Threat Indicator Analytics Orchestrating Automated Network Responses

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems lack effective methods for identifying and mitigating evolving cyber-threats in real-time, particularly in defending against internal threats and automating responses to security incidents.

Innovation Solution

A computer-implemented method utilizing a management and process orchestration server to identify potential indicators of compromise, determine their credibility, and orchestrate automated responses, including network topology changes, through threat intelligence and analytics, leveraging deception networks and software-defined networking.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If automated threat analysis is implemented using isolated core environments, then threat detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the threat analysis function into isolated core components that can be independently executed in sandboxed environments. Each core represents a segmented unit of analysis that operates separately, reducing interdependencies and managing complexity while maintaining detection capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components including sandboxed execution environments and orchestration layers that mediate between the threat analysis cores and the main system. These intermediaries isolate complex operations from the core system, managing complexity while preserving detection effectiveness.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive system monitoring and snapshotting is performed, then indicator identification accuracy is improved, but processing time increases

Engineering Contradiction:
Improveindicator identification accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously monitoring and maintaining snapshots of system state before threats fully manifest. Indicators of compromise are identified in advance through proactive snapshotting and analysis, improving detection accuracy while reducing the time needed for incident response.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The monitoring system operates continuously, maintaining ongoing snapshots and analysis rather than performing discrete periodic checks. This continuous operation ensures that indicators are identified accurately and promptly, balancing precision with processing efficiency.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If multiple credibility assessment metrics are applied to potential indicators, then threat indicator reliability is improved, but computational load increases

Engineering Contradiction:
Improvethreat indicator reliabilityVSAvoidcomputational load
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system dynamically adjusts assessment parameters and thresholds based on the specific context and type of indicator being evaluated. Rather than applying all metrics uniformly, the system selects and weights parameters appropriately for each situation, improving reliability while managing computational resources efficiently.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The credibility assessment applies a tiered approach where basic metrics are always evaluated, and additional comprehensive metrics are applied selectively based on initial assessment results. This partial application of full assessment capabilities maintains reliability for critical indicators while reducing unnecessary computational load for lower-priority cases.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2955895B1Threat indicator analytics system
Publication Date: 2019.10.16 ACCENTURE GLOBAL SERVICES LTD
  • EP2955895B1 patent drawingFigure 1
  • EP2955895B1 patent drawingFigure 2
  • EP2955895B1 patent drawingFigure 3

AI summary

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for analyzing threat intelligence information. One of the methods includes receiving by a threat information server, threat intelligence information from one or more intelligence feeds and generating one or more identified security threats, identifying a compromise by a management process orchestration server and retrieving information from the threat information server and identifying one or more actions to be performed, determining by an indicator analytics processor, a composite credibility based on the actions, and determining one or more components for profiling and determining indicators of compromise for each component, and communicating the indicators of compromise to the management process orchestration server.