Threat Mapping Engine for Bad Actor Network Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for addressing online threats are inadequate as they focus on known threats and fail to capture the entire scope of a bad actor's operations, allowing unknown threats to remain operational and new threats to emerge quickly, especially in complex networks with multiple online presences.
Innovation Solution
A threat mapping engine system that includes a vertex discovery harvester, edge extractor, vertex correlator, and recursive graph builder to identify and map connections between vertices, determining threat scores and generating a threat graph to visualize and quantify the threat landscape.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional takedown methods are used to remove known threats, then individual known threats are eliminated, but unknown threats remain operational and new threats emerge quickly
Solution Approach 1:
The system segments the threat landscape into discrete vertices (online presences) and edges (connections), allowing individual threats to be identified and eliminated while preserving information about the overall network structure. This enables continuous threat removal without losing sight of the broader operational scope of bad actors.
Solution Approach 2:
The patent transitions from a one-dimensional list of known threats to a multi-dimensional threat graph that maps relationships across multiple platforms and vectors. This dimensional expansion allows simultaneous visualization of both individual threats and the comprehensive scope of bad actor operations, resolving the contradiction between eliminating specific threats and understanding overall threat landscapes.
2Loss of information
If a comprehensive threat graph is generated to capture all bad actor operations, then the entire scope of operations is revealed, but the complexity of data processing and graph generation increases
Solution Approach 1:
The system divides the complex task of threat analysis into modular subsystems: vertex discovery harvesters that collect individual online presences, edge extractors that identify connections, and graph generation components that assemble the threat landscape. This segmentation reduces processing complexity while maintaining comprehensive threat coverage.
Solution Approach 2:
The system implements iterative graph generation that can operate at varying levels of completeness. Users can generate partial threat graphs focusing on specific platforms or time periods, or execute comprehensive analyses when resources permit. This flexible approach manages processing complexity while preserving the option for complete threat scope analysis.
3Loss of information
If multiple online presences are monitored to capture all threat vectors, then comprehensive threat coverage is achieved, but the difficulty of detecting and measuring connections between presences increases
Solution Approach 1:
The system introduces automated edge extractors as intermediary components that mediate between vertex discovery (collecting online presences) and graph generation (visualizing connections). These extractors apply standardized algorithms to identify relationships across diverse platforms, reducing the complexity of detecting and measuring connections while maintaining comprehensive threat coverage.
Solution Approach 2:
The system creates standardized data representations (vertices and edges) that copy the essential characteristics of diverse online presences and their connections into a unified graph format. This abstraction copying simplifies the detection and measurement of connections across different platforms by translating them into a common structural language.
Data Source
AI summary
Various embodiments provide novel tools and techniques for a threat mapping engine. A system includes a vertex discovery harvester subsystem, an edge extractor subsystem, a vertex correlator subsystem, and a recursive graph builder subsystem. The recursive graph builder subsystem includes a processor, and a computer readable medium in communication with the processor, the computer readable medium having encoded thereon a set of instructions executable by the processor to generate a map of one or more connections from the first known vertex to at least one related vertex of the one or more vertices via at least one edge, based on the one or more vertex correlations, determine a threat score indicative of a threat posed by at least one related vertex of the map, and generate a threat graph based on the map and the threat score of the at least one related vertex layered over the map.


