Security Indicator Scoring via Source Reliability and Sightings
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing security information sharing platforms face issues with erroneous classification of security indicators, leading to potential misidentification of benign entities as malicious, resulting in unnecessary blocking and contamination of shared data.
Innovation Solution
A scoring mechanism is implemented to determine an indicator score based on the number of sightings and source reliability of a security indicator, which includes obtaining sightings from multiple source entities and calculating an observable score and indicator score using normalization algorithms, presented to the community via a user interface.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If security indicators are shared freely among users without verification, then information sharing efficiency is improved, but the reliability of security information deteriorates due to erroneous classification
Solution Approach 1:
The patent introduces an intermediary scoring mechanism that acts as a mediator between security indicator submission and community utilization. The indicator score, calculated based on multiple sightings from different source entities, serves as a trust intermediary that validates security indicators before they are fully adopted by the community, thus maintaining both sharing efficiency and information reliability
Solution Approach 2:
The system performs preliminary validation by calculating indicator scores based on multiple sightings before the security indicator is fully propagated to the community. This preliminary action of verification through repeated observations from different sources prevents erroneous indicators from contaminating the shared information pool while maintaining efficient sharing of validated indicators
2Reliability
If multiple source entities are required to verify security indicators, then the reliability of security information is improved, but the complexity of the verification process increases
Solution Approach 1:
The patent merges multiple verification activities into a unified indicator score calculation process. Instead of separate verification steps for each source entity, the system combines sightings from multiple sources and calculates a single composite indicator score, simplifying the verification process while maintaining high reliability through multi-source validation
Solution Approach 2:
The system transforms the complex multi-source verification process into a simplified parameter-based evaluation by calculating an indicator score based on the number of sightings and source entity characteristics. This parameter change from multiple discrete verification checks to a continuous score parameter simplifies the verification process while preserving reliability
3Object-affected harmful factors
If security indicators with low reliability are blocked, then data contamination is reduced, but the loss of potentially valid security information increases
Solution Approach 1:
The patent applies local quality by treating each security indicator individually with its own calculated indicator score, rather than applying uniform blocking rules. This allows the system to selectively block only those indicators with low scores while permitting high-scoring indicators to pass, thus reducing data contamination without losing potentially valid security information
Solution Approach 2:
The system implements feedback through the indicator score mechanism that continuously evaluates security indicators based on sightings from multiple source entities. This feedback loop allows the system to dynamically adjust which indicators are blocked or permitted, reducing data contamination while preserving valid indicators that accumulate sufficient positive sightings
Data Source
AI summary
Examples disclosed herein relate to security indicator scores. The examples enable obtaining a security indicator created by a first user where the security indicator may comprise a first observable, and obtaining, from a first source entity, a first sighting of the first observable. The first sighting of the first observable may indicate that the first observable has been observed by the first source entity where the first source entity is associated with a first level of source reliability. The examples enable determining a number of sightings of the first observable. The examples enable determining a first observable score based on the number of sightings of the first observable and the first level of source reliability, and determining an indicator score associated with the security indicator based on the first observable score. The indicator score may be presented to a community of users via a user interface.


