Third-Party Threat Detection via Segmented Analytics Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security systems fail to effectively detect and manage security threats originating from third-party systems and applications, which can compromise the security of entities relying on them, leading to potential data loss and incidents.

Innovation Solution

A two-component system comprising a security threat assessment engine and an analytics engine, which utilizes both internal and external data to identify and analyze security threats, detect patterns, and communicate notifications to vulnerable third parties through approved channels, enabling real-time mitigation and control measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional security systems are used to monitor third-party threats, then system simplicity is maintained, but security threat detection accuracy deteriorates

Engineering Contradiction:
Improvesecurity threat detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system is divided into distinct functional modules: a data collection module that gathers information from multiple external sources (social media, news, security databases), an analysis module that processes the collected data using machine learning algorithms, and a notification module that alerts relevant parties. This segmentation allows each module to specialize in specific tasks, improving overall detection accuracy without requiring the entire system to become unnecessarily complex.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary analytics engine that acts as a bridge between raw external data and security threat determination. This intermediary component collects and analyzes data from various third-party sources (social media platforms, news outlets, security databases) and translates it into actionable security intelligence, thereby improving detection accuracy while managing complexity through a dedicated intermediate layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive external data collection is implemented to improve threat identification, then security monitoring capability is improved, but data processing time increases

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoiddata processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously collecting and pre-processing security-relevant data from external sources before threats actually materialize. Social media mentions, news articles, and security database entries are gathered and analyzed in advance, allowing the system to quickly determine whether a security threat exists when needed, rather than starting from scratch during an incident.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The data collection and analysis operations run continuously rather than intermittently. The analytics engine maintains constant monitoring of third-party data sources, ensuring that security threats are detected as soon as they emerge. This continuous operation eliminates gaps in monitoring and reduces the time required to respond to emerging threats.

Inventive Principle:
Principle #20Continuity of useful action

3Productivity

If manual threat assessment processes are used, then system complexity is reduced, but productivity in identifying and responding to threats deteriorates

Engineering Contradiction:
Improvethreat identification speedVSAvoidautomation system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs self-service through automated data collection, analysis, and threat determination. The analytics engine autonomously gathers data from external sources, processes it using machine learning algorithms, and generates security threat assessments without requiring manual intervention. This automation significantly improves productivity in threat identification while the modular architecture keeps complexity manageable.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Manual mechanical assessment processes are replaced with automated electronic systems. Instead of human analysts manually reviewing third-party data, the patent implements an automated analytics engine that uses machine learning and data processing algorithms to rapidly analyze security information, thereby increasing productivity while replacing complex manual procedures with streamlined automated systems.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10841330B2System for generating a communication pathway for third party vulnerability management
Publication Date: 2020.11.17 BANK OF AMERICA CORP
  • US10841330B2 patent drawing
  • US10841330B2 patent drawing
  • US10841330B2 patent drawing

AI summary

The invention utilizes a two-component system to detect third party security threats and drive improved security threat mitigation based on the detection. The first component of the system is a security threat assessment engine, which receives and/or identifies external data and internal data regarding third parties in order to determine information security threats posed by third-parties. The second component of the system is an analytics engine, which may comprise a machine learning component which is configured to detect threat patterns and anomalies. In response to the detection of the threat patterns and anomalies the security threat assessment engine may be modified in order to more accurately determine security threats. The system after identifying a security threat, generates a notification associated with the security threat and transfers the notification to a first set of third parties that may be affected by the security threat.