Automated Threat Indicator Aggregation and Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity threat indicator tracking systems face issues such as version control problems, limited intelligence pivoting, and the need for manual data compilation due to differences in data formats, leading to inefficiencies in mitigating active information security threats.
Innovation Solution
An automated system integrating modules for Indicator Management, Event Analysis, Adversary Profiling, and Sensor Grid to ingest, standardize, analyze, and distribute threat indicators, capable of parsing various data formats and providing actionable intelligence through automated processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If manual data compilation and analysis is used to handle different data formats, then flexibility in handling various formats is achieved, but time consumption and operational efficiency deteriorate
Solution Approach 1:
The patent replaces manual mechanical data compilation processes with automated computer-based systems that use standardized protocols (STIX, MACH) to automatically ingest, normalize, and analyze threat indicators from multiple sources, eliminating the time-consuming manual work while maintaining format adaptability
Solution Approach 2:
The system changes the parameter of data format handling by implementing automated normalization processes that convert various input formats into standardized representations, allowing the system to adapt to different formats without manual intervention and significantly reducing processing time
2Productivity
If automated systems are implemented for threat indicator management, then productivity and efficiency are improved, but system complexity increases
Solution Approach 1:
The patent segments the automated threat detection system into distinct functional modules: data ingestion components, normalization engines, analysis modules, and reporting systems. This segmentation allows high productivity through automation while managing complexity by organizing functions into independent, manageable units
Solution Approach 2:
The system implements universal standardized protocols (STIX, MACH) that enable a single automated platform to handle multiple data formats and threat types simultaneously, achieving high productivity without proportionally increasing complexity through multi-functional design
3Stability of the object's composition
If standardized formats are enforced for all threat indicators, then data consistency and automated processing are improved, but adaptability to diverse external formats deteriorates
Solution Approach 1:
The patent introduces intermediary normalization layers that act as mediators between diverse external data formats and the internal standardized representation. These intermediaries automatically translate incoming data into consistent formats, maintaining both data consistency and adaptability to diverse sources
Solution Approach 2:
The system performs preliminary format normalization and standardization as a preliminary action before data analysis and storage. This upfront conversion ensures data consistency throughout the system while maintaining the ability to accept various external formats, resolving the contradiction between standardization and adaptability
Data Source
AI summary
The systems and methods described herein generally relate to techniques for automated detection, aggregation, and integration of cybersecurity threats. The system ingests multiple data feeds which can be in one or numerous different formats. The system evaluates information based on defined scores to display to users threats and risks associated with them. The system also calculates decay rates for expiration of threats and indicators through various methods.


