Threat Intelligence Curation Through Normalized Reputation Scores

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing threat intelligence data from multiple sources is inconsistent, proprietary, and prone to staleness, leading to erroneous reputation scores and convoluted analysis, which can result in false positives and ineffective threat identification.

Innovation Solution

A method and device for curating threat intelligence data by normalizing reputation scores and associations using confidence values, and training machine learning models to identify threats based on entity associations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If threat intelligence data is collected from multiple proprietary sources, then the quantity and variety of threat data increases, but the consistency and reliability of reputation scores deteriorate due to different scales and enumerations

Engineering Contradiction:
Improvequantity of threat intelligence dataVSAvoidreliability of reputation scores
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent transforms proprietary reputation scores from different sources by applying mathematical functions to map them to a common standardized scale. This parameter transformation allows aggregation of diverse threat intelligence data while maintaining reliability through normalization, resolving the contradiction between data quantity and score reliability.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary normalization layer that sits between multiple proprietary data sources and the threat analysis system. This intermediary component standardizes reputation scores from different sources onto a unified scale, enabling reliable aggregation without losing the benefits of multiple data sources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If threat intelligence data is aggregated from multiple sources, then the coverage of threat entities increases, but the complexity of data analysis increases due to inconsistent formats and proprietary enumerations

Engineering Contradiction:
Improvecoverage of threat entitiesVSAvoidcomplexity of data analysis
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent applies parameter transformation to convert proprietary enumerations and formats from multiple sources into a standardized representation. This reduces analysis complexity by eliminating format inconsistencies while preserving the expanded entity coverage from multiple sources.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent segments the complex aggregation task into distinct processing stages: data collection, normalization, association detection, and analysis. This segmentation simplifies the overall complexity by handling each aspect separately with dedicated processing logic.

Inventive Principle:
Principle #1Segmentation

3Speed

If reputation scores are used to identify threats, then the speed of threat identification improves, but the accuracy deteriorates due to stale or outdated data

Engineering Contradiction:
Improvespeed of threat identificationVSAvoidaccuracy of threat assessment
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The patent implements feedback mechanisms where the system continuously monitors and updates reputation scores based on new threat intelligence data. This feedback loop ensures that scores remain current and accurate while maintaining the speed of identification through automated real-time updates.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent makes the reputation scoring system dynamic by continuously updating scores as new data arrives, rather than using static historical scores. This dynamic approach maintains accuracy while preserving fast identification through automated real-time score adjustments.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3769248B1Techniques for curating threat intelligence data
Publication Date: 2025.08.06 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3769248B1 patent drawingFigure 1
  • EP3769248B1 patent drawingFigure 2
  • EP3769248B1 patent drawingFigure 3

AI summary

Described are examples for curating threat intelligence data including receiving threat intelligence data comprising a list of entities, one or more associations between entities, a reputation score for each entity, and/or a confidence value corresponding to the one or more associations. An updated reputation score for at least one of a first type of entities can be determined based at least in part on the confidence value and/or on determining a reputation score of at least one of a second type of entities to which the at least one of the first type of entities is associated in the one or more associations. The reputation score of the at least one of the first type of entities can be updated, in the threat intelligence data, to the updated reputation score.