assessment system. IP addresses are assigned to risk categories (high, medium, low) based on continuous monitoring and analysis of threat intelligence. The system dynamically adjusts blocking decisions based on risk level, confidence scores, and organizational policies. This dynamic approach provides flexibility in threat assessment while maintaining operational simplicity through automated categorization and policy-based enforcement.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent adds new dimensions to the blocking decision space by introducing risk categories, confidence scores, and time-based factors. Instead of a single binary dimension (blocked/not blocked), the system creates a multi-dimensional risk assessment framework. Organizations can set policies along these new dimensions (e.g., block all high-risk addresses, monitor medium-risk addresses), providing flexible threat assessment while keeping the actual firewall rules simple and manageable.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9342691B2Internet protocol threat prevention
Publication Date: 2016.05.17 THREATER INC
  • US9342691B2 patent drawing
  • US9342691B2 patent drawing
  • US9342691B2 patent drawing

AI summary

Blocking high-risk IP connections in real-time while allowing tailoring of an acceptable risk profile to match the security requirements of network resources. By acquiring IP threat information about IP addresses, including risk confidence levels, assigning weighting factor values corresponding to various characteristics of the IP addresses, and mathematically transforming the risk confidence levels using the weighting factor values, traffic from IP addresses posing unacceptable levels of risk is blocked. Further, mathematically transforming risk confidence level to a user-defined acceptable risk level permits allowing traffic from the IP addresses having an acceptable level of risk.