Threat Rating System for Informed Security Decisions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer users face challenges in making informed decisions about potential security threats from sources like malicious websites and executable files due to inadequate reporting from local security tools, which fail to properly inform users about unknown threats.

Innovation Solution

A computer-implemented methodology and system that assesses potential threat sources by determining security threats, providing threat ratings, and recommending security tools to mitigate these threats, using a client-server architecture with modules for threat characterization, rating, and tool matching.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If local security tools are used to detect threats, then security detection capability is improved, but user awareness of actual threats deteriorates due to inadequate reporting

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoiduser awareness of threats
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements a feedback mechanism where the security system continuously monitors threats, assesses user's security tool coverage, and provides actionable recommendations. The system feeds back information about detected threats that are not covered by local tools, enabling users to make informed decisions about additional security investments while maintaining continuous improvement of their security posture.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary assessment system that acts as a mediator between local security tools and the user. This intermediary analyzes the output of local security tools, identifies gaps in coverage, and translates technical detection data into user-friendly threat assessments and recommendations, thereby bridging the information gap without requiring changes to the underlying detection mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive threat detection is implemented, then security coverage is improved, but system complexity increases due to multiple security tools required

Engineering Contradiction:
Improvesecurity coverageVSAvoidnumber of security tools
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal security assessment system that can evaluate multiple types of threats and multiple security tool configurations through a single interface. The system performs multi-functional analysis including detecting various threat types, assessing coverage across different security tool categories, and providing consolidated recommendations, thereby achieving comprehensive security coverage without requiring users to manage multiple separate tools.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent utilizes parameter changes by dynamically adjusting the assessment based on the user's existing security tool configuration. The system modifies its detection and recommendation parameters according to what security tools are already present, avoiding redundant recommendations and optimizing the path to comprehensive coverage with minimal additional tools.

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If threat information is provided to users, then user decision-making capability is improved, but information overload occurs without prioritization

Engineering Contradiction:
Improvethreat information completenessVSAvoiduser decision-making
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent applies local quality by providing differentiated information presentation based on user needs and context. Rather than uniformly presenting all possible threat information, the system tailors the depth and type of information provided to each specific threat scenario and user profile, delivering detailed technical information when needed while providing simplified summaries for routine situations.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments threat information into hierarchical levels of detail and priority. The system divides comprehensive threat data into structured components, presenting high-priority actionable recommendations first, followed by supporting details and contextual information. This segmentation allows users to quickly grasp critical decisions while having access to complete information if needed.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8332947B1Security threat reporting in light of local security tools
Publication Date: 2012.12.11 GEN DIGITAL INC
  • US8332947B1 patent drawing
  • US8332947B1 patent drawing
  • US8332947B1 patent drawing

AI summary

When a client receives a potential threat source (PTS), a user of the client may desire to make an informed decision regarding the PTS. The PTS can be, for example, an email or instant message with an embedded executable, a link to a network destination (e.g., included in search engine results or an email, or webpage), or an executable file (e.g., downloaded from a website). The PTS is identified and characterized to establish a threat rating. The threat rating can then be presented to the user, so as to inform the user as to the PTS riskiness. The threat rating is determined in light of the local security tools available. If there are no local security tools that mitigate the threat of the PTS, then a security tool that is known to mitigate the threat can be identified and recommended to the user.