Threat Intelligence Analysis System for Data Deduplication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for evaluating and managing security threats in enterprise networks face challenges in efficiently categorizing, prioritizing, and distributing threat intelligence from multiple sources, leading to duplicate data and confusion among stakeholders.
Innovation Solution
A method and system that identify and categorize intelligence types within datasets, associate subsets of data with these types, determine rules for third-party data distribution, and assign priorities to ensure relevant and accurate threat information is provided to stakeholders, reducing duplicates and improving expressiveness and relevance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If threat intelligence data from multiple sources is collected and aggregated, then the quantity and coverage of security threat information is improved, but duplicate data and confusion among stakeholders increase
Solution Approach 1:
The patent merges threat intelligence data from multiple sources by identifying and consolidating duplicate information. The system aggregates datasets, detects duplicates through comparison algorithms, and consolidates them into unified threat intelligence records, thereby maintaining data quantity while eliminating redundancy and confusion.
Solution Approach 2:
The patent creates a universal threat intelligence platform that handles multiple data sources, formats, and stakeholder requirements through a single system. This multi-functional system performs data collection, deduplication, prioritization, and distribution to various stakeholders, resolving confusion by providing a unified view of threat intelligence.
2Adaptability or versatility
If threat intelligence data is distributed to multiple third parties, then the relevance and operational value of security information is improved, but the complexity of data management and distribution increases
Solution Approach 1:
The patent segments threat intelligence data into priority levels (high, medium, low) based on severity and relevance criteria. This segmentation allows the system to manage distribution complexity by categorizing data into manageable groups that can be selectively distributed to appropriate third parties based on their specific needs and risk profiles.
Solution Approach 2:
The patent applies local quality by customizing threat intelligence distribution according to specific stakeholder requirements. Different third parties receive tailored subsets of threat data based on their organizational context, risk appetite, and security needs, thereby improving relevance while managing distribution complexity through targeted, rather than universal, data delivery.
3Measurement precision
If manual categorization and prioritization of threat intelligence is performed, then the accuracy of threat assessment is improved, but the time and resources required for processing increase
Solution Approach 1:
The patent implements self-service automation where the threat intelligence system automatically categorizes and prioritizes data using predefined criteria and algorithms. The system autonomously assigns priority levels, identifies relevant threats, and distributes information without requiring manual intervention, thereby maintaining assessment accuracy while dramatically reducing processing time and resource requirements.
Solution Approach 2:
The patent changes the parameters of threat assessment by introducing automated priority scoring based on multiple factors (threat severity, relevance to stakeholder, time sensitivity). This parameter-based automated classification system replaces manual categorization, achieving both high accuracy through multi-criteria evaluation and speed through algorithmic processing.
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
Methods, systems, and apparatus, including computer programs encoded on computer storage media, for analyzing data that includes security threat information. One of the methods includes identifying intelligence types that each categorizes a subset of data, associating, for each of the intelligence types, each of the subsets of data, which are categorized by the respective intelligence type, with the respective intelligence type, determining rules for a third party that each indicate that the third party should receive data associated with particular types of potential security threats and priority information for the data, determining, for each of the potential security threats indicated in the rules, a group of the subsets that include information associated with the respective potential security threat, assigning, for each subset in each of the groups, a priority to the respective subset using the priority information, and providing the determined subsets to the third party using the respective priorities.