Security Threat Assessment Engine with External Data Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information security systems lack effective methods to detect and mitigate security threats from third-party systems and applications, as they rely solely on internal data, neglecting external data sources that could provide critical threat information.

Innovation Solution

A two-component system comprising a security threat assessment engine and an analytics engine, where the assessment engine identifies and analyzes external and internal data to determine security threats and threat levels, utilizing machine learning to detect patterns and anomalies, and the analytics engine refines the threat assessment for more accurate predictions and mitigation plans.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If only internal data is used for security threat assessment, then the system is simpler to operate, but the detection accuracy and reliability of threat identification deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent combines internal data (from the entity's own systems) with external data (from third-party security feeds, vulnerability databases, and external monitoring sources) to create a comprehensive security threat assessment. This merging of data sources improves detection accuracy and reliability while the automated processing framework manages the complexity through standardized integration protocols.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If external data sources are integrated into the assessment system, then the reliability of threat detection improves, but the device complexity increases

Engineering Contradiction:
Improvethreat detection reliabilityVSAvoiddata integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an automated processing framework that acts as an intermediary between multiple external data sources and the core assessment engine. This framework standardizes data ingestion, validates inputs, and manages the complexity of integrating diverse external sources while improving detection reliability through comprehensive data collection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The assessment system is designed with multi-functional capabilities to handle various types of data sources (internal logs, external threat feeds, vulnerability databases, third-party security reports) through a unified processing architecture. This universal approach manages complexity by providing a single integrated system that can process multiple data types rather than requiring separate systems for each source.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If comprehensive data analysis is performed to improve threat assessment accuracy, then the measurement precision improves, but the processing time increases

Engineering Contradiction:
Improvethreat assessment accuracyVSAvoidassessment processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements automated data collection and preliminary analysis processes that continuously gather and pre-process security data before formal assessments are needed. Threat indicators, vulnerability information, and security events are pre-aggregated and validated, so when a formal assessment is required, the system can quickly retrieve and analyze pre-processed data, maintaining high accuracy without excessive processing delays.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10824734B2System for recurring information security threat assessment
Publication Date: 2020.11.03 BANK OF AMERICA CORP
  • US10824734B2 patent drawing
  • US10824734B2 patent drawing
  • US10824734B2 patent drawing

AI summary

The invention utilizes a two-component system to detect third party security threats and drive improved security threat mitigation based on the detection. The first component of the system is a security threat assessment engine, which receives and/or identifies external data and internal data regarding third parties in order to determine information security threats posed by third parties. The second component of the system is an analytics engine, which may comprise a machine learning component which is configured to detect threat patterns and anomalies. In response to the detection of the threat patterns and anomalies the security threat assessment engine may be modified in order to more accurately determine security threats.