Threat Intelligence Analysis System for Data Deduplication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for evaluating and managing security threats in enterprise networks face challenges in efficiently categorizing, prioritizing, and distributing threat intelligence from multiple sources, leading to duplicate data and confusion among stakeholders.

Innovation Solution

A method and system that identify and categorize intelligence types within datasets, associate subsets of data with these types, determine rules for third-party data distribution, and assign priorities to ensure relevant and accurate threat information is provided to stakeholders, reducing duplicates and improving expressiveness and relevance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If threat intelligence data from multiple sources is collected and aggregated, then the quantity and coverage of security threat information is improved, but duplicate data and confusion among stakeholders increase

Engineering Contradiction:
Improvequantity of threat intelligence dataVSAvoiddata duplication and confusion
Core Design Contradiction:
Quantity of substanceVSLoss of information

Solution Approach 1:

The patent merges threat intelligence data from multiple sources by identifying and consolidating duplicate information. The system aggregates datasets, detects duplicates through comparison algorithms, and consolidates them into unified threat intelligence records, thereby maintaining data quantity while eliminating redundancy and confusion.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal threat intelligence platform that handles multiple data sources, formats, and stakeholder requirements through a single system. This multi-functional system performs data collection, deduplication, prioritization, and distribution to various stakeholders, resolving confusion by providing a unified view of threat intelligence.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If threat intelligence data is distributed to multiple third parties, then the relevance and operational value of security information is improved, but the complexity of data management and distribution increases

Engineering Contradiction:
Improverelevance of threat intelligence to stakeholdersVSAvoidcomplexity of data distribution system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments threat intelligence data into priority levels (high, medium, low) based on severity and relevance criteria. This segmentation allows the system to manage distribution complexity by categorizing data into manageable groups that can be selectively distributed to appropriate third parties based on their specific needs and risk profiles.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by customizing threat intelligence distribution according to specific stakeholder requirements. Different third parties receive tailored subsets of threat data based on their organizational context, risk appetite, and security needs, thereby improving relevance while managing distribution complexity through targeted, rather than universal, data delivery.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If manual categorization and prioritization of threat intelligence is performed, then the accuracy of threat assessment is improved, but the time and resources required for processing increase

Engineering Contradiction:
Improveaccuracy of threat assessmentVSAvoidtime for data processing
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements self-service automation where the threat intelligence system automatically categorizes and prioritizes data using predefined criteria and algorithms. The system autonomously assigns priority levels, identifies relevant threats, and distributes information without requiring manual intervention, thereby maintaining assessment accuracy while dramatically reducing processing time and resource requirements.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the parameters of threat assessment by introducing automated priority scoring based on multiple factors (threat severity, relevance to stakeholder, time sensitivity). This parameter-based automated classification system replaces manual categorization, achieving both high accuracy through multi-criteria evaluation and speed through algorithmic processing.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2990984B1Security threat information analysis
Publication Date: 2020.07.15 ACCENTURE GLOBAL SERVICES LTD
  • EP2990984B1 patent drawingFigure 1
  • EP2990984B1 patent drawingFigure 2
  • EP2990984B1 patent drawingFigure 3A

AI summary

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for analyzing data that includes security threat information. One of the methods includes identifying intelligence types that each categorizes a subset of data, associating, for each of the intelligence types, each of the subsets of data, which are categorized by the respective intelligence type, with the respective intelligence type, determining rules for a third party that each indicate that the third party should receive data associated with particular types of potential security threats and priority information for the data, determining, for each of the potential security threats indicated in the rules, a group of the subsets that include information associated with the respective potential security threat, assigning, for each subset in each of the groups, a priority to the respective subset using the priority information, and providing the determined subsets to the third party using the respective priorities.