Threat Score Determination via Linked Resource Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing threat intelligence systems face challenges in accurately assigning threat scores due to the dynamic nature of cyber threats, where a server's malicious status can change rapidly, making it difficult to determine precise and timely threat scores.
Innovation Solution
The system determines threat scores by analyzing known properties and scores of linked objects in a database, detecting changes in malicious activity, and adjusting scores based on relationships, historical data, and external sources, using a combination of hardware and software components to provide real-time threat assessments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If threat scores are determined based on static historical data, then computational complexity is reduced, but the accuracy and timeliness of threat scores deteriorate due to the dynamic nature of cyber threats
Solution Approach 1:
The system implements dynamic threat score determination by continuously monitoring changes in malicious activity for security objects and their linked resources. When changes are detected, the system automatically recalculates threat scores to reflect current threat levels, transforming a static scoring system into a dynamic one that adapts to changing threat conditions in real-time
Solution Approach 2:
The system performs preliminary actions by pre-establishing relationships between security objects and their linked resources in a database before threats materialize. This pre-configuration of object relationships enables rapid threat score recalculation when changes occur, as the structural framework is already in place and only needs to be updated with current activity data
2Loss of time
If threat scores are updated in real-time to reflect rapid changes in malicious activity, then timeliness is improved, but system complexity and resource consumption increase
Solution Approach 1:
The system implements self-service by automatically detecting changes in malicious activity and triggering threat score recalculations without human intervention. The system monitors its own data sources, identifies when security objects or linked resources exhibit changed behavior, and autonomously updates threat scores, eliminating the need for manual reassessment while maintaining current threat level accuracy
Solution Approach 2:
The system employs feedback mechanisms by continuously monitoring malicious activity changes and using this information to adjust threat scores. When new information about security objects or their relationships is detected, the system feeds this back into the scoring model, creating a closed-loop system that automatically adapts to new threat intelligence
Data Source
AI summary
In one example in accordance with the present disclosure, a method for threat score determination includes detecting a change in malicious activity for a security object. The method also includes identifying an indicator that provides contextual information for the security object and determining a linked resource that is associated with a database record of the security object. The method also includes determining a first threat score associated with the security object and determining a relationship between the linked resource and the security object. The method also includes determining a second threat score associated with the linked resource based on the indicator, the threat score of the linked object and the relationship between the linked resource and the security object.


