Threat Submitter Rating Engine for Security Intelligence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Entities face challenges in quickly and accurately detecting and addressing sophisticated security threats within their IT infrastructures due to the overwhelming volume of security threat alerts from various intelligence sources, often resulting in false positives that require significant human resources to analyze.

Innovation Solution

A threat exchange community system that rates threat submitters based on the utilization and relevance of their submitted data through automated and manual processes, utilizing a threat management platform to correlate security indicators and provide customized threat scores to community members, thereby enhancing the detection and mitigation of security threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If entities monitor multiple threat intelligence sources to detect security threats, then detection capability is improved, but the volume of false positive alerts increases

Engineering Contradiction:
Improvesecurity threat detection capabilityVSAvoidfalse positive alerts
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The system implements feedback loops where threat alerts are correlated across multiple intelligence sources, and the results feed back into the correlation engine to refine future alert generation. This reduces false positives by validating threats through multiple independent sources before generating alerts.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The correlation engine acts as an intermediary between multiple threat intelligence sources and the final alerting system. It processes, correlates, and validates threat data from various sources, filtering out false positives before presenting consolidated threat information to users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If entities analyze all security threat alerts manually, then detection accuracy is improved, but resource consumption and time requirements increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidresource efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The correlation engine performs automated self-service by independently correlating threat data from multiple sources, validating alerts, and generating consolidated threat assessments without requiring manual analysis of every individual alert. This maintains high detection accuracy while reducing resource consumption.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces manual mechanical analysis processes with automated computational correlation engines that use algorithms to correlate threat data, validate alerts, and generate intelligence. This substitution maintains or improves detection accuracy while dramatically reducing time and resource requirements.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If entities correlate security indicators across multiple sources, then threat detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidcorrelation system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The correlation engine is designed as a universal multi-functional system that can correlate various types of security indicators from diverse threat intelligence sources using standardized processes. This multi-functionality achieves high detection accuracy while managing complexity through a unified correlation framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10104112B2Rating threat submitter
Publication Date: 2018.10.16 MICRO FOCUS LLC
  • US10104112B2 patent drawing
  • US10104112B2 patent drawing
  • US10104112B2 patent drawing

AI summary

Example embodiments disclosed herein relate to update a rating of threat submitters. Information is received of threat observables from threat submitters. Information about the threat observables is provided to one or more entities. Feedback about a threat observable is received from one of the entities. A rating of the threat submitter associated with the feedback is updated.