Security Threat Assessment Engine Using External Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information security systems lack effective methods to detect and mitigate security threats from third-party systems and applications, relying solely on internal data and failing to account for external vulnerabilities, which can compromise the security of entities relying on these third parties.
Innovation Solution
A two-component system comprising a security threat assessment engine and an analytics engine, with the latter utilizing machine learning to analyze both internal and external data to identify threat patterns and anomalies, providing a more accurate assessment of security threats and enabling real-time management of security controls.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If only internal data is used for security threat assessment, then the system is simpler to operate, but the detection accuracy of third-party security threats is insufficient
Solution Approach 1:
The patent combines internal data (from the entity's own systems) with external data (from third-party sources, public databases, and external monitoring systems) to create a comprehensive security threat assessment. This merging of data sources improves detection accuracy by providing a broader view of potential threats while maintaining manageable system complexity through automated integration processes.
Solution Approach 2:
The patent introduces an intermediary security assessment system that acts as a mediator between internal security monitoring and external threat intelligence. This intermediary layer processes, correlates, and analyzes both internal and external data sources, improving detection accuracy while shielding the core system from the complexity of directly managing multiple external data feeds.
2Reliability
If traditional security monitoring is used, then the system is easier to implement, but it cannot detect emerging threat patterns and anomalies
Solution Approach 1:
The patent implements feedback mechanisms where detected threat patterns and anomalies are continuously fed back into the assessment system to refine future detections. The system learns from past incidents and adjusts its detection algorithms, improving reliability over time while managing complexity through automated machine learning processes that adapt without requiring proportional increases in system complexity.
Solution Approach 2:
The patent employs self-service capabilities through automated machine learning and anomaly detection algorithms that continuously improve their own performance. The system automatically identifies emerging threat patterns, adjusts detection parameters, and refines its assessment models without requiring manual intervention, thereby improving reliability while keeping operational complexity manageable.
3Measurement precision
If comprehensive data analysis is performed, then threat assessment accuracy improves, but the processing time increases
Solution Approach 1:
The patent performs preliminary actions by pre-processing and pre-analyzing data from multiple sources before actual threat assessment is needed. External threat intelligence is continuously gathered and prepared in advance, and historical data is pre-tagged and indexed, allowing the system to quickly perform comprehensive analysis when actual assessment is required, thereby maintaining high accuracy while reducing real-time processing time.
Solution Approach 2:
The patent implements periodic action by conducting comprehensive data analysis at optimized intervals rather than continuously. The system performs deep analytical processing periodically when sufficient data has accumulated, while using lighter-weight real-time monitoring in between. This approach maintains assessment accuracy by ensuring thorough analysis occurs regularly, while avoiding the time cost of continuous comprehensive processing.
Data Source
AI summary
The invention utilizes a two-component system to detect third party security threats and drive improved security threat mitigation based on the detection. The first component of the system is a security threat assessment engine, which receives and/or identifies external data and internal data regarding third parties in order to determine information security threats posed by third parties. The second component of the system is an analytics engine, which may comprise a machine learning component which is configured to detect threat patterns and anomalies. In response to the detection of the threat patterns and anomalies the security threat assessment engine may be modified in order to more accurately determine security threats.


