Threat Data Platform With Asynchronous Scoring and Auto Investigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise networks face challenges in effectively monitoring and investigating sophisticated security threats due to their complexity, necessitating improved techniques for integrating and analyzing threat data from various sources.
Innovation Solution
A platform that integrates threat data from internal and external sources, including cloud-based applications, to automatically launch investigations when a composite threat score meets a predetermined threshold, using a threat management facility that updates threat assessments asynchronously and creates investigation containers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If threat data from multiple internal and external sources is integrated and continuously updated, then threat detection accuracy and completeness improve, but system complexity and data processing requirements increase
Solution Approach 1:
The system segments threat data processing by creating separate data lakes for different data sources (internal security events, cloud resource data, contextual data) and uses modular processing components including data ingestion modules, processing modules, and storage modules that can independently handle specific data types
Solution Approach 2:
The patent introduces intermediary components including event stream processors that mediate between raw data sources and analysis systems, and investigation containers that serve as intermediaries between threat detection and investigator review, managing the complexity of multi-source data integration
2Loss of time
If real-time threat monitoring and automatic investigation launch are implemented, then response time to security threats improves, but computational resources and processing power increase
Solution Approach 1:
The system applies partial action by using incremental updates to threat assessments rather than complete re-evaluations, and by selectively launching investigations only when composite threat scores meet predetermined thresholds, avoiding unnecessary full-system processing
Solution Approach 2:
The patent implements preliminary action through pre-configured threat score thresholds and pre-established investigation templates, allowing the system to quickly respond to threats by comparing incoming data against predetermined criteria rather than performing complex analysis from scratch
3Loss of information
If comprehensive threat data collection from diverse sources is performed, then threat investigation completeness improves, but data integration difficulty and processing time increase
Solution Approach 1:
The system implements universality through a standardized data lake architecture that can ingest and store multiple data types (security events, cloud resource data, contextual data) from diverse sources using common schemas and formats, enabling efficient querying and analysis across all data types
Data Source
AI summary
A platform for managing threat data integrates threat data from a variety of sources including internal threat data from instrumented compute instances associated with an enterprise network and threat data from one or more independent, external resources. Threat assessments are incrementally revised as this threat data is asynchronously received from various sources, and a threat intervention container is automatically created and presented to an investigator when a composite threat score for one or more of the compute instances meets a predetermined threshold.


