Devices, systems, and methods for ingesting and enriching security information to autonomously secure multiple tenant networks

The SIEM provider server with a job manager and workflow engine addresses inefficiencies in conventional SIEM/SOAR platforms by autonomously managing security information across multiple tenant networks, enhancing security and reducing costs through adaptive and scalable management.

JP2025519081APending Publication Date: 2025-06-24BLUEVOYANT LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024568879
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-05-20
Filing Date
2023-05-19
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

Conventional SIEM and SOAR platforms are inefficient and costly due to the need for manual integration and management across multiple tenant networks, lacking scalability and the ability to leverage synergies among clients, leading to high operational costs and increased vulnerability.

Method used

A system and method utilizing a SIEM provider server with a job manager and workflow engine to autonomously ingest, enrich, and enhance security information across multiple tenant networks, incorporating a content library, variable store, and automation scheme to dynamically manage SOAR platforms, enabling scalable and adaptive security management.

Benefits of technology

Enables efficient, scalable, and adaptive security management across multiple tenant networks, reducing manual labor, lowering costs, and enhancing network security through automated monitoring and response, while leveraging synergies among clients.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025519081000001_ABST
    Figure 2025519081000001_ABST
Patent Text Reader

Abstract

Disclosed herein is a Security Information and Event Management (“SIEM”) provider server configured to enhance network security on behalf of a tenant network by autonomously ingesting and enriching security information associated with the tenant network. The SIEM provider server periodically monitors the tenant network for configuration changes, detects configuration changes within the tenant network, updates fetch job parameters stored in a job database based on the detected configuration changes within the tenant network, generates a fetch job for the tenant network based on the updated job parameters stored in the job database, stores the generated fetch job in a queue, and executes the generated fetch job such that a job manager obtains security information from a data source associated with the tenant network, enriches the obtained security information, and generates an output configured to enhance the security of the tenant network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Cross - Reference to Related Applications This application claims the benefit of U.S. Provisional Patent Application No. 63 / 344,305, filed May 20, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR INGESTING & ENRICHING SECURITY INFORMATION TO AUTONOMOUSLY SECURE A PLURALITY OF TENANT NETWORKS", which is incorporated herein by reference in its entirety.

[0002] This disclosure generally relates to network security, and more specifically, to improved devices, systems, and methods for issuing security information event management (SIEM) client updates.

Summary of the Invention

[0003] The following summary is provided to facilitate an understanding of some of the innovative features specific to the aspects disclosed herein and is not intended to be a complete description. A complete understanding of the various aspects can be obtained by taking the entire specification, claims, and abstract.

[0004] In various aspects, a Security Information and Event Management (SIEM) provider server is disclosed. The SIEM provider server can be configured to enhance network security on behalf of a tenant network by autonomously ingesting and enriching security information related to the tenant network. The SIEM provider server can include a processor and a memory configured to store a job manager and a workflow engine, which, when executed by the processor, cause the processor to periodically monitor the tenant network for configuration changes, detect configuration changes within the tenant network, update fetch job parameters stored in a job database based on the detected configuration changes within the tenant network, generate a fetch job for the tenant network based on the updated job parameters stored in the job database, store the generated fetch job in a queue, execute the generated fetch job such that the job manager obtains security information from a data source associated with the tenant network, and generate an output configured to enrich the obtained security information and enhance the security of the tenant network.

[0005] In various aspects, a method for enhancing network security instead of a tenant network is disclosed. The method can include autonomously ingesting and enriching security information associated with a tenant network via a security information and event management (SIEM) provider server, where the SIEM provider server includes a processor and a memory configured to store a job manager and a workflow engine. The method may further include periodically monitoring the tenant network for configuration changes, detecting a configuration change within the tenant network, updating fetch job parameters stored in a job database based on the detected configuration change within the tenant network, generating a fetch job for the tenant network based on the updated job parameters stored in the job database, storing the generated fetch job in a queue, executing the generated fetch job such that the job manager obtains security information from a data source associated with the tenant network, enriching the obtained security information, and generating an output configured to enhance the security of the tenant network.

