Threat Intelligence Platform for Malicious IP Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises and security solutions vendors face limited visibility into malicious internet activities, making it difficult to detect and manage sophisticated threats from evolving attack vectors, necessitating a system for real-time identification and sharing of threat IP addresses across networks.

Innovation Solution

A cloud-based system utilizing sensors to collect and analyze network activity data in real-time, combining first-hand observations with third-party sources, and employing HADOOP technology for scalable processing, threat verification through whitelisting and reputation analysis, and an aging process for threat IP addresses to manage risk effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If traditional security monitoring methods are used, then implementation complexity is low, but visibility into malicious internet activities is limited

Engineering Contradiction:
Improvevisibility into malicious activitiesVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent combines multiple data sources including first-hand sensor observations, third-party threat intelligence feeds, and open-source intelligence into a unified threat intelligence platform. This merging of diverse information sources resolves the contradiction by significantly improving visibility into malicious activities while distributing the complexity across multiple integrated components rather than requiring a single complex system.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces cloud-based threat intelligence platforms and data aggregation services as intermediaries between raw network traffic and security analysis systems. These intermediaries pre-process and consolidate threat data from multiple sources, providing enhanced visibility to security systems without requiring them to directly handle the complexity of collecting and processing raw data from numerous sources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If real-time threat identification is implemented, then response time to threats is reduced, but data processing requirements increase

Engineering Contradiction:
Improvethreat detection timeVSAvoiddata processing power
Core Design Contradiction:
Loss of timeVSPower

Solution Approach 1:

The patent implements preliminary processing of threat data through sensor collection and initial filtering before data reaches the main analysis system. Threat indicators are pre-processed, aggregated, and validated in advance, allowing real-time detection to occur with reduced computational burden on the primary processing system while maintaining rapid response times.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the data processing architecture into distributed components including edge sensors, regional aggregation points, and central analysis platforms. This segmentation allows real-time processing to occur at multiple levels simultaneously, reducing the computational power required at any single point while enabling fast threat detection through distributed parallel processing.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If comprehensive threat data collection is performed, then threat identification accuracy is improved, but data volume to be processed increases

Engineering Contradiction:
Improvethreat identification accuracyVSAvoiddata volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts and focuses on specific high-value threat indicators from comprehensive data collections, such as malicious IP addresses, suspicious domain names, and known attack patterns. By extracting only the most relevant threat signals from the broader data set, the system maintains high identification accuracy while reducing the volume of data requiring intensive processing and analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transforms comprehensive raw threat data into standardized threat intelligence parameters with defined formats, severity levels, and classification schemes. This parameter transformation consolidates diverse data into structured information that maintains analytical accuracy while reducing data volume through normalization and aggregation of related threat indicators.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8561187B1System and method for prosecuting dangerous IP addresses on the internet
Publication Date: 2013.10.15 OPEN TEXT CORPORATION
  • US8561187B1 patent drawing
  • US8561187B1 patent drawing
  • US8561187B1 patent drawing

AI summary

A method and system for prosecuting threatening IP addresses on the Internet and publishing a list of these threatening IP addresses for users to block is disclosed herein. If the IP address behaves properly according to a policy adhered to by the users, then the IP address may be paroled and removed from the list.