Targeted Security Alerts via Threat Relevancy Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Entities face challenges in quickly and accurately detecting and addressing sophisticated security threats within their IT infrastructures due to the vast amount of information from threat intelligence sources, leading to false positive security alerts and resource inefficiencies.
Innovation Solution
A threat exchange community is established where participant servers share information with a threat exchange server, which analyzes data to provide targeted security alerts based on threat relevancy scores, preventing free-riders by ensuring participants contribute relevant security data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If entities access multiple threat intelligence sources to identify security threats, then the completeness of threat detection is improved, but the volume of information increases leading to false positive alerts and resource inefficiencies
Solution Approach 1:
The patent extracts and isolates relevant security threat information from vast threat intelligence sources using automated analysis systems. The system selectively extracts only the most critical and relevant threats, filtering out noise and false positives, thereby reducing information volume while maintaining detection completeness.
Solution Approach 2:
The system changes parameters of threat information by prioritizing and scoring threats based on relevance, severity, and specificity to each entity. This parameter transformation converts raw unstructured threat data into ranked, actionable intelligence, reducing the effective information volume that security teams must process.
2Measurement precision
If security teams analyze vast amounts of threat information manually, then comprehensive threat assessment is achieved, but time consumption and resource allocation increase
Solution Approach 1:
The patent replaces manual mechanical analysis of threat information with automated computational systems. Machine learning algorithms and automated analysis tools process threat data at scales and speeds impossible for human analysts, maintaining assessment accuracy while dramatically reducing response time and resource consumption.
Solution Approach 2:
The system introduces an automated threat analysis platform as an intermediary between raw threat intelligence and security decision-makers. This intermediary layer pre-processes, prioritizes, and presents only the most critical threats, saving time for both automated systems and human analysts while maintaining comprehensive assessment capabilities.
3Adaptability or versatility
If generic security alerts are distributed to all entities, then broad threat coverage is provided, but resource allocation efficiency decreases due to false positives
Solution Approach 1:
The patent applies local quality by customizing security alerts according to each entity's specific characteristics, infrastructure, and risk profile. Instead of uniform generic alerts, the system tailors threat information to local needs and vulnerabilities, ensuring broad threat coverage while minimizing false positives and improving resource allocation efficiency for each organization.
Data Source
AI summary
Providing a targeted security alert can include collecting participant data from a plurality of participants within a threat exchange community, calculating, using a threat exchange server, a threat relevancy score of a participant among the plurality of participants within the threat exchange community using the collected participant data, and providing, from the threat exchange server to the participant, the targeted security alert based on the calculated threat relevancy score via a communication link within the threat exchange community.