[0006] In various aspects, a system is disclosed that includes a plurality of tenant networks and a security information and event management (SIEM) provider server communicatively coupled to the plurality of tenant networks. The SIEM provider server can include a processor and a memory configured to store a job manager and a workflow engine, which, when executed by the processor, cause the processor to periodically monitor the plurality of tenant networks for configuration changes, detect a configuration change in a first tenant network of the plurality of tenant networks, update fetch job parameters stored in a job database based on the detected configuration change within the first tenant network, generate a fetch job for the tenant network based on the updated fetch job parameters stored in the job database, store the generated fetch job in a queue, execute the generated fetch job such that the job manager obtains security information from a data source associated with the tenant network, and enrich the obtained security information to generate an output configured to enhance the security of the tenant network.

[0007] These and other objects, features, and characteristics of the present invention, as well as the methods of operation and functions of the related structural elements, combinations of parts, and economies of manufacture, will become more apparent upon consideration of the following description, appended claims, and accompanying drawings, all of which form a part of this specification, and like reference numerals designate corresponding parts in the various figures. It should be expressly understood, however, that the drawings are for the purpose of illustration and description only and are not intended as a definition of the limits of the present invention.

[0008] The various features of the aspects described herein are set forth in detail in the appended claims. However, various aspects regarding both the organization and method of operation, as well as advantages thereof, can be understood from the following description in conjunction with the accompanying drawings as follows.

Brief Description of the Drawings

[0009]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Modes for Carrying Out the Invention

[0010] Corresponding reference numerals indicate corresponding parts throughout the several views. The embodiments described herein illustrate various aspects of the present invention in one form, and such embodiments should not be construed as limiting the scope of the present invention in any way.

[0011] The applicant of the present application owns the following U.S. provisional patent applications, the disclosures of each of which are incorporated herein by reference in their entirety. - U.S. Provisional Patent Application No. 63 / 341,264, filed on May 12, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR SUMMARIZING ANALYTIC OBSERVATIONS", - U.S. Provisional Patent Application No. 63 / 344,305, filed on May 20, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR INGESTING & ENRICHING SECURITY INFORMATION TO AUTONOMOUSLY SECURE A PLURALITY OF TENANT NETWORKS", - U.S. Provisional Patent Application No. 63 / 345,679, filed on May 25, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTIONS BASED ON A DEMOCRATIC MATCHING ALGORITHM", - International Patent Application No. PCT / US2022 / 072739, filed on June 3, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS", - International Patent Application No. PCT / US2022 / 072743, filed on June 3, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR STANDARDIZING & STREAMLINING THE DEPLOYMENT OF SECURITY INFORMATION & EVENT MANAGEMENT ARTIFACTS FOR MULTIPLE TENANTS" - U.S. Provisional Patent Application No. 63 / 365,819, filed on June 3, 2022, entitled "DEVICES, METHODS, AND SYSTEMS FOR GENERATING A HIGHLY-SCALABLE, EFFICIENT COMPOSITE RECORD INDEX" - U.S. Provisional Patent Application No. 63 / 353,992, filed on June 21, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR CATEGORIZING, PRIORITIZING, AND MITIGATING CYBER SECURITY RISKS" - U.S. Provisional Patent Application No. 63 / 366,903, filed on June 23, 2022, entitled "DEVICES, SYSTEMS, AND METHOD FOR GENERATING AND USING A QUERYABLE INDEX IN A CYBER DATA MODEL TO ENHANCE NETWORK SECURITY" - U.S. Provisional Patent Application No. 63 / 368,567, filed on July 15, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR UTILIZING A NETWORKED, COMPUTER-ASSISTED, THREAT HUNTING PLATFORM TO ENHANCE NETWORK SECURITY" - U.S. Provisional Patent Application No. 63 / 369,582, filed on July 27, 2022, entitled "AUTONOMOUS THREAT SCORING AND SECURITY ENHANCEMENT" - U.S. Provisional Patent Application No. 63 / 377,304, filed on September 27, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR CONTINUOUSLY ENHANCING THE IMPLEMENTATION OF CODE CHANGES VIA ENRICHED PIPELINES" - International Patent Application No. PCT / US2022 / 082167, filed on December 21, 2022, entitled "DEVICES, SYSTEMS, and MethodS For PROVISIONING AND UPDATING SECURITY INFORMATION & EVENT MANAGEMENT ARTIFACTS FOR MULTIPLE TENANTS" - International Patent Application No. PCT / US2022 / 082173, filed on December 21, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR STREAMLINING AND STANDARDIZING THE INGEST OF SECURITY DATA ACROSS MULTIPLE TENANTS" - International Patent Application No. PCT / US2023 / 061069, filed on January 23, 2023, entitled "DEVICES, SYSTEMS, AND METHODS FOR REMOTELY MANAGING ANOTHER ORGANIZATION’S SECURITY ORCHESTRATION, AUTOMATION, AND RESPONSE" - International Patent Application No. PCT / US2023 / 062894, filed on February 20, 2023, entitled "DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTION BASED ON DOMAIN REDIRECTS"

