Threat Intelligence Aggregation and Normalization System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network administrators face challenges in aggregating and utilizing disparate threat intelligence feeds from various sources due to proprietary formats, varying validation, and reliability, leading to underutilization of threat information for defending information networks against malware.

Innovation Solution

A system that aggregates, normalizes, validates, and filters threat intelligence feeds from multiple sources, assigning threat scores and reformats the data to integrate with security tools like SIEM systems, ensuring real-time usability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If multiple proprietary threat intelligence feeds are aggregated, then the quantity of threat information increases, but the complexity of processing and integrating disparate formats increases

Engineering Contradiction:
Improvequantity of threat informationVSAvoidcomplexity of processing disparate formats
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent introduces a normalization layer as an intermediary component that receives threat intelligence feeds in various proprietary formats and converts them into a standardized internal representation. This mediator handles format conversion, field mapping, and data structure unification, allowing the system to aggregate multiple feeds without requiring complex custom integration logic for each source.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system applies parameter changes by transforming diverse threat intelligence data structures into a unified schema with standardized fields, data types, and formats. The normalization process modifies parameters such as timestamp formats, severity scales, and field naming conventions across all feeds to match a common structure, enabling consistent processing regardless of source format.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If threat intelligence feeds from multiple sources are combined, then the coverage of threat sources increases, but the reliability of the aggregated information decreases due to varying validation standards

Engineering Contradiction:
Improvecoverage of threat sourcesVSAvoidreliability of aggregated information
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements feedback mechanisms where the system continuously monitors the quality and reliability of incoming threat intelligence feeds. Validation rules and confidence scoring provide feedback about data quality, allowing the system to adjust processing priorities, filter low-quality feeds, and prioritize information from highly reliable sources while maintaining broad source coverage.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system applies local quality principles by treating different threat intelligence feeds with differentiated processing based on their individual reliability characteristics. Each feed source receives customized validation rules, filtering thresholds, and confidence weightings appropriate to its quality level, rather than applying uniform processing to all sources. This allows high-reliability feeds to contribute more significantly to the aggregated intelligence.

Inventive Principle:
Principle #3Local quality

3Reliability

If threat intelligence data is normalized and validated through multiple processing steps, then the quality of information improves, but the processing time increases

Engineering Contradiction:
Improvequality of threat intelligenceVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by implementing validation rules, confidence scoring, and quality checks at the point of data ingestion rather than delaying processing until later stages. The normalization framework pre-processes incoming feeds by validating formats, filtering obvious duplicates, and assigning initial confidence scores, so that downstream processing receives pre-filtered, pre-validates data ready for rapid analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The processing pipeline is segmented into distinct stages: initial validation and normalization, confidence scoring and filtering, and final aggregation. Each segment handles specific processing tasks independently and in parallel where possible, allowing the system to process different aspects of multiple feeds simultaneously rather than sequentially processing each feed through all validation steps.

Inventive Principle:
Principle #1Segmentation

4Speed

If threat intelligence feeds are processed in real-time, then the responsiveness to current threats improves, but the computational resources required increase

Engineering Contradiction:
Improveresponsiveness to threatsVSAvoidcomputational resources
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system applies partial action by implementing selective processing where not all threat intelligence feeds receive full validation and normalization processing at the same level of intensity. Low-risk feeds or those from highly trusted sources may receive streamlined processing, while feeds requiring extensive validation are processed more thoroughly but less frequently or with lower priority, balancing real-time responsiveness with resource conservation.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8813228B2Collective threat intelligence gathering system
Publication Date: 2014.08.19 DELOITTE DEVELOPMENT LLC
  • US8813228B2 patent drawing
  • US8813228B2 patent drawing
  • US8813228B2 patent drawing

AI summary

Threat intelligence is collected from a variety of different sources. The threat intelligence information is aggregated, normalized, filtered and scored to identify threats to an information network. Threats are categorized by type, maliciousness and confidence level. Threats are reported to network administrators in a plurality of threat feeds, including for example malicious domains, malicious IP addresses, malicious e-mail addresses, malicious URLs and malicious software files.