Threat Score Determination via Linked Resource Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing threat intelligence systems face challenges in accurately assigning threat scores due to the dynamic nature of cyber threats, where a server's malicious status can change rapidly, making it difficult to determine precise and timely threat scores.

Innovation Solution

The system determines threat scores by analyzing known properties and scores of linked objects in a database, detecting changes in malicious activity, and adjusting scores based on relationships, historical data, and external sources, using a combination of hardware and software components to provide real-time threat assessments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If threat scores are determined based on static historical data, then computational complexity is reduced, but the accuracy and timeliness of threat scores deteriorate due to the dynamic nature of cyber threats

Engineering Contradiction:
Improvecomputational complexityVSAvoidthreat score accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The system implements dynamic threat score determination by continuously monitoring changes in malicious activity for security objects and their linked resources. When changes are detected, the system automatically recalculates threat scores to reflect current threat levels, transforming a static scoring system into a dynamic one that adapts to changing threat conditions in real-time

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary actions by pre-establishing relationships between security objects and their linked resources in a database before threats materialize. This pre-configuration of object relationships enables rapid threat score recalculation when changes occur, as the structural framework is already in place and only needs to be updated with current activity data

Inventive Principle:
Principle #10Preliminary action

2Loss of time

If threat scores are updated in real-time to reflect rapid changes in malicious activity, then timeliness is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvethreat score timelinessVSAvoidsystem complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system implements self-service by automatically detecting changes in malicious activity and triggering threat score recalculations without human intervention. The system monitors its own data sources, identifies when security objects or linked resources exhibit changed behavior, and autonomously updates threat scores, eliminating the need for manual reassessment while maintaining current threat level accuracy

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system employs feedback mechanisms by continuously monitoring malicious activity changes and using this information to adjust threat scores. When new information about security objects or their relationships is detected, the system feeds this back into the scoring model, creating a closed-loop system that automatically adapts to new threat intelligence

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10896259B2Threat score determination
Publication Date: 2021.01.19 MICRO FOCUS LLC
  • US10896259B2 patent drawing
  • US10896259B2 patent drawing
  • US10896259B2 patent drawing

AI summary

In one example in accordance with the present disclosure, a method for threat score determination includes detecting a change in malicious activity for a security object. The method also includes identifying an indicator that provides contextual information for the security object and determining a linked resource that is associated with a database record of the security object. The method also includes determining a first threat score associated with the security object and determining a relationship between the linked resource and the security object. The method also includes determining a second threat score associated with the linked resource based on the indicator, the threat score of the linked object and the relationship between the linked resource and the security object.