Security Threat Assessment Engine Using External Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information security systems lack effective methods to detect and mitigate security threats from third-party systems and applications, relying solely on internal data and failing to account for external vulnerabilities, which can compromise the security of entities relying on these third parties.

Innovation Solution

A two-component system comprising a security threat assessment engine and an analytics engine, with the latter utilizing machine learning to analyze both internal and external data to identify threat patterns and anomalies, providing a more accurate assessment of security threats and enabling real-time management of security controls.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If only internal data is used for security threat assessment, then the system is simpler to operate, but the detection accuracy of third-party security threats is insufficient

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent combines internal data (from the entity's own systems) with external data (from third-party sources, public databases, and external monitoring systems) to create a comprehensive security threat assessment. This merging of data sources improves detection accuracy by providing a broader view of potential threats while maintaining manageable system complexity through automated integration processes.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an intermediary security assessment system that acts as a mediator between internal security monitoring and external threat intelligence. This intermediary layer processes, correlates, and analyzes both internal and external data sources, improving detection accuracy while shielding the core system from the complexity of directly managing multiple external data feeds.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional security monitoring is used, then the system is easier to implement, but it cannot detect emerging threat patterns and anomalies

Engineering Contradiction:
Improvethreat detection reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where detected threat patterns and anomalies are continuously fed back into the assessment system to refine future detections. The system learns from past incidents and adjusts its detection algorithms, improving reliability over time while managing complexity through automated machine learning processes that adapt without requiring proportional increases in system complexity.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent employs self-service capabilities through automated machine learning and anomaly detection algorithms that continuously improve their own performance. The system automatically identifies emerging threat patterns, adjusts detection parameters, and refines its assessment models without requiring manual intervention, thereby improving reliability while keeping operational complexity manageable.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If comprehensive data analysis is performed, then threat assessment accuracy improves, but the processing time increases

Engineering Contradiction:
Improveassessment accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-processing and pre-analyzing data from multiple sources before actual threat assessment is needed. External threat intelligence is continuously gathered and prepared in advance, and historical data is pre-tagged and indexed, allowing the system to quickly perform comprehensive analysis when actual assessment is required, thereby maintaining high accuracy while reducing real-time processing time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements periodic action by conducting comprehensive data analysis at optimized intervals rather than continuously. The system performs deep analytical processing periodically when sufficient data has accumulated, while using lighter-weight real-time monitoring in between. This approach maintains assessment accuracy by ensuring thorough analysis occurs regularly, while avoiding the time cost of continuous comprehensive processing.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11095677B2System for information security threat assessment based on data history
Publication Date: 2021.08.17 BANK OF AMERICA CORP
  • US11095677B2 patent drawing
  • US11095677B2 patent drawing
  • US11095677B2 patent drawing

AI summary

The invention utilizes a two-component system to detect third party security threats and drive improved security threat mitigation based on the detection. The first component of the system is a security threat assessment engine, which receives and/or identifies external data and internal data regarding third parties in order to determine information security threats posed by third parties. The second component of the system is an analytics engine, which may comprise a machine learning component which is configured to detect threat patterns and anomalies. In response to the detection of the threat patterns and anomalies the security threat assessment engine may be modified in order to more accurately determine security threats.