Threat Indicator Distribution Automation for Endpoint Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current threat indicator management in information handling systems is inefficient, requiring manual processes and human intervention, leading to duplicated work and resource challenges, as threat indicators are not directly connected to specific systems or applications, and mapping to vulnerabilities often necessitates human expertise.

Innovation Solution

Implement automated methods and systems to integrate threat indicator characteristic information with application behavior patterns and information handling system types in real-time, allowing endpoint systems to perform threat detection and prevention, and enabling automatic distribution and application of threat indicators across networks, even in small and medium-sized organizations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual processes are used to evaluate and associate threat indicators with information handling systems and applications, then expertise and careful analysis can be applied, but the process requires significant human time and resources, and cannot be scaled efficiently

Engineering Contradiction:
Improvethreat indicator evaluation accuracyVSAvoidthreat indicator distribution efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system performs preliminary actions by automatically evaluating threat indicators, associating them with information handling system types and application types, and creating structured data sets before distribution. This preliminary automated processing eliminates the need for manual evaluation at each receiving organization, maintaining accuracy while enabling scalable distribution across many systems simultaneously

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates standardized data sets containing threat indicator information that can be copied and distributed to multiple information handling systems and organizations. These standardized templates ensure consistent evaluation criteria and association methods are applied uniformly across all recipients, maintaining measurement precision while enabling efficient replication and scaling

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If threat indicators are distributed manually to individual organizations, then each organization can apply them to their specific environment, but the process results in duplicated work and scarce resource utilization

Engineering Contradiction:
Improvethreat indicator application flexibilityVSAvoidthreat indicator distribution time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system creates universal data sets that contain threat indicator information structured to be applicable across multiple information handling system types and application types simultaneously. These standardized data sets can be distributed to numerous organizations at once, each able to apply them to their specific environments without requiring separate manual evaluation, thereby eliminating duplicated work while maintaining adaptability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary automated system that acts as a mediator between threat indicator sources and individual organizations. This intermediary performs the evaluation, association, and packaging of threat indicators into standardized data sets for distribution, eliminating the need for each organization to perform redundant manual work while still enabling customized application at the receiving end

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of information

If threat indicators are not directly connected to specific information handling system types and application types, then general threat intelligence can be shared, but mapping to specific vulnerabilities requires human intervention and expertise

Engineering Contradiction:
Improvethreat indicator characteristic informationVSAvoidthreat indicator mapping complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system segments threat indicator information into structured data sets that are specifically associated with information handling system types and application types. This segmentation organizes general threat intelligence into targeted categories, automatically linking indicators to specific vulnerability contexts without requiring manual mapping expertise at the receiving organization

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transforms threat indicator information by changing its parameters from general, unstructured intelligence into structured data sets with specific associations to information handling system types and application types. This parameter transformation automatically embeds vulnerability mapping information, eliminating the need for manual intervention while preserving all necessary threat indicator characteristics

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11704412B2Methods and systems for distribution and integration of threat indicators for information handling systems
Publication Date: 2023.07.18 DELL PROD LP
  • US11704412B2 patent drawing
  • US11704412B2 patent drawing
  • US11704412B2 patent drawing

AI summary

Methods and systems are provided that may be implemented in an automated manner to distribute and integrate information regarding threat indicators as they occur in real time. The provided methods and systems may be implemented to combine threat indicator characteristic information in real time with application behavior patterns, information handling system types, and/or application types; and to automatically apply the resulting intelligence together to improve malicious attack defense at the application and information handling system level at scale.