Threat Indicator Analytics Orchestrating Automated Network Responses
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security systems lack effective methods for identifying and mitigating evolving cyber-threats in real-time, particularly in defending against internal threats and automating responses to security incidents.
Innovation Solution
A computer-implemented method utilizing a management and process orchestration server to identify potential indicators of compromise, determine their credibility, and orchestrate automated responses, including network topology changes, through threat intelligence and analytics, leveraging deception networks and software-defined networking.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If automated threat analysis is implemented using isolated core environments, then threat detection capability is improved, but system complexity increases
Solution Approach 1:
The system divides the threat analysis function into isolated core components that can be independently executed in sandboxed environments. Each core represents a segmented unit of analysis that operates separately, reducing interdependencies and managing complexity while maintaining detection capability.
Solution Approach 2:
The patent introduces intermediary components including sandboxed execution environments and orchestration layers that mediate between the threat analysis cores and the main system. These intermediaries isolate complex operations from the core system, managing complexity while preserving detection effectiveness.
2Measurement precision
If comprehensive system monitoring and snapshotting is performed, then indicator identification accuracy is improved, but processing time increases
Solution Approach 1:
The system performs preliminary actions by continuously monitoring and maintaining snapshots of system state before threats fully manifest. Indicators of compromise are identified in advance through proactive snapshotting and analysis, improving detection accuracy while reducing the time needed for incident response.
Solution Approach 2:
The monitoring system operates continuously, maintaining ongoing snapshots and analysis rather than performing discrete periodic checks. This continuous operation ensures that indicators are identified accurately and promptly, balancing precision with processing efficiency.
3Reliability
If multiple credibility assessment metrics are applied to potential indicators, then threat indicator reliability is improved, but computational load increases
Solution Approach 1:
The system dynamically adjusts assessment parameters and thresholds based on the specific context and type of indicator being evaluated. Rather than applying all metrics uniformly, the system selects and weights parameters appropriately for each situation, improving reliability while managing computational resources efficiently.
Solution Approach 2:
The credibility assessment applies a tiered approach where basic metrics are always evaluated, and additional comprehensive metrics are applied selectively based on initial assessment results. This partial application of full assessment capabilities maintains reliability for critical indicators while reducing unnecessary computational load for lower-priority cases.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Methods, systems, and apparatus, including computer programs encoded on computer storage media, for analyzing threat intelligence information. One of the methods includes receiving by a threat information server, threat intelligence information from one or more intelligence feeds and generating one or more identified security threats, identifying a compromise by a management process orchestration server and retrieving information from the threat information server and identifying one or more actions to be performed, determining by an indicator analytics processor, a composite credibility based on the actions, and determining one or more components for profiling and determining indicators of compromise for each component, and communicating the indicators of compromise to the management process orchestration server.