Network Threat Risk Scoring via Metadata Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems fail to provide a comprehensive and real-time threat risk scoring system that can quantify the severity of modern security threats within a specific network environment, leading to ineffective resource allocation and response to potential vulnerabilities and attacks.

Innovation Solution

A system and method that detect threat activities on a network by extracting and correlating threat events using metadata, generating risk scores based on asset value, threat severity, and threat relevance, and providing real-time risk quantification to prioritize responses effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional antivirus threat detection methods are used, then threat detection capability is provided, but comprehensive real-time risk scoring and quantification of threat severity within specific network environment is not achieved

Engineering Contradiction:
Improvethreat risk scoring precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the threat assessment process into distinct components: threat event extraction from metadata, correlation of multiple threat events to identify incidents, and generation of risk scores based on asset value, threat severity, and threat relevance. This segmentation allows each component to be optimized independently while achieving comprehensive real-time risk scoring without overwhelming system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a multi-dimensional risk scoring framework that evaluates threats across multiple dimensions simultaneously: asset value (what is being targeted), threat severity (how dangerous the threat is), and threat relevance (how applicable the threat is to the specific environment). This dimensional approach transforms traditional single-metric threat detection into comprehensive real-time risk quantification.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If comprehensive threat analysis considering multiple factors is performed, then accurate risk assessment is achieved, but real-time processing capability is compromised

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidreal-time processing speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system performs preliminary actions by continuously monitoring and extracting threat events from metadata in real-time, maintaining a ready pool of identified threats and their characteristics. When new information arrives, the system can immediately correlate it with pre-identified threats and generate risk scores without delay, achieving both comprehensive analysis and real-time responsiveness.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where risk scores are continuously updated and refined based on new threat events, correlation results, and changing asset values. This feedback loop allows the system to maintain accurate real-time risk assessment by constantly adjusting to new information while leveraging previously gathered intelligence.

Inventive Principle:
Principle #23Feedback

3Productivity

If threat risk scoring system is implemented, then resource allocation optimization is achieved, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improveresource allocation efficiencyVSAvoidsystem implementation complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system manages complexity by standardizing the assessment around three key parameters: asset value, threat severity, and threat relevance. By focusing on these specific parameters with defined calculation methods, the system achieves comprehensive risk scoring without requiring complex proprietary algorithms for every aspect of threat analysis, facilitating easier implementation while maintaining resource allocation optimization.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10095866B2System and method for threat risk scoring of security threats
Publication Date: 2018.10.09 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10095866B2 patent drawing
  • US10095866B2 patent drawing
  • US10095866B2 patent drawing

AI summary

A system configured to generate a risk score for a threat activity including a digital device. The digital device configured to extract one or more threat events on a network based on metadata for one or more targeted digital devices on the network. Further, the digital device is configured to detect one or more incidents based on a correlation between at least a first threat event of the one or more threat events and a second threat event of the one or more threat events. And, the digital device is configured to generate a risk score for each of said one or more incidents.