Threat Data Platform With Asynchronous Scoring and Auto Investigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise networks face challenges in effectively monitoring and investigating sophisticated security threats due to their complexity, necessitating improved techniques for integrating and analyzing threat data from various sources.

Innovation Solution

A platform that integrates threat data from internal and external sources, including cloud-based applications, to automatically launch investigations when a composite threat score meets a predetermined threshold, using a threat management facility that updates threat assessments asynchronously and creates investigation containers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If threat data from multiple internal and external sources is integrated and continuously updated, then threat detection accuracy and completeness improve, but system complexity and data processing requirements increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments threat data processing by creating separate data lakes for different data sources (internal security events, cloud resource data, contextual data) and uses modular processing components including data ingestion modules, processing modules, and storage modules that can independently handle specific data types

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components including event stream processors that mediate between raw data sources and analysis systems, and investigation containers that serve as intermediaries between threat detection and investigator review, managing the complexity of multi-source data integration

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If real-time threat monitoring and automatic investigation launch are implemented, then response time to security threats improves, but computational resources and processing power increase

Engineering Contradiction:
Improveresponse timeVSAvoidcomputational resources
Core Design Contradiction:
Loss of timeVSUse of energy by moving object

Solution Approach 1:

The system applies partial action by using incremental updates to threat assessments rather than complete re-evaluations, and by selectively launching investigations only when composite threat scores meet predetermined thresholds, avoiding unnecessary full-system processing

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent implements preliminary action through pre-configured threat score thresholds and pre-established investigation templates, allowing the system to quickly respond to threats by comparing incoming data against predetermined criteria rather than performing complex analysis from scratch

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If comprehensive threat data collection from diverse sources is performed, then threat investigation completeness improves, but data integration difficulty and processing time increase

Engineering Contradiction:
Improvethreat investigation completenessVSAvoiddata processing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system implements universality through a standardized data lake architecture that can ingest and store multiple data types (security events, cloud resource data, contextual data) from diverse sources using common schemas and formats, enabling efficient querying and analysis across all data types

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20260046294A1Platform for managing threat data
Publication Date: 2026.02.12 SOPHOS LTD
  • US20260046294A1 patent drawing
  • US20260046294A1 patent drawing
  • US20260046294A1 patent drawing

AI summary

A platform for managing threat data integrates threat data from a variety of sources including internal threat data from instrumented compute instances associated with an enterprise network and threat data from one or more independent, external resources. Threat assessments are incrementally revised as this threat data is asynchronously received from various sources, and a threat intervention container is automatically created and presented to an investigator when a composite threat score for one or more of the compute instances meets a predetermined threshold.