Cyber Threat Intelligence Refinement System for Real-Time Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures, such as firewalls and anti-virus systems, are ineffective against evolving malware threats, leading to a need for real-time information and intelligence sharing to identify threat agents and targeted assets on the Internet, rather than relying on endless vulnerability patching and signature scanning.

Innovation Solution

A method of refining cyber threat intelligence data by sending threat lists to multiple sources, obtaining and combining original and new intelligence data, and creating updated threat lists to identify and prioritize potential threats, with a focus on threat intelligence reporting and delivery to network elements within or outside the carrier network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewalls and anti-virus systems are used for security protection, then existing malware can be detected and blocked, but the system becomes increasingly ineffective against evolving and unknown malware threats

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidcapability to detect new malware
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements feedback loops where threat intelligence data from multiple sources is continuously collected, analyzed, and used to update security measures. The refined cyber threat intelligence data is fed back into the network to dynamically adjust detection and response capabilities, enabling adaptive security against evolving threats rather than relying on static signatures.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary intelligence refinement system that sits between raw threat intelligence sources and security enforcement points. This intermediary processes and refines raw data from multiple sources, filtering and enhancing it to produce actionable intelligence that improves security effectiveness without directly implementing the security functions themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If vulnerability patching and signature scanning are performed continuously, then known malware can be addressed, but the process becomes endless and reactive rather than proactive

Engineering Contradiction:
Improvemalware protectionVSAvoidtime for security updates
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by proactively refining and preparing threat intelligence data before threats manifest as actual infections. By continuously analyzing traffic patterns and intelligence sources in advance, the system can identify and prepare countermeasures for emerging threats before they spread, rather than reacting after damage occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes continuity of useful action through ongoing intelligence refinement processes that operate continuously rather than in discrete cycles. The system maintains constant analysis and refinement of threat data streams, ensuring that security measures are always current and effective without the interruptions and delays associated with periodic updates.

Inventive Principle:
Principle #20Continuity of useful action

3Quantity of substance

If raw cyber threat intelligence data is collected from multiple sources, then comprehensive threat coverage is achieved, but the data requires significant processing and refinement

Engineering Contradiction:
Improvevolume of threat intelligence dataVSAvoiddata processing complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The system segments the complex data processing task into distinct functional modules: data collection from multiple sources, data refinement and analysis, and data delivery to network elements. This segmentation allows each module to specialize in specific processing functions, making the overall complex task manageable and scalable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges multiple raw intelligence sources into a unified refined output through systematic processing. By combining data from various sources and applying consistent refinement logic, the system achieves comprehensive threat coverage while producing standardized, actionable intelligence that reduces the complexity of consuming and applying the data.

Inventive Principle:
Principle #5Merging (Combining)

4Productivity

If real-time threat identification is implemented, then proactive security is achieved, but the system complexity increases

Engineering Contradiction:
Improvespeed of threat detectionVSAvoidsystem architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The intelligence refinement system serves as an intermediary layer that simplifies real-time threat identification by processing and prepping data before it reaches security enforcement points. This intermediary handles the complexity of multi-source data aggregation and analysis, presenting simplified, actionable intelligence to downstream systems without exposing them to the underlying complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9118702B2System and method for generating and refining cyber threat intelligence data
Publication Date: 2015.08.25 BCE
  • US9118702B2 patent drawing
  • US9118702B2 patent drawing
  • US9118702B2 patent drawing

AI summary

A method of refining cyber threat intelligence data, comprising: sending a first version of a threat list to a first cyber threat intelligence source and to a second cyber threat intelligence source; obtaining original first cyber threat intelligence data from the first source; obtaining original second cyber threat intelligence data from the second source; creating a second version of the threat list based on at least the original first cyber threat intelligence data and the original second cyber threat intelligence data; sending the second version of the threat list to the first source and to the second source; obtaining new first cyber threat intelligence data from the first source; obtaining new second cyber threat intelligence data from the second source; and creating a third version of the threat list based on at least the new first cyber threat intelligence data and the new second cyber threat intelligence data.