Threat Vector Catalog for Security Risk Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in assimilating and prioritizing vast amounts of unordered threat intelligence, leading to potential overlooking of critical security information, as existing systems lack efficient methods to correlate relevant threat data with specific vulnerabilities, thereby delaying timely responses to security threats.

Innovation Solution

A security system and method that utilizes threat vectors with predefined descriptor values to articulate and correlate threat intelligence, allowing for automated notification of relevant security risks to stakeholders, integrating threat intelligence from various sources into a coherent format for efficient risk management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If threat intelligence is collected from multiple sources, then the quantity of security information increases, but the difficulty of assimilating and prioritizing the information increases

Engineering Contradiction:
Improvequantity of threat intelligenceVSAvoidcomplexity of assimilating threat intelligence
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The threat intelligence is segmented into structured threat vectors with standardized fields and enumerated values. Each threat vector represents a discrete unit of threat information with consistent formatting, enabling systematic processing and correlation across multiple sources without overwhelming complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transforms unstructured or semi-structured threat intelligence into standardized parameters through enumerated value constraints. By defining specific parameter types (e.g., threat type, severity level, affected system) with predefined options, the system enables automated processing while maintaining information richness

Inventive Principle:
Principle #35Parameter changes

2Reliability

If threat intelligence is not correlated with specific vulnerabilities, then the system remains simple, but critical security information may be overlooked

Engineering Contradiction:
Improvereliability of security informationVSAvoidcomplexity of correlating threat data
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces threat vectors as intermediary structures that bridge threat intelligence and vulnerability data. These vectors contain standardized fields that can be correlated with vulnerability databases, enabling systematic matching without requiring direct complex relationships between all threat sources and vulnerabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary correlation by pre-defining threat vectors with standardized fields that map to vulnerability characteristics. This preliminary structuring enables efficient matching when threats are received, reducing the complexity of real-time correlation while maintaining reliability

Inventive Principle:
Principle #10Preliminary action

3Productivity

If manual analysis of threat intelligence is performed, then the system remains simple, but timely response to security threats is delayed

Engineering Contradiction:
Improvespeed of threat responseVSAvoidcomplexity of automated threat processing
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

By converting threat intelligence into standardized parameters with enumerated values, the system enables automated processing and comparison. This parameterization allows computational analysis instead of manual review, dramatically improving response speed while the standardization keeps the processing logic manageable

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system creates standardized copies of threat information in the form of threat vectors with consistent field structures. These standardized representations can be efficiently processed, stored, and correlated by automated systems, replacing manual analysis while maintaining information fidelity

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9015846B2Information system security based on threat vectors
Publication Date: 2015.04.21 GOOGLE LLC
  • US9015846B2 patent drawing
  • US9015846B2 patent drawing
  • US9015846B2 patent drawing

AI summary

A security system is provided. The system comprises a computer system, a memory accessible to the computer system, a data store, and an application. The data store comprises a threat catalog, wherein the threat catalog comprises a plurality of threat vectors, each threat vector comprising a plurality of fields, wherein each field is constrained to carry a value selected from a predefined list of enumerated values. The application is stored in the memory and, when executed by the computer system receives a threat report, wherein the threat report comprises an identification of at least one threat vector, determines a correlation between the at least one threat vector received in the threat report with the threat vectors comprising the threat catalog, and, based on the correlation, sends a notification to a stakeholder in an organization under the protection of the security system.