Threat Management System with Automated Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managed services systems face challenges in effectively monitoring and responding to security threats and policy compliance across diverse customer assets and networks, as existing solutions are cumbersome and difficult to implement.

Innovation Solution

A tailored threat management system that includes a network architecture with modules for centralizing asset and threat data, prioritizing threat handling, and utilizing correlation and visualization tools to facilitate proactive threat identification and response, enabling granular access controls and integrated workflow management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security monitoring systems are used to track individual user assets and threats, then security coverage can be achieved, but the system becomes cumbersome and difficult to operate

Engineering Contradiction:
Improvesecurity monitoring effectivenessVSAvoidsystem operation difficulty
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments security management into two layers: automated granular monitoring of individual user assets and threats, combined with centralized policy management. This segmentation allows comprehensive security coverage while reducing operational complexity through automation and hierarchical structuring.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer that automatically correlates user details, assets at risk, and threat information. This intermediary processing layer shields operators from the complexity of individual user data while maintaining effective security monitoring, thus improving ease of operation without sacrificing reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If detailed individual user information is collected for threat management, then personalized security policies can be implemented, but system complexity increases

Engineering Contradiction:
Improvecustomized security policy capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system adds a new dimension of automated data correlation and policy mapping that transforms complex multi-dimensional user information into simplified policy enforcement rules. This dimensional transformation allows customized security policies without proportionally increasing system complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The system implements self-service mechanisms where the threat management platform automatically collects, correlates, and processes user information and asset data without requiring manual configuration. This automation reduces system complexity while maintaining the ability to implement personalized security policies.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If comprehensive threat data parsing is performed for each user, then accurate threat identification is achieved, but processing time and resources increase

Engineering Contradiction:
Improvethreat identification accuracyVSAvoidthreat processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-collecting and organizing user asset information and threat data in structured formats. This preliminary preparation enables rapid and accurate threat identification when needed, reducing processing time while maintaining measurement precision through advance data organization.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual or mechanical threat data parsing with automated electronic correlation systems that use predefined rules and algorithms to rapidly process user information, assets, and threats. This substitution maintains accurate threat identification while dramatically reducing processing time and resource requirements.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8220056B2Threat management system and method
Publication Date: 2012.07.10 COLORADO WSC LLC
  • US8220056B2 patent drawing
  • US8220056B2 patent drawing
  • US8220056B2 patent drawing

AI summary

In a threat management system and method for managed systems, leveraging of identifications and/or assessments of common threats, and/or valuation of assets which may be susceptible to common threats, can be applied to facilitate monitoring of customer compliance with policies needed to guard against threats to customer assets. Threat identification and response in managed systems may be tailored for different customers, in some instances without having to parse individual customer details, such as assets at risk and types of threats to those assets.