Threat Intelligence Cloud for Real-Time Customized Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face challenges in effectively detecting and responding to unknown threats and variations of known threats due to universal, non-customized IPS signatures and the lack of global intelligence integration, leading to delayed manual adjustments that can allow infections to spread.

Innovation Solution

A system and method that correlates global threat intelligence with local intelligence through a threat intelligence cloud and event analysis sub-cloud, providing real-time customized security policies and updates to sensors and hosts, enabling proactive threat detection and response.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If universal IPS signatures are used for threat detection, then broad coverage is achieved, but detection precision for unknown and variant threats deteriorates

Engineering Contradiction:
Improvebroad coverageVSAvoiddetection precision
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent segments the monolithic IPS signature system into hierarchical components: universal signatures for broad coverage, customized signatures for specific threats, and behavioral analysis for unknown threats. This segmentation allows each component to operate at its optimal level, resolving the contradiction between broad coverage and detection precision.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by proactively generating customized signatures and updating sensors before threats fully propagate. Threat intelligence is collected and analyzed in advance, enabling preemptive deployment of targeted detection rules that improve precision without sacrificing broad coverage.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If manual adjustments are made to security policies, then customization is achieved, but response time deteriorates

Engineering Contradiction:
ImprovecustomizationVSAvoidresponse time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system implements self-service through automated signature generation and policy adjustment mechanisms. When threats are detected, the system automatically generates customized signatures and pushes updates to sensors without requiring manual administrator intervention, thereby achieving both customization and rapid response time.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system establishes feedback loops where threat detection results automatically trigger signature generation and policy updates. This closed-loop feedback mechanism enables continuous adaptation to new threats while maintaining rapid response times, eliminating the delay inherent in manual adjustment processes.

Inventive Principle:
Principle #23Feedback

3Reliability

If global intelligence integration is implemented, then threat detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an event analysis sub-cloud as an intermediary layer between local sensors and the global threat intelligence cloud. This intermediary aggregates events locally, performs preliminary analysis, and only transmits relevant information globally, thereby improving threat detection capability while managing system complexity through hierarchical abstraction.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If real-time updates are pushed to sensors, then protection effectiveness is improved, but network bandwidth consumption increases

Engineering Contradiction:
Improveprotection effectivenessVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system applies partial updates by pushing only the specific signature changes and threat intelligence relevant to each sensor's context, rather than transmitting complete policy sets. This selective update approach maintains protection effectiveness while significantly reducing network bandwidth consumption compared to full system updates.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2756439B1System and method for real-time customized threat protection
Publication Date: 2018.11.14 MCAFEE LLC
  • EP2756439B1 patent drawingFigure 1
  • EP2756439B1 patent drawingFigure 2
  • EP2756439B1 patent drawingFigure 3

AI summary

A method is provided in one example embodiment that includes receiving event information associated with reports from sensors distributed throughout a network environment and correlating the event information to identify a threat. A customized security policy based on the threat may be sent to the sensors.