[0012] Numerous specific details are described in this disclosure and are described to provide a complete understanding of the overall structure, function, manufacture, and use of the aspects illustrated in the accompanying drawings. Well-known operations, components, and elements are not described in detail so as not to obscure the aspects described herein. The reader will understand that the aspects described and illustrated herein are non-limiting aspects. Thus, it will be understood that the specific structural and functional details disclosed herein may be representative and exemplary.

[0013] Before detailing various aspects and methods of the systems disclosed herein, it should be noted that the exemplary aspects are not limited to the applications or uses disclosed in the accompanying drawings and description. Of course, the exemplary aspects may be implemented or incorporated in other aspects, variations, and modifications and may be practiced or carried out in various ways. Further, unless otherwise indicated, the terms and expressions used herein are selected for the purpose of describing the exemplary aspects for the convenience of the reader and are not intended for purposes of limitation. For example, any reference herein to a particular manufacturer, software suite, application, or development platform is merely intended to illustrate some of the many aspects of this disclosure. This includes any reference to trademarks. Thus, it should be understood that the devices, systems, and methods disclosed herein can be carried out to enhance any software updates according to any purpose of use and / or user preference.

[0014] As used herein, the term "server" refers to, or may include, one or more computing devices that are operated by, or facilitate, communication and processing for multiple parties in a network environment such as the Internet, or any public or private network. As used herein, a reference to a "server" or "processor" may refer to a previously recited server and / or processor that performs a previous step or function, a different server, and / or processor, and / or a combination of servers, and / or a combination of processors.

[0015] As used herein, the term "tenant" may refer to one or more client organizations managed by a managed security service provider ("MSSP"). A tenant can include one or more servers configured to manage a network such as an intranet, to which a number of client instances are connected. For example, as used herein, a "client" or "client instance" may include a computing device (e.g., a laptop, desktop computer, mobile phone, etc.) connected to the tenant's network. According to some non-limiting aspects, a "client" or "client instance" may be a software agent or a computing device external to the tenant's network connected via a virtual private network (VPN) connection.

[0016] As used herein, the term "constant" may refer to one or more SIEM functions that do not change during the issuance of an alert. For example, constants can include, in particular, Azure Sentinel Log Analytics functions. According to some non-limiting aspects, the constants can be specifically configured according to the preferences and / or requirements of individual clients. For example, as described herein, the alert rules may be the same for the introduction of all clients. However, the use of the devices, systems, and methods disclosed herein can "fine-tune" the method of managing alerts for each specific client using client-specific constants. In other words, each constant may include a whitelist of specific protocols, accounts, etc., which the alert rules manage separately (e.g., skip) those constants.

[0017] As used herein, the term "enrich" can include any process that enhances or adds to the initial input (e.g., data, files, portions of code, etc.) collected by ingestion. For example, the enrichment process can include using the initial input to detect additional relevant information from the same or alternative sources. According to other non-limiting aspects, enrichment can include correlation, where the relationship between the input and existing artifacts (e.g., data, files, portions of code, etc.) is detected.

[0018] The above examples are EDR alerts, and since the basic alerts have less information, the original source is requested for detailed information about the alert. If a specific IP or domain exists in that data, more information such as an evaluation score can be obtained by querying a third party or an internal source.

