Threat Intelligence Curation Through Normalized Reputation Scores
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing threat intelligence data from multiple sources is inconsistent, proprietary, and prone to staleness, leading to erroneous reputation scores and convoluted analysis, which can result in false positives and ineffective threat identification.
Innovation Solution
A method and device for curating threat intelligence data by normalizing reputation scores and associations using confidence values, and training machine learning models to identify threats based on entity associations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If threat intelligence data is collected from multiple proprietary sources, then the quantity and variety of threat data increases, but the consistency and reliability of reputation scores deteriorate due to different scales and enumerations
Solution Approach 1:
The patent transforms proprietary reputation scores from different sources by applying mathematical functions to map them to a common standardized scale. This parameter transformation allows aggregation of diverse threat intelligence data while maintaining reliability through normalization, resolving the contradiction between data quantity and score reliability.
Solution Approach 2:
The patent introduces an intermediary normalization layer that sits between multiple proprietary data sources and the threat analysis system. This intermediary component standardizes reputation scores from different sources onto a unified scale, enabling reliable aggregation without losing the benefits of multiple data sources.
2Quantity of substance
If threat intelligence data is aggregated from multiple sources, then the coverage of threat entities increases, but the complexity of data analysis increases due to inconsistent formats and proprietary enumerations
Solution Approach 1:
The patent applies parameter transformation to convert proprietary enumerations and formats from multiple sources into a standardized representation. This reduces analysis complexity by eliminating format inconsistencies while preserving the expanded entity coverage from multiple sources.
Solution Approach 2:
The patent segments the complex aggregation task into distinct processing stages: data collection, normalization, association detection, and analysis. This segmentation simplifies the overall complexity by handling each aspect separately with dedicated processing logic.
3Speed
If reputation scores are used to identify threats, then the speed of threat identification improves, but the accuracy deteriorates due to stale or outdated data
Solution Approach 1:
The patent implements feedback mechanisms where the system continuously monitors and updates reputation scores based on new threat intelligence data. This feedback loop ensures that scores remain current and accurate while maintaining the speed of identification through automated real-time updates.
Solution Approach 2:
The patent makes the reputation scoring system dynamic by continuously updating scores as new data arrives, rather than using static historical scores. This dynamic approach maintains accuracy while preserving fast identification through automated real-time score adjustments.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Described are examples for curating threat intelligence data including receiving threat intelligence data comprising a list of entities, one or more associations between entities, a reputation score for each entity, and/or a confidence value corresponding to the one or more associations. An updated reputation score for at least one of a first type of entities can be determined based at least in part on the confidence value and/or on determining a reputation score of at least one of a second type of entities to which the at least one of the first type of entities is associated in the one or more associations. The reputation score of the at least one of the first type of entities can be updated, in the threat intelligence data, to the updated reputation score.