Threat Mapping Engine for Bad Actor Network Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for addressing online threats are inadequate as they focus on known threats and fail to capture the entire scope of a bad actor's operations, allowing unknown threats to remain operational and new threats to emerge quickly, especially in complex networks with multiple online presences.

Innovation Solution

A threat mapping engine system that includes a vertex discovery harvester, edge extractor, vertex correlator, and recursive graph builder to identify and map connections between vertices, determining threat scores and generating a threat graph to visualize and quantify the threat landscape.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional takedown methods are used to remove known threats, then individual known threats are eliminated, but unknown threats remain operational and new threats emerge quickly

Engineering Contradiction:
Improvethreat elimination effectivenessVSAvoidscope of bad actor operations
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system segments the threat landscape into discrete vertices (online presences) and edges (connections), allowing individual threats to be identified and eliminated while preserving information about the overall network structure. This enables continuous threat removal without losing sight of the broader operational scope of bad actors.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a one-dimensional list of known threats to a multi-dimensional threat graph that maps relationships across multiple platforms and vectors. This dimensional expansion allows simultaneous visualization of both individual threats and the comprehensive scope of bad actor operations, resolving the contradiction between eliminating specific threats and understanding overall threat landscapes.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Loss of information

If a comprehensive threat graph is generated to capture all bad actor operations, then the entire scope of operations is revealed, but the complexity of data processing and graph generation increases

Engineering Contradiction:
Improvecompleteness of threat scopeVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system divides the complex task of threat analysis into modular subsystems: vertex discovery harvesters that collect individual online presences, edge extractors that identify connections, and graph generation components that assemble the threat landscape. This segmentation reduces processing complexity while maintaining comprehensive threat coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements iterative graph generation that can operate at varying levels of completeness. Users can generate partial threat graphs focusing on specific platforms or time periods, or execute comprehensive analyses when resources permit. This flexible approach manages processing complexity while preserving the option for complete threat scope analysis.

Inventive Principle:
Principle #16Partial or excessive action

3Loss of information

If multiple online presences are monitored to capture all threat vectors, then comprehensive threat coverage is achieved, but the difficulty of detecting and measuring connections between presences increases

Engineering Contradiction:
Improvethreat coverageVSAvoidconnection detection complexity
Core Design Contradiction:
Loss of informationVSDifficulty of detecting and measuring

Solution Approach 1:

The system introduces automated edge extractors as intermediary components that mediate between vertex discovery (collecting online presences) and graph generation (visualizing connections). These extractors apply standardized algorithms to identify relationships across diverse platforms, reducing the complexity of detecting and measuring connections while maintaining comprehensive threat coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates standardized data representations (vertices and edges) that copy the essential characteristics of diverse online presences and their connections into a unified graph format. This abstraction copying simplifies the detection and measurement of connections across different platforms by translating them into a common structural language.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11831417B2Threat mapping engine
Publication Date: 2023.11.28 FOCUS IP INC
  • US11831417B2 patent drawing
  • US11831417B2 patent drawing
  • US11831417B2 patent drawing

AI summary

Various embodiments provide novel tools and techniques for a threat mapping engine. A system includes a vertex discovery harvester subsystem, an edge extractor subsystem, a vertex correlator subsystem, and a recursive graph builder subsystem. The recursive graph builder subsystem includes a processor, and a computer readable medium in communication with the processor, the computer readable medium having encoded thereon a set of instructions executable by the processor to generate a map of one or more connections from the first known vertex to at least one related vertex of the one or more vertices via at least one edge, based on the one or more vertex correlations, determine a threat score indicative of a threat posed by at least one related vertex of the map, and generate a threat graph based on the map and the threat score of the at least one related vertex layered over the map.