[0019] Security Information and Event Management (SIEM) includes software configured to aggregate and analyze activities from many different resources across an information technology (IT) infrastructure. For example, SIEM can be run to aggregate data from multiple systems and analyze that data to capture abnormal behavior or potential cyberattacks. For example, SIEM can collect security data from network devices, servers, domain controllers, etc. SIEM can be run to apply storage, normalization, aggregation, and analysis to that data to detect trends, detect threats, and enable an organization to investigate any alerts. Known SIEM tools provide excellent capabilities, including event monitoring, data collection, and issuance of security alerts across a network, but such tools are typically fine-tuned to the organization implementing them, i.e., more specifically, they can often be complex and customized to a particular organization.

[0020] An example of SIEM is Azure Sentinel, a widely used cloud-based tool. However, the introduction of Azure Sentinel requires advanced skills and is very time-consuming, making it prone to errors. Each organization that needs a security solution has special needs regarding monitoring, alert generation, data ingestion, detection / alert rules, automation of responses, and reporting. Microsoft is often used by Managed Security Service Providers ("MSSPs") to manage multiple clients, but the complexity of the initial configuration, introduction, and ongoing maintenance of artifacts (such as resource groups, log analytics workspaces, alert rules, workbooks, playbooks, etc.) has increased significantly. This can result in high costs for both MSSPs, who have to hire more expensive specialists, and clients, who often bear at least part of the increasing costs. However, in many cases, there is overlap among the introduction needs of various clients. For example, many organizations may need similar firewall monitoring solutions. In such cases, asset reuse and reintroduction (and updates) can lead to significant cost savings and operational simplification. Unfortunately, known SIEM tools are technically unable to take advantage of such synergies. Therefore, from the initial provisioning to the automation of incident response, MSSPs have limited opportunities for reuse among multiple clients and cannot capture efficiency.

[0021] The MSSP provides external monitoring and management of security devices and systems on behalf of organizational clients. For example, the MSSP may provide common services to clients, including managed firewalls, intrusion detection, virtual private networks, vulnerability scanning, and antivirus services. A new trend in the MSSP industry is to develop technologies that are 3-5 years more effective than what is available in the open market. For example, some proprietary SIEM technologies were developed when it became clear that the MSSP could not purchase off-the-shelf ones. Following the development of its own SIEM technology, the MSSP then developed a platform to automate the management of the SIEM platform for clients in a scalable manner when the technology became generally available. - U.S. Provisional Patent Application No. 63 / 196,458, filed on June 3, 2021, entitled "DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS", the disclosure of which is incorporated herein by reference in its entirety.

[0022] The SIEM platform can analyze multiple data sources, perform advanced correlations to detect threats, and intelligently rank the events detected in order of importance. However, it can execute a Security Orchestration, Automation, and Response (SOAR) platform to automate the investigation path workflow based on SIEM-generated alerts, significantly reducing the amount of time required to manage and mitigate security threats. The SOAR platform is a collection of security software solutions and tools for browsing and collecting diverse data from various sources to be analyzed, understanding and prioritizing security incident response actions, and improving the productivity of MSSPs. In essence, the SOAR platform is executed as an integrated development environment built on top of a collection of application programming interface (API) bridges that enable modules of code described herein as "playbooks", automatically collecting data, communicating commands, or returning an organized response to its system. In other words, the SOAR platform not only enables enterprises to collect threat-related data from a variety of sources but also, based on the analysis, can respond to the detected threats. When a threat is detected, a typical SOAR platform can secure the network by executing an incident response to mitigate the detected threat.

[0023] Conventionally, the SOAR platform has been designed to automate the incident response lifecycle by enhancing the capabilities of cyber defense teams to detect, investigate, and respond to security alerts in a given environment, either manually or through the use of automation. However, to fully realize its potential, the SOAR platform requires a high degree of integration with the environment, as well as customized playbooks and response activities, in order to fully realize its potential. Therefore, traditional SOAR platforms are generally directly managed by the implementing organization, as the organization is better positioned to integrate the platform into its network and can manage its own single network myopically. For the SOAR platform to be managed by a service provider, manual integration is required to achieve an appropriate level of integration to fully protect the client organization's network. In other words, a significant amount of manual labor is required to establish sufficient connections to the various SOAR platforms and APIs, which are, however, implemented by each client organization.

