Security Indicator Scoring via Source Reliability and Sightings

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing security information sharing platforms face issues with erroneous classification of security indicators, leading to potential misidentification of benign entities as malicious, resulting in unnecessary blocking and contamination of shared data.

Innovation Solution

A scoring mechanism is implemented to determine an indicator score based on the number of sightings and source reliability of a security indicator, which includes obtaining sightings from multiple source entities and calculating an observable score and indicator score using normalization algorithms, presented to the community via a user interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If security indicators are shared freely among users without verification, then information sharing efficiency is improved, but the reliability of security information deteriorates due to erroneous classification

Engineering Contradiction:
Improveinformation sharing efficiencyVSAvoidsecurity information reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an intermediary scoring mechanism that acts as a mediator between security indicator submission and community utilization. The indicator score, calculated based on multiple sightings from different source entities, serves as a trust intermediary that validates security indicators before they are fully adopted by the community, thus maintaining both sharing efficiency and information reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary validation by calculating indicator scores based on multiple sightings before the security indicator is fully propagated to the community. This preliminary action of verification through repeated observations from different sources prevents erroneous indicators from contaminating the shared information pool while maintaining efficient sharing of validated indicators

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple source entities are required to verify security indicators, then the reliability of security information is improved, but the complexity of the verification process increases

Engineering Contradiction:
Improvesecurity indicator accuracyVSAvoidverification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple verification activities into a unified indicator score calculation process. Instead of separate verification steps for each source entity, the system combines sightings from multiple sources and calculates a single composite indicator score, simplifying the verification process while maintaining high reliability through multi-source validation

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system transforms the complex multi-source verification process into a simplified parameter-based evaluation by calculating an indicator score based on the number of sightings and source entity characteristics. This parameter change from multiple discrete verification checks to a continuous score parameter simplifies the verification process while preserving reliability

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If security indicators with low reliability are blocked, then data contamination is reduced, but the loss of potentially valid security information increases

Engineering Contradiction:
Improvedata contaminationVSAvoidvalid security indicator loss
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent applies local quality by treating each security indicator individually with its own calculated indicator score, rather than applying uniform blocking rules. This allows the system to selectively block only those indicators with low scores while permitting high-scoring indicators to pass, thus reducing data contamination without losing potentially valid security information

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements feedback through the indicator score mechanism that continuously evaluates security indicators based on sightings from multiple source entities. This feedback loop allows the system to dynamically adjust which indicators are blocked or permitted, reducing data contamination while preserving valid indicators that accumulate sufficient positive sightings

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11303662B2Security indicator scores
Publication Date: 2022.04.12 MICRO FOCUS LLC
  • US11303662B2 patent drawing
  • US11303662B2 patent drawing
  • US11303662B2 patent drawing

AI summary

Examples disclosed herein relate to security indicator scores. The examples enable obtaining a security indicator created by a first user where the security indicator may comprise a first observable, and obtaining, from a first source entity, a first sighting of the first observable. The first sighting of the first observable may indicate that the first observable has been observed by the first source entity where the first source entity is associated with a first level of source reliability. The examples enable determining a number of sightings of the first observable. The examples enable determining a first observable score based on the number of sightings of the first observable and the first level of source reliability, and determining an indicator score associated with the security indicator based on the first observable score. The indicator score may be presented to a community of users via a user interface.