Threat Submitter Rating Engine for Security Intelligence
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Entities face challenges in quickly and accurately detecting and addressing sophisticated security threats within their IT infrastructures due to the overwhelming volume of security threat alerts from various intelligence sources, often resulting in false positives that require significant human resources to analyze.
Innovation Solution
A threat exchange community system that rates threat submitters based on the utilization and relevance of their submitted data through automated and manual processes, utilizing a threat management platform to correlate security indicators and provide customized threat scores to community members, thereby enhancing the detection and mitigation of security threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If entities monitor multiple threat intelligence sources to detect security threats, then detection capability is improved, but the volume of false positive alerts increases
Solution Approach 1:
The system implements feedback loops where threat alerts are correlated across multiple intelligence sources, and the results feed back into the correlation engine to refine future alert generation. This reduces false positives by validating threats through multiple independent sources before generating alerts.
Solution Approach 2:
The correlation engine acts as an intermediary between multiple threat intelligence sources and the final alerting system. It processes, correlates, and validates threat data from various sources, filtering out false positives before presenting consolidated threat information to users.
2Measurement precision
If entities analyze all security threat alerts manually, then detection accuracy is improved, but resource consumption and time requirements increase
Solution Approach 1:
The correlation engine performs automated self-service by independently correlating threat data from multiple sources, validating alerts, and generating consolidated threat assessments without requiring manual analysis of every individual alert. This maintains high detection accuracy while reducing resource consumption.
Solution Approach 2:
The system replaces manual mechanical analysis processes with automated computational correlation engines that use algorithms to correlate threat data, validate alerts, and generate intelligence. This substitution maintains or improves detection accuracy while dramatically reducing time and resource requirements.
3Measurement precision
If entities correlate security indicators across multiple sources, then threat detection accuracy is improved, but system complexity increases
Solution Approach 1:
The correlation engine is designed as a universal multi-functional system that can correlate various types of security indicators from diverse threat intelligence sources using standardized processes. This multi-functionality achieves high detection accuracy while managing complexity through a unified correlation framework.
Data Source
AI summary
Example embodiments disclosed herein relate to update a rating of threat submitters. Information is received of threat observables from threat submitters. Information about the threat observables is provided to one or more entities. Feedback about a threat observable is received from one of the entities. A rating of the threat submitter associated with the feedback is updated.


