Targeted Security Alerts via Threat Relevancy Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Entities face challenges in quickly and accurately detecting and addressing sophisticated security threats within their IT infrastructures due to the vast amount of information from threat intelligence sources, leading to false positive security alerts and resource inefficiencies.

Innovation Solution

A threat exchange community is established where participant servers share information with a threat exchange server, which analyzes data to provide targeted security alerts based on threat relevancy scores, preventing free-riders by ensuring participants contribute relevant security data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If entities access multiple threat intelligence sources to identify security threats, then the completeness of threat detection is improved, but the volume of information increases leading to false positive alerts and resource inefficiencies

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidinformation volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts and isolates relevant security threat information from vast threat intelligence sources using automated analysis systems. The system selectively extracts only the most critical and relevant threats, filtering out noise and false positives, thereby reducing information volume while maintaining detection completeness.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes parameters of threat information by prioritizing and scoring threats based on relevance, severity, and specificity to each entity. This parameter transformation converts raw unstructured threat data into ranked, actionable intelligence, reducing the effective information volume that security teams must process.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If security teams analyze vast amounts of threat information manually, then comprehensive threat assessment is achieved, but time consumption and resource allocation increase

Engineering Contradiction:
Improvethreat assessment accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical analysis of threat information with automated computational systems. Machine learning algorithms and automated analysis tools process threat data at scales and speeds impossible for human analysts, maintaining assessment accuracy while dramatically reducing response time and resource consumption.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system introduces an automated threat analysis platform as an intermediary between raw threat intelligence and security decision-makers. This intermediary layer pre-processes, prioritizes, and presents only the most critical threats, saving time for both automated systems and human analysts while maintaining comprehensive assessment capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If generic security alerts are distributed to all entities, then broad threat coverage is provided, but resource allocation efficiency decreases due to false positives

Engineering Contradiction:
Improvethreat coverage breadthVSAvoidresource allocation efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent applies local quality by customizing security alerts according to each entity's specific characteristics, infrastructure, and risk profile. Instead of uniform generic alerts, the system tailors threat information to local needs and vulnerabilities, ensuring broad threat coverage while minimizing false positives and improving resource allocation efficiency for each organization.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10635817B2Targeted security alerts
Publication Date: 2020.04.28 MICRO FOCUS LLC
  • US10635817B2 patent drawing
  • US10635817B2 patent drawing
  • US10635817B2 patent drawing

AI summary

Providing a targeted security alert can include collecting participant data from a plurality of participants within a threat exchange community, calculating, using a threat exchange server, a threat relevancy score of a participant among the plurality of participants within the threat exchange community using the collected participant data, and providing, from the threat exchange server to the participant, the targeted security alert based on the calculated threat relevancy score via a communication link within the threat exchange community.