Cybersecurity Threat Intelligence Enrichment and Reputation Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional SIEM systems require network security analysts to manually investigate and respond to cybersecurity threats, which is inefficient due to the growing number of events and limited analyst resources, leading to compromised network security.
Innovation Solution
A cloud-based enrichment and analysis system that processes threat models, integrates various data feeds, and generates a reputation score to automate responses to cybersecurity threats, allowing analysts to focus on unknown threats and improving response times.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If conventional SIEM systems are used to generate and store security alerts in historical logs, then security events can be tracked and trends identified, but network security analysts require excessive time to investigate and respond to threats manually
Solution Approach 1:
The patent introduces an automated threat intelligence system that acts as an intermediary between SIEM alerts and analyst investigation. The system automatically enriches alerts with threat intelligence data, performs analysis, and generates actionable intelligence, thereby mediating the gap between raw alerts and informed response decisions without requiring direct analyst involvement in every alert investigation
Solution Approach 2:
The system enables self-service by automatically performing threat intelligence gathering, enrichment, and analysis functions that would otherwise require analyst time. The automated processes include collecting threat data from multiple sources, correlating it with organizational assets, assessing risk levels, and generating prioritized intelligence reports, allowing the security system to serve itself without constant analyst intervention
2Adaptability or versatility
If the number of cybersecurity events increases rapidly, then the scope of security monitoring must expand, but the limited number of qualified network security analysts cannot keep up with the growing volume of threats
Solution Approach 1:
The patent replaces the mechanical system of manual analyst investigation with an automated computational system. The automated threat intelligence platform performs data collection, enrichment, correlation, and analysis functions that would otherwise require human analysts, thereby substituting manual labor with automated processes that can scale indefinitely without being constrained by the availability of qualified personnel
Solution Approach 2:
The system achieves universality by designing a multi-functional automated platform that can handle diverse threat types (malware, phishing, DDoS, etc.), multiple data sources (threat feeds, logs, intelligence reports), and various enrichment techniques all through a single unified system, allowing it to adapt to any cybersecurity event without requiring specialized human expertise for each threat type
3Reliability
If manual investigation of security alerts is performed to obtain sufficient information for appropriate response, then response accuracy can be maintained, but the time required for adequate response becomes excessive and compromises network security
Solution Approach 1:
The system performs preliminary action by automatically gathering and preparing all necessary threat intelligence data before analyst review or automated response execution. The platform pre-enriches alerts with contextual information, pre-assesses risk levels, and pre-generates actionable intelligence, so that when responses are needed, the information is already prepared and validated, eliminating the need for time-consuming manual investigation while maintaining high response accuracy
Data Source
AI summary
Techniques are disclosed which can provide an orchestrated response to a cybersecurity threat. This orchestrated response may be based upon, at least in part, a reputation score. Threat model(s) may be received that identify cybersecurity threat(s). An indication of observations, false positives, and/or page views for the threat may be obtained. Data feeds may be received including known good data feeds, known bad data feeds, and enrichment data feeds. The data feeds may provide information about one or more indicators of compromise (IOC). For each IOC, a weighted criticality score may be determined. The weighted criticality score may be mapped to a corresponding point value. An aggregated score may be determined based upon at least the corresponding point value. A reputation score may be computed, and in some configurations, provided to a user.


