Threat Intelligence Aggregation and Normalization System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network administrators face challenges in aggregating and utilizing disparate threat intelligence feeds from various sources due to proprietary formats, varying validation, and reliability, leading to underutilization of threat information for defending information networks against malware.
Innovation Solution
A system that aggregates, normalizes, validates, and filters threat intelligence feeds from multiple sources, assigning threat scores and reformats the data to integrate with security tools like SIEM systems, ensuring real-time usability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If multiple proprietary threat intelligence feeds are aggregated, then the quantity of threat information increases, but the complexity of processing and integrating disparate formats increases
Solution Approach 1:
The patent introduces a normalization layer as an intermediary component that receives threat intelligence feeds in various proprietary formats and converts them into a standardized internal representation. This mediator handles format conversion, field mapping, and data structure unification, allowing the system to aggregate multiple feeds without requiring complex custom integration logic for each source.
Solution Approach 2:
The system applies parameter changes by transforming diverse threat intelligence data structures into a unified schema with standardized fields, data types, and formats. The normalization process modifies parameters such as timestamp formats, severity scales, and field naming conventions across all feeds to match a common structure, enabling consistent processing regardless of source format.
2Adaptability or versatility
If threat intelligence feeds from multiple sources are combined, then the coverage of threat sources increases, but the reliability of the aggregated information decreases due to varying validation standards
Solution Approach 1:
The patent implements feedback mechanisms where the system continuously monitors the quality and reliability of incoming threat intelligence feeds. Validation rules and confidence scoring provide feedback about data quality, allowing the system to adjust processing priorities, filter low-quality feeds, and prioritize information from highly reliable sources while maintaining broad source coverage.
Solution Approach 2:
The system applies local quality principles by treating different threat intelligence feeds with differentiated processing based on their individual reliability characteristics. Each feed source receives customized validation rules, filtering thresholds, and confidence weightings appropriate to its quality level, rather than applying uniform processing to all sources. This allows high-reliability feeds to contribute more significantly to the aggregated intelligence.
3Reliability
If threat intelligence data is normalized and validated through multiple processing steps, then the quality of information improves, but the processing time increases
Solution Approach 1:
The patent applies preliminary action by implementing validation rules, confidence scoring, and quality checks at the point of data ingestion rather than delaying processing until later stages. The normalization framework pre-processes incoming feeds by validating formats, filtering obvious duplicates, and assigning initial confidence scores, so that downstream processing receives pre-filtered, pre-validates data ready for rapid analysis.
Solution Approach 2:
The processing pipeline is segmented into distinct stages: initial validation and normalization, confidence scoring and filtering, and final aggregation. Each segment handles specific processing tasks independently and in parallel where possible, allowing the system to process different aspects of multiple feeds simultaneously rather than sequentially processing each feed through all validation steps.
4Speed
If threat intelligence feeds are processed in real-time, then the responsiveness to current threats improves, but the computational resources required increase
Solution Approach 1:
The system applies partial action by implementing selective processing where not all threat intelligence feeds receive full validation and normalization processing at the same level of intensity. Low-risk feeds or those from highly trusted sources may receive streamlined processing, while feeds requiring extensive validation are processed more thoroughly but less frequently or with lower priority, balancing real-time responsiveness with resource conservation.
Data Source
AI summary
Threat intelligence is collected from a variety of different sources. The threat intelligence information is aggregated, normalized, filtered and scored to identify threats to an information network. Threats are categorized by type, maliciousness and confidence level. Threats are reported to network administrators in a plurality of threat feeds, including for example malicious domains, malicious IP addresses, malicious e-mail addresses, malicious URLs and malicious software files.


