Multidimensional Data Normalization for Threat Pattern Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information security technologies fail to effectively identify and analyze common threat vectors targeting groups of individuals, making it difficult to understand past attacks, assess vulnerabilities, predict future threats, and prevent cyber and fraudulent activities due to the limitations of manual data reconstruction and disparate datasets from big data.

Innovation Solution

A scalable information security computing platform that performs connectivity analysis by data mining, normalizing data into multidimensional storage structures, and analyzing it in real-time to identify connections between individuals targeted by common threat vectors, using both internal and external data sources, including social media and the Dark Web.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual data reconstruction is performed using generic commercial software, then some limited information can be assembled, but the process takes months or years and fails to locate all applicable data

Engineering Contradiction:
Improvecompleteness of attack pattern identificationVSAvoidtime required for data analysis
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical data reconstruction processes with automated computer-based systems. The system automatically collects, normalizes, and analyzes data from multiple sources using software agents and databases, eliminating the need for manual data assembly while achieving complete attack pattern identification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates a universal data collection and analysis system that handles multiple data types from diverse sources (internal logs, external threat intelligence, social media, dark web) through a single integrated platform. This multi-functional system simultaneously performs data collection, normalization, storage, and analysis across different attack scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Loss of information

If disparate datasets from big data sources are analyzed, then more comprehensive threat information can be obtained, but the data cannot be effectively connected or normalized

Engineering Contradiction:
Improveconnectivity information between attacked individualsVSAvoidcomplexity of data normalization and storage
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent applies data normalization techniques that transform disparate data from multiple sources into a standardized format. The system changes the parameters and structure of raw data from various sources (different schemas, formats, and sources) into a unified normalized format that enables effective connection and analysis of connectivity information.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces intermediate normalization layers and standardized data structures that mediate between disparate data sources and the analysis engine. These intermediaries translate and harmonize data from different sources into a common format, enabling effective connectivity analysis without direct complex interactions between all data sources.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If comprehensive data collection from multiple sources is performed, then better vulnerability assessment and prediction can be achieved, but the system complexity and resource requirements increase

Engineering Contradiction:
Improveaccuracy of threat prediction and vulnerability assessmentVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex data collection and analysis system into distinct functional modules: data collection agents for different sources, normalization layers, storage databases, and analysis engines. This segmentation allows comprehensive data collection from multiple sources while managing system complexity through modular, independently manageable components.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11381591B2Information security system based on multidimensional disparate user data
Publication Date: 2022.07.05 BANK OF AMERICA CORP
  • US11381591B2 patent drawing
  • US11381591B2 patent drawing
  • US11381591B2 patent drawing

AI summary

Aspects of the disclosure relate to information security by identifying unique or related factors in common between individuals subject to a common threat vector. Data mining and data acquisition of public and non-public user information is performed to prevent, disrupt, and/or address criminal, cyber, and fraudulent threats. The information can be normalized into template(s) to align information across disparate datasets and enable efficient storage of the big data into appropriate fields to be tracked. The information can be stored in data warehouse(s) or in multidimensional data structure(s) for investigation if a threat vector against a group of individuals is detected. The multidimensional data can be analyzed to identify direct connections, common connecting entities, and/or connectivity clusters between individuals who were attacked or who may be attacked in the future. Remediation, machine learning, enhanced security, and/or vulnerability assessments may be implemented based on the results of the analysis.