Network Threat Assessment via Sanitized Data Aggregation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Private computer networks face challenges in sharing network threat information due to reluctance to expose vulnerabilities, and existing security products lack effective mechanisms for dynamically predicting attacks based on previous patterns specific to industry, company, or geography.
Innovation Solution
A system and method for aggregating computer network threat information from multiple networks, where threat data is collected, correlated, and alerts are generated to alert potentially affected networks, using a central hub that sanitizes data to protect sensitive information and employs encryption to obscure client identities, enabling quick response to evolving threats and enhancing network security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If networks share threat information openly, then collective security improves, but networks expose their vulnerabilities and sensitive information
Solution Approach 1:
A central hub acts as an intermediary between client networks, receiving threat data, sanitizing sensitive information, and distributing alerts without exposing raw vulnerability data. The hub processes and anonymizes information before sharing, enabling security collaboration while protecting individual network confidentiality.
Solution Approach 2:
Sensitive identifying information and specific vulnerability details are extracted and removed from threat data before distribution. The system separates essential threat intelligence from confidential network-specific information, sharing only the sanitized portions that maintain security value without exposing sensitive details.
2Measurement precision
If manual threat analysis is performed, then accuracy improves, but response time to evolving threats decreases
Solution Approach 1:
The system performs automated threat analysis using correlation engines that automatically process received threat data, identify patterns, generate alerts, and update threat scores without human intervention. This self-service approach maintains analytical accuracy while dramatically reducing response time to evolving threats.
Solution Approach 2:
The system implements automated feedback loops where threat data from multiple networks is continuously correlated, analyzed, and used to generate real-time alerts. The correlation engine processes incoming data, compares it against known threat patterns, and automatically distributes alerts to affected networks, creating a rapid responsive feedback mechanism.
3Loss of information
If threat data is collected from multiple networks, then threat intelligence quality improves, but data privacy and security risks increase
Solution Approach 1:
The central hub serves as a trusted intermediary that collects threat data from multiple networks, sanitizes sensitive information, and distributes processed alerts. This intermediary approach enables aggregation of threat intelligence from diverse sources while protecting individual network privacy through controlled data processing and anonymization.
Solution Approach 2:
The system extracts and removes sensitive identifying information from collected threat data before analysis and distribution. By separating confidential network-specific details from essential threat intelligence, the system maintains high-quality threat intelligence while eliminating privacy risks associated with sharing raw data.
Data Source
Figure 1
Figure 2A~2B
Figure 2C~3A
AI summary
Systems and methods are disclosed for computer network threat assessment. For example, methods may include receiving from client networks respective threat data and storing the respective threat data in a security event database; maintaining affiliations for groups of the client networks; detecting correlation between a network threat and one of the groups; identifying an indicator associated with the network threat, and, dependent on the affiliation for the group, identifying a client network and generating a message, which conveys an alert to the client network, comprising the indicator; responsive to the message, receiving, from the client network, a report of detected correlation between the indicator and security event data maintained by the client network; and updating the security event database responsive to the report of detected correlation.