Security Threat Assessment Engine with External Data Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information security systems lack effective methods to detect and mitigate security threats from third-party systems and applications, as they rely solely on internal data, neglecting external data sources that could provide critical threat information.
Innovation Solution
A two-component system comprising a security threat assessment engine and an analytics engine, where the assessment engine identifies and analyzes external and internal data to determine security threats and threat levels, utilizing machine learning to detect patterns and anomalies, and the analytics engine refines the threat assessment for more accurate predictions and mitigation plans.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If only internal data is used for security threat assessment, then the system is simpler to operate, but the detection accuracy and reliability of threat identification deteriorates
Solution Approach 1:
The patent combines internal data (from the entity's own systems) with external data (from third-party security feeds, vulnerability databases, and external monitoring sources) to create a comprehensive security threat assessment. This merging of data sources improves detection accuracy and reliability while the automated processing framework manages the complexity through standardized integration protocols.
2Reliability
If external data sources are integrated into the assessment system, then the reliability of threat detection improves, but the device complexity increases
Solution Approach 1:
The patent introduces an automated processing framework that acts as an intermediary between multiple external data sources and the core assessment engine. This framework standardizes data ingestion, validates inputs, and manages the complexity of integrating diverse external sources while improving detection reliability through comprehensive data collection.
Solution Approach 2:
The assessment system is designed with multi-functional capabilities to handle various types of data sources (internal logs, external threat feeds, vulnerability databases, third-party security reports) through a unified processing architecture. This universal approach manages complexity by providing a single integrated system that can process multiple data types rather than requiring separate systems for each source.
3Measurement precision
If comprehensive data analysis is performed to improve threat assessment accuracy, then the measurement precision improves, but the processing time increases
Solution Approach 1:
The patent implements automated data collection and preliminary analysis processes that continuously gather and pre-process security data before formal assessments are needed. Threat indicators, vulnerability information, and security events are pre-aggregated and validated, so when a formal assessment is required, the system can quickly retrieve and analyze pre-processed data, maintaining high accuracy without excessive processing delays.
Data Source
AI summary
The invention utilizes a two-component system to detect third party security threats and drive improved security threat mitigation based on the detection. The first component of the system is a security threat assessment engine, which receives and/or identifies external data and internal data regarding third parties in order to determine information security threats posed by third parties. The second component of the system is an analytics engine, which may comprise a machine learning component which is configured to detect threat patterns and anomalies. In response to the detection of the threat patterns and anomalies the security threat assessment engine may be modified in order to more accurately determine security threats.


