Cyber Threat Intelligence Reliability Update via Social Feedback

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber threat intelligence systems do not effectively reflect the reliability of user evaluations from social networking services (SNS) on cyber threat intelligence, limiting the efficiency and accuracy of analysis.

Innovation Solution

A cyber attack information processing apparatus and method that associates and updates the reliability of cyber threat intelligence based on the source of the information and user evaluations, using a system that integrates user terminals, a storage device, and a cyber threat intelligence management system to register, manage, and analyze cyber threat intelligence in a standardized format like STIX, incorporating user feedback to adjust reliability values.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If cyber threat intelligence is collected from multiple sources including social networking services, then the quantity and diversity of threat information increases, but the reliability and accuracy of the intelligence decreases due to unverified user evaluations

Engineering Contradiction:
Improvequantity of threat informationVSAvoidreliability of threat intelligence
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The system implements feedback mechanisms where user evaluations of cyber threat intelligence are collected, processed, and used to update reliability scores. The reliability information is then fed back into the system to influence future information collection and validation processes, creating a continuous improvement loop that balances quantity and quality of threat intelligence

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system enables self-service evaluation where users can independently assess and rate the reliability of cyber threat intelligence they encounter. This distributed evaluation approach allows the system to maintain reliability standards while scaling information collection across multiple sources including social networking services

Inventive Principle:
Principle #25Self-service

2Measurement precision

If user evaluations from social networking services are incorporated into reliability assessment, then the accuracy of threat intelligence improves, but the system complexity increases due to integration requirements

Engineering Contradiction:
Improveaccuracy of reliability assessmentVSAvoidsystem integration complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system introduces intermediary components including reliability information management units and evaluation processing modules that act as mediators between user evaluations from social networking services and the core threat intelligence system. These intermediaries standardize and process incoming evaluations, reducing the complexity of direct integration while maintaining measurement precision

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the reliability assessment process into distinct functional modules: evaluation collection, validation, scoring, and updating. This segmentation allows each component to handle specific tasks independently, reducing overall system complexity while improving the precision of reliability measurements through specialized processing at each stage

Inventive Principle:
Principle #1Segmentation

3Loss of time

If reliability is updated dynamically based on posted information, then the timeliness of threat intelligence improves, but the computational resources and time required for processing increase

Engineering Contradiction:
Improvetimeliness of threat intelligenceVSAvoidprocessing efficiency
Core Design Contradiction:
Loss of timeVSProductivity

Solution Approach 1:

The system implements periodic action by updating reliability information at scheduled intervals and triggering updates based on specific events such as new posted information or threshold crossings. This approach maintains timeliness of threat intelligence while avoiding continuous processing, thereby preserving computational efficiency and productivity

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10880337B2Social networking service analysis apparatus, social networking service analysis method, and computer-readable medium
Publication Date: 2020.12.29 FUJITSU LTD
  • US10880337B2 patent drawing
  • US10880337B2 patent drawing
  • US10880337B2 patent drawing

AI summary

A cyber attack information processing apparatus includes one or more memories, and one or more processors coupled to the one or more memories and the one or more processors configured to, when acquiring information regarding a first cyber attack, store the information in the one or more memories in association with reliability based on an acquisition source of the information, and when detecting that posted information related to the information is uploaded from a terminal, perform update of the reliability associated with the information in accordance with first reliability of the posted information.