[0024] This can result in high costs for both MSSPs, which must hire more expensive specialists, and clients, who often bear at least a portion of the increasing costs. However, in many cases, there are overlaps among the onboarding needs of various clients. For example, many organizations may utilize similar SOAR platforms and require similar monitoring and management solutions. In such cases, asset reuse, reintroduction, and updates can lead to significant cost savings and operational simplification. Unfortunately, known SIEM tools are technically unable to leverage such synergies. As a result, MSSPs have limited opportunities for reuse to capture efficiency across multiple clients, from initial provisioning to incident response automation. The lack of reusable onboarding is not only extremely costly but can also be inherently unscalable due to differences in each client organization's network, detection capabilities, and risk tolerance levels. Many client organizations may be skeptical and hesitant about pursuing an automated SOAR platform that can reduce costs driven by manual execution, at least minimally, but automation alone does not enhance the scalability of traditional SOAR platforms.

[0025] Furthermore, the need for a scalable SIEM service comes with a new requirement to quickly provision or configure a SIEM / SOAR platform so that an MSSP can immediately start monitoring the security of new clients. Once configured, the SIEM must also be updated repeatedly (e.g., daily, weekly, monthly, etc.) and / or on an ad-hoc basis. These SIEM / SOAR updates are necessary to accommodate new client needs (e.g., new log sources) and include new security content (e.g., alerts, playbooks, etc.) as information technology requirements and security threats continue to evolve.

[0026] Furthermore, conventional SOAR technologies have significant drawbacks. Specifically, conventional SOAR platforms lack the robust data storage necessary to facilitate the amount of data required for scaling and enriching MSSP services for multiple tenants. Effectively scaling MSSP services involves engaging with a large number of data sources and potential destinations that conventional SOAR platforms are not technically configured to interface with and / or manage. In other words, the amount of data is too large, and conventional SOAR platforms are not configured to ingest, process, and respond by taking appropriate security actions on data volumes from a very large number of tenants. Thus, conventional SOAR platforms are not technically capable of simultaneously monitoring the networks of multiple tenants and only execute playbooks to protect these networks. Therefore, there is a need for improved devices, systems, and methods for ingesting, enriching, and transforming security information to autonomously protect multiple tenant networks.

[0027] The present disclosure contemplates such devices, systems, and methods, all of which provide many technical benefits over conventional MSSP and SIEM platforms. For example, conventional MSSP devices, systems, and methods lack the automation, artifacts, and interfaces necessary to seamlessly scale the MSSP platform so that SIEM services can be provided to hundreds (if not thousands) of tenant networks. Rather, conventional MSSP devices, systems, and methods require manual integration and management, i.e., they are inefficient and more expensive. Further, conventional MSSP devices, systems, and methods require that each tenant network share the manual resources employed by the MSSP, which reduces the security of each tenant network. In contrast, the devices, systems, and methods disclosed herein are highly automated and are thus configured so that an MSSP can continuously monitor tenant networks and clients in real time. Conventional MSSP devices, systems, and methods not only cannot technically perform such automation, but it is not very realistic, if not impossible, for an MSSP to continuously monitor hundreds, if not thousands, of tenant networks manually in real time. The devices, systems, and methods disclosed herein are also technically configured to be adaptable. Combined with being highly scalable, this adaptability, and the MSSP can track changes across a large number of tenant onboards, monitor responses to those changes, and autonomously execute on any suitable tenant onboarding for which they can similarly benefit. In other words, conventional MSSP apparatuses, systems, and methods are inherently more susceptible to the impact of security events and are thus not as technically secure as the apparatuses, systems, and methods disclosed herein.

