Trusted Intermediary Platform for Secure Security Data Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current managed network security systems face challenges in detecting and responding to malicious threats efficiently, as attackers can use rudimentary technology to penetrate defenses, and often only become recognizable after security has been compromised, making it difficult to quickly identify and stop malicious actors.
Innovation Solution
A security platform that enables the rapid development and sharing of new or updated security analytic applications using AI, neural networks, and machine learning, allowing for the aggregation and analysis of security data from various sources, and enabling data controllers to select and control access to their proprietary data based on set policies, facilitating enhanced detection and prevention of malicious activities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security data is shared across multiple data controllers, then detection and prevention capabilities improve through network effect, but data control and compliance requirements worsen
Solution Approach 1:
The patent introduces a trusted intermediary platform that mediates between data controllers and security analysts. This platform enables secure data sharing and collaborative threat analysis while maintaining data controller ownership and compliance with regulations. The intermediary manages access controls, data anonymization, and policy enforcement, resolving the contradiction between sharing benefits and control requirements.
Solution Approach 2:
The patent segments security data into different levels of sensitivity and sharing permissions. Data controllers can selectively share specific datasets or anonymized portions while retaining control over proprietary information. This segmentation allows participation in the network effect without exposing sensitive data, balancing detection capabilities with data control.
2Productivity
If security data is centralized for analysis, then threat detection efficiency improves, but data security risks and compliance complexity worsen
Solution Approach 1:
The trusted intermediary platform acts as a secure centralized analysis environment where data can be aggregated for threat detection without being stored or accessed by individual participants. The platform implements security controls, access management, and compliance monitoring, enabling efficient centralized analysis while mitigating security risks through professional stewardship.
Solution Approach 2:
The patent uses data anonymization and aggregation techniques that create copies or derived representations of security data for analysis purposes. Original sensitive data remains with data controllers, while anonymized copies are shared for collective threat analysis. This approach enables efficient analysis without centralizing sensitive information, reducing security risks.
3Productivity
If proprietary data is shared openly, then security model development accelerates, but data controller control and privacy protection worsen
Solution Approach 1:
The patent implements differential access rights where different data controllers can share different levels of data based on their specific needs and risk tolerances. The trusted intermediary manages granular permission sets, allowing each data controller to maintain local control over their proprietary information while contributing to collective security model development. This resolves the contradiction by enabling accelerated development without uniform loss of control.
Data Source
AI summary
Methods and systems for building security applications can be provided. Data policies for accessing security data can be set, and a module pipeline including one or more modules selected from a plurality of modules can be generated. The modules can include at least one module operable to apply a predictive security application or model for detection or identification of security threats. Module execution policies governing execution of the one or more modules in the module pipeline also can be set. Upon receipt of a request to initiate execution of the module pipeline, it can be determined if the execution thereof would violate the data policies or the module execution policies. If so, execution of the module pipeline can be blocked, otherwise the module pipeline can be executed to process the portion of the security data.


