Threat Exchange Server for Proactive Attack Notification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computing systems face challenges in detecting and mitigating security attacks due to resource limitations and the inability to take preventive measures until an attack is successful, leading to potential undetected attacks and damage.

Innovation Solution

A threat exchange server that clusters entities based on shared characteristics, analyzes security-related data in real-time to identify attack patterns, and sends early warnings to vulnerable entities, allowing for proactive measures to be taken before an attack is completed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If entities monitor security attacks independently using their own resources, then detection capability is limited to individual entity scope, but resource consumption increases for each entity and detection coverage remains incomplete

Engineering Contradiction:
Improveattack detection capabilityVSAvoidresources consumed
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges security monitoring resources across multiple entities by creating a federated system where security events from different entities are aggregated and analyzed collectively. This allows shared detection capabilities without requiring each entity to maintain full independent monitoring resources, thus improving detection reliability while optimizing resource consumption.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system creates universal security analysis capabilities that serve multiple entities simultaneously. A single analysis engine can process security events from various entities, providing multi-functional detection services that benefit all participating entities without requiring duplicate specialized resources at each entity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If entities wait to detect attacks after they occur, then resource consumption is reduced by not maintaining constant monitoring, but attacks cause damage before detection and prevention is impossible

Engineering Contradiction:
Improvepreventive security capabilityVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary security analysis by continuously monitoring and analyzing security events before actual attacks complete their damage. By detecting attack patterns in early stages across multiple entities, the system enables preventive actions to be taken before attacks succeed, rather than waiting for damage to occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where security events from one entity inform detection capabilities for other entities. When an attack pattern is detected at one entity, this information is fed back to the collective system, enabling other entities to preemptively defend against similar attacks before they occur.

Inventive Principle:
Principle #23Feedback

3Reliability

If entities share security data across all entities, then detection capability improves through collective intelligence, but data privacy and security risks increase

Engineering Contradiction:
Improvecollective detection capabilityVSAvoidprivacy and security risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments security data sharing into controlled portions rather than complete data exchange. Entities share specific security event types or aggregated patterns rather than all raw data, enabling collective detection capability while maintaining boundaries that protect privacy and reduce security risks associated with full data exposure.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9456001B2Attack notification
Publication Date: 2016.09.27 MICRO FOCUS LLC
  • US9456001B2 patent drawing
  • US9456001B2 patent drawing
  • US9456001B2 patent drawing

AI summary

Systems, methods, and machine-readable and executable instructions are provided for attack notification. Attack notification can include receiving security-related data from a number of computing devices that are associated with a number of entities through a communication link and analyzing a first portion of the security-related data that is associated with a first entity from the number of entities to determine whether the first entity has experienced an attack. Attack notification can include analyzing a second portion of the security-related data that is associated with a second entity from the number of entities and the first portion of the security-related data that is associated with the first entity to determine whether the second entity is experiencing the attack. Attack notification can include notifying, through the communication link, the second entity that the second entity is experiencing the attack if it is determined that the second entity is experiencing the attack.