Trusted Intermediary Platform for Secure Security Data Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current managed network security systems face challenges in detecting and responding to malicious threats efficiently, as attackers can use rudimentary technology to penetrate defenses, and often only become recognizable after security has been compromised, making it difficult to quickly identify and stop malicious actors.

Innovation Solution

A security platform that enables the rapid development and sharing of new or updated security analytic applications using AI, neural networks, and machine learning, allowing for the aggregation and analysis of security data from various sources, and enabling data controllers to select and control access to their proprietary data based on set policies, facilitating enhanced detection and prevention of malicious activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security data is shared across multiple data controllers, then detection and prevention capabilities improve through network effect, but data control and compliance requirements worsen

Engineering Contradiction:
Improvedetection and prevention capabilitiesVSAvoiddata control and compliance management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trusted intermediary platform that mediates between data controllers and security analysts. This platform enables secure data sharing and collaborative threat analysis while maintaining data controller ownership and compliance with regulations. The intermediary manages access controls, data anonymization, and policy enforcement, resolving the contradiction between sharing benefits and control requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments security data into different levels of sensitivity and sharing permissions. Data controllers can selectively share specific datasets or anonymized portions while retaining control over proprietary information. This segmentation allows participation in the network effect without exposing sensitive data, balancing detection capabilities with data control.

Inventive Principle:
Principle #1Segmentation

2Productivity

If security data is centralized for analysis, then threat detection efficiency improves, but data security risks and compliance complexity worsen

Engineering Contradiction:
Improvethreat detection efficiencyVSAvoiddata security risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The trusted intermediary platform acts as a secure centralized analysis environment where data can be aggregated for threat detection without being stored or accessed by individual participants. The platform implements security controls, access management, and compliance monitoring, enabling efficient centralized analysis while mitigating security risks through professional stewardship.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses data anonymization and aggregation techniques that create copies or derived representations of security data for analysis purposes. Original sensitive data remains with data controllers, while anonymized copies are shared for collective threat analysis. This approach enables efficient analysis without centralizing sensitive information, reducing security risks.

Inventive Principle:
Principle #26Copying

3Productivity

If proprietary data is shared openly, then security model development accelerates, but data controller control and privacy protection worsen

Engineering Contradiction:
Improvesecurity model development speedVSAvoiddata controller control
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent implements differential access rights where different data controllers can share different levels of data based on their specific needs and risk tolerances. The trusted intermediary manages granular permission sets, allowing each data controller to maintain local control over their proprietary information while contributing to collective security model development. This resolves the contradiction by enabling accelerated development without uniform loss of control.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11632398B2Systems and methods for sharing, distributing, or accessing security data and/or security applications, models, or analytics
Publication Date: 2023.04.18 SOPHOS INC
  • US11632398B2 patent drawing
  • US11632398B2 patent drawing
  • US11632398B2 patent drawing

AI summary

Methods and systems for building security applications can be provided. Data policies for accessing security data can be set, and a module pipeline including one or more modules selected from a plurality of modules can be generated. The modules can include at least one module operable to apply a predictive security application or model for detection or identification of security threats. Module execution policies governing execution of the one or more modules in the module pipeline also can be set. Upon receipt of a request to initiate execution of the module pipeline, it can be determined if the execution thereof would violate the data policies or the module execution policies. If so, execution of the module pipeline can be blocked, otherwise the module pipeline can be executed to process the portion of the security data.