Social Threat Scoring via Predictive Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional cybersecurity approaches focus on reactive endpoint and perimeter security, which are inadequate against evolving cyber threats that leverage social media and networks, necessitating predictive and proactive measures to identify dormant malicious entities before attacks occur.

Innovation Solution

An active social risk defense engine paired with a predictive analysis framework uses a scoring algorithm to analyze characteristics of social entities, determining risk scores and initiating security actions based on comparisons to predefined thresholds, including alerting users to potential threats and blocking malicious communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional reactive security measures (anti-virus, firewalls) are used to secure endpoints and networks, then system security is maintained against known threats, but the system cannot detect or prevent emerging social media-based cyber threats and dormant malicious entities

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoidcapability against evolving threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by proactively scanning social networks to identify dormant malicious entities before they can initiate attacks. The predictive analysis framework continuously monitors and assesses potential threats in advance, allowing the system to prepare defensive measures beforehand rather than reacting after breaches occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional mechanical security perimeters (firewalls, endpoint protection) with an information-based predictive analysis system. Instead of relying on static boundary defenses, the system uses social network data analysis, entity behavior monitoring, and risk scoring algorithms to dynamically identify and respond to threats regardless of their origin.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If security monitoring is expanded to include social network data analysis and predictive threat identification, then the system can detect dormant malicious entities before attacks, but the complexity of the security system increases significantly

Engineering Contradiction:
Improvepredictive threat detection capabilityVSAvoidsecurity system architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security system is segmented into distinct functional modules: social network data collection component, entity identification module, predictive analysis framework, risk scoring engine, and response mechanism. Each module performs a specific function, allowing the complex system to be managed through modular components that can be independently developed, tested, and maintained.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary elements such as risk scoring algorithms and confidence threshold mechanisms that bridge the gap between raw social network data and security decisions. These intermediaries process and interpret complex data patterns, transforming unstructured social media information into actionable security intelligence through standardized evaluation criteria.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If comprehensive social network scanning and entity analysis are performed to identify all potential threats, then detection accuracy improves, but the time and computational resources required increase substantially

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidanalysis and processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system dynamically adjusts evaluation parameters such as confidence thresholds, risk score weights, and monitoring intensity based on threat levels and available resources. By changing these parameters, the system can optimize between detection accuracy and processing speed, intensifying analysis when threats are detected and reducing overhead during normal operations.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent applies partial action by focusing scanning and analysis resources on high-risk areas and entities that exhibit suspicious characteristics, rather than uniformly analyzing all social network data. The system performs excessive action selectively by conducting deeper analysis only when initial screening indicates potential threats, avoiding unnecessary processing of benign entities.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9027134B2Social threat scoring
Publication Date: 2015.05.05 ZEROFOX INC
  • US9027134B2 patent drawing
  • US9027134B2 patent drawing
  • US9027134B2 patent drawing

AI summary

A method includes identifying data on a social network that is associated with a social entity, and determining one or more characteristics of the identified data. A reference to the identified data is generated for each of the one or more characteristics. Each generated reference is compared to one or more known references, and a risk score for a social entity is determined based on each of the comparisons. A confidence score for the risk score is determined.