Cybersecurity Threat Intelligence Enrichment and Reputation Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional SIEM systems require network security analysts to manually investigate and respond to cybersecurity threats, which is inefficient due to the growing number of events and limited analyst resources, leading to compromised network security.

Innovation Solution

A cloud-based enrichment and analysis system that processes threat models, integrates various data feeds, and generates a reputation score to automate responses to cybersecurity threats, allowing analysts to focus on unknown threats and improving response times.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If conventional SIEM systems are used to generate and store security alerts in historical logs, then security events can be tracked and trends identified, but network security analysts require excessive time to investigate and respond to threats manually

Engineering Contradiction:
Improvesecurity event tracking capabilityVSAvoidresponse time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent introduces an automated threat intelligence system that acts as an intermediary between SIEM alerts and analyst investigation. The system automatically enriches alerts with threat intelligence data, performs analysis, and generates actionable intelligence, thereby mediating the gap between raw alerts and informed response decisions without requiring direct analyst involvement in every alert investigation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by automatically performing threat intelligence gathering, enrichment, and analysis functions that would otherwise require analyst time. The automated processes include collecting threat data from multiple sources, correlating it with organizational assets, assessing risk levels, and generating prioritized intelligence reports, allowing the security system to serve itself without constant analyst intervention

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If the number of cybersecurity events increases rapidly, then the scope of security monitoring must expand, but the limited number of qualified network security analysts cannot keep up with the growing volume of threats

Engineering Contradiction:
Improvesecurity monitoring scopeVSAvoidthreat response capacity
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent replaces the mechanical system of manual analyst investigation with an automated computational system. The automated threat intelligence platform performs data collection, enrichment, correlation, and analysis functions that would otherwise require human analysts, thereby substituting manual labor with automated processes that can scale indefinitely without being constrained by the availability of qualified personnel

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system achieves universality by designing a multi-functional automated platform that can handle diverse threat types (malware, phishing, DDoS, etc.), multiple data sources (threat feeds, logs, intelligence reports), and various enrichment techniques all through a single unified system, allowing it to adapt to any cybersecurity event without requiring specialized human expertise for each threat type

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If manual investigation of security alerts is performed to obtain sufficient information for appropriate response, then response accuracy can be maintained, but the time required for adequate response becomes excessive and compromises network security

Engineering Contradiction:
Improveresponse accuracyVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by automatically gathering and preparing all necessary threat intelligence data before analyst review or automated response execution. The platform pre-enriches alerts with contextual information, pre-assesses risk levels, and pre-generates actionable intelligence, so that when responses are needed, the information is already prepared and validated, eliminating the need for time-consuming manual investigation while maintaining high response accuracy

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11245713B2Enrichment and analysis of cybersecurity threat intelligence and orchestrating application of threat intelligence to selected network security events
Publication Date: 2022.02.08 THREATCONNECT INC
  • US11245713B2 patent drawing
  • US11245713B2 patent drawing
  • US11245713B2 patent drawing

AI summary

Techniques are disclosed which can provide an orchestrated response to a cybersecurity threat. This orchestrated response may be based upon, at least in part, a reputation score. Threat model(s) may be received that identify cybersecurity threat(s). An indication of observations, false positives, and/or page views for the threat may be obtained. Data feeds may be received including known good data feeds, known bad data feeds, and enrichment data feeds. The data feeds may provide information about one or more indicators of compromise (IOC). For each IOC, a weighted criticality score may be determined. The weighted criticality score may be mapped to a corresponding point value. An aggregated score may be determined based upon at least the corresponding point value. A reputation score may be computed, and in some configurations, provided to a user.