Threat Information Model for Security Data Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in efficiently collecting and examining information about unknown and known vulnerabilities in components of products, particularly in control systems, which are complex and lack self-updating capabilities, making it difficult to detect security threats effectively.

Innovation Solution

A security information processing device and method that generates a threat information model using known threat information, collects candidate threat information from various sources, and detects potential security threats affecting the product using this model, enabling efficient examination of security threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual examination of threat information is performed, then detection accuracy is improved, but examination efficiency deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoidexamination efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent introduces an automated threat information examination system that acts as an intermediary between raw threat data and security decision-making. The system collects threat information from multiple sources, extracts relevant features, evaluates threats using predefined criteria, and presents structured results to security personnel, thereby maintaining high detection accuracy while dramatically improving examination efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual mechanical examination processes with automated computational systems. The threat information examination device uses algorithms to automatically collect, analyze, and evaluate threat data from multiple sources, substituting human analysts' manual work with automated processing that maintains accuracy while significantly increasing throughput and efficiency.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If comprehensive threat information collection is performed, then detection completeness is improved, but information complexity deteriorates

Engineering Contradiction:
Improvedetection completenessVSAvoidinformation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex threat information processing task into distinct functional modules: information collection from multiple sources, feature extraction, threat evaluation, and result presentation. Each module handles a specific aspect of the processing pipeline, making the overall system more manageable and reducing the perceived complexity while maintaining comprehensive detection capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces intermediate processing layers that transform raw, complex threat information into structured, evaluated results. The threat information examination device acts as an intermediary that collects comprehensive data from multiple sources, processes it through standardized evaluation criteria, and presents simplified, actionable intelligence to users, thereby maintaining detection completeness while reducing information complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If automated threat detection is implemented, then examination efficiency is improved, but detection precision deteriorates

Engineering Contradiction:
Improveexamination efficiencyVSAvoiddetection precision
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent implements feedback mechanisms where the automated system's detection results are reviewed and validated against established threat criteria and historical data. The system continuously refines its evaluation algorithms based on feedback from security analysts and actual threat outcomes, ensuring that automated processing maintains high detection precision while delivering improved examination efficiency.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent replaces manual examination with automated systems that use sophisticated algorithms and predefined evaluation criteria to maintain detection precision. The automated threat information examination device processes data through structured methodologies that preserve accuracy while dramatically improving efficiency, using computational methods that mimic and enhance human analytical capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11409888B2Security information processing device, information processing method, and recording medium
Publication Date: 2022.08.09 NEC CORP
  • US11409888B2 patent drawing
  • US11409888B2 patent drawing
  • US11409888B2 patent drawing

AI summary

An efficient examination of a security threat that may affect a product is enabled. A security information processing device includes threat information model generation means for generating, by use of first threat information including threat information indicating a threat related to security, a threat information model capable of classifying a piece of information as the threat information, collection means for collecting one or more threat information candidates each being a candidate for the threat information, from an information source providing information related to security, and detection means for detecting, by use of information about a component constituting a product and the threat information model, second threat information including the threat information that may affect the product, from the collected one or more threat information candidates.