Automated Threat Indicator Aggregation and Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity threat indicator tracking systems face issues such as version control problems, limited intelligence pivoting, and the need for manual data compilation due to differences in data formats, leading to inefficiencies in mitigating active information security threats.

Innovation Solution

An automated system integrating modules for Indicator Management, Event Analysis, Adversary Profiling, and Sensor Grid to ingest, standardize, analyze, and distribute threat indicators, capable of parsing various data formats and providing actionable intelligence through automated processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If manual data compilation and analysis is used to handle different data formats, then flexibility in handling various formats is achieved, but time consumption and operational efficiency deteriorate

Engineering Contradiction:
Improvecapability to handle various data formatsVSAvoidtime for data compilation and analysis
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical data compilation processes with automated computer-based systems that use standardized protocols (STIX, MACH) to automatically ingest, normalize, and analyze threat indicators from multiple sources, eliminating the time-consuming manual work while maintaining format adaptability

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system changes the parameter of data format handling by implementing automated normalization processes that convert various input formats into standardized representations, allowing the system to adapt to different formats without manual intervention and significantly reducing processing time

Inventive Principle:
Principle #35Parameter changes

2Productivity

If automated systems are implemented for threat indicator management, then productivity and efficiency are improved, but system complexity increases

Engineering Contradiction:
Improvethreat detection and analysis efficiencyVSAvoidsystem architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the automated threat detection system into distinct functional modules: data ingestion components, normalization engines, analysis modules, and reporting systems. This segmentation allows high productivity through automation while managing complexity by organizing functions into independent, manageable units

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements universal standardized protocols (STIX, MACH) that enable a single automated platform to handle multiple data formats and threat types simultaneously, achieving high productivity without proportionally increasing complexity through multi-functional design

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Stability of the object's composition

If standardized formats are enforced for all threat indicators, then data consistency and automated processing are improved, but adaptability to diverse external formats deteriorates

Engineering Contradiction:
Improvedata format consistencyVSAvoidability to ingest various external formats
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The patent introduces intermediary normalization layers that act as mediators between diverse external data formats and the internal standardized representation. These intermediaries automatically translate incoming data into consistent formats, maintaining both data consistency and adaptability to diverse sources

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary format normalization and standardization as a preliminary action before data analysis and storage. This upfront conversion ensures data consistency throughout the system while maintaining the ability to accept various external formats, resolving the contradiction between standardization and adaptability

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12019740B2Automated cybersecurity threat detection with aggregation and analysis
Publication Date: 2024.06.25 SECURONIX INC
  • US12019740B2 patent drawing
  • US12019740B2 patent drawing
  • US12019740B2 patent drawing

AI summary

The systems and methods described herein generally relate to techniques for automated detection, aggregation, and integration of cybersecurity threats. The system ingests multiple data feeds which can be in one or numerous different formats. The system evaluates information based on defined scores to display to users threats and risks associated with them. The system also calculates decay rates for expiration of threats and indicators through various methods.