[0028] For example, the devices, systems, and methods disclosed herein include: (1) means for dynamically plugging in JavaScript Object Notation (JSON)-based solution bundle descriptions of various Sentinel artifacts (e.g., resource groups, log analytics workspaces, data connectors, alert rules, playbooks, workbooks, etc.) referred to herein as "sentinel-in-a-Box"; (2) a visual interface for authorized users to select a desired sentinel-in-a-Box bundle; (3) an action button to "introduce" a selected bundle into a user's desired SIEM subscription by essentially creating all necessary artifacts (e.g., resource groups, log analytics workspaces, etc.), configuring appropriate data connectors (specific to the selected bundle), and creating analysis / alert rules, playbooks, workbooks, and queries required for the solution as needed based on the specific bundled configuration; (4) a backend service operating center (SOC) configuration to onboard new clients with clearly defined automation rules in response to events triggered by alerts / detections configured for a specific bundle; and (5) an MSSP / CSP model where a service provider with access to the client's Azure environment (e.g., via Azure Lighthouse, etc.) can introduce the bundle on behalf of the client into each of the client's workspaces. Thus, the bundle provider manages only the relationship with the MSSP / CSP with sufficient filtering by the client workspaces for specific alerts / incidents. This can be important for claim streamlining, support, and avoidance of unnecessary client interactions.

[0029] Referring now to FIG. 1, a block diagram of a system 1000 configured to remotely manage security orchestration, automation, and response (SOAR) of another organization is illustrated in accordance with at least one non-limiting aspect of the present disclosure. According to a non-limiting aspect of FIG. 1, the system 1000 may include an MSSP provider server 1002 comprising a memory 1006 configured to store a SOAR application (see FIG. 2) and a processor 1004 configured to execute the stored SOAR application (see FIG. 2), as further discussed with reference to FIG. 2. For example, the MSSP provider server 1002 may be computing resources owned or leased by a managed security service provider (the “MSSP”). The MSSP provider server 1002 can be communicatively coupled to a plurality of tenants 10101, 10102 ··· 1010 n via a network 1008. Each of the plurality of tenants 10101, 10102 ··· 1010 n can represent a customer (e.g., an organization) that has a contract with the MSSP. According to a non-limiting aspect of FIG. 1, the network 1008 can include any of a variety of wired, long-range wireless, and / or short-range wireless networks. For example, the network 1008 can include, among other things, an internal network, a local area network (LAN), WiFi (registered trademark), a cellular network, near field communication (hereinafter, NFC), etc. The MSSP provider server 1002 can be configured to perform a SOAR management service instead of a SIEM service, more specifically, for a plurality of tenants 10101, 10102 ··· 1010 n

[0030] Referring still to FIG. 1, each of the plurality of tenants 10101, 10102 ··· 1010 n can host one or more instances of one or more clients 1012, 1014, 1016. For example, the first tenant 10101 can host one or more client applications 10121, 10122 ··· 1012 n ​may include one or more machines that execute, and a second tenant 10102 may include one or more client applications 10141, 10142 ··· 1014 n may include one or more machines that execute, and / or a third tenant 1010 n may include one or more machines that execute client applications 10161, 10162 ··· 1016 n Each tenant 10101, 10102, and 1010 may include an intranet by each machine that executes a client application. For example, each tenant 10101, 1010 n and 1010 may each represent a customer, such as an organization that has contracted with an MSSP for security services. 2、 and 1010 n Accordingly, the MSSP provider server 1002 can be configured to have monitoring of multiple respective tenants 10101, 10102, and 1010, and thus is responsible for monitoring and managing each client application 1012, 1014, and 1016 against threats. As described above, the differences and complexities in the tenant 10101, 10102, and 1010 architectures can complicate this and make it inefficient for the MSSP. Thus, known SOAR tools can leave the tenants 10101, 10102, and 1010 technically exposed to attacks and thus vulnerable. According to non-limiting aspects of the present disclosure, the MSSP provider server 1002 can address these deficiencies technically and practically by enhancing the management capabilities, alert sending capabilities, and client application update capabilities of the MSSP provider server 1002 for multiple tenants based on correlated and synergistic development needs, and execute a SOAR management application (see FIG. 2). Further, the architecture 2000 of FIG. 2 further shows different means of communication between various modules.

[0031] Accordingly, the MSSP provider server 1002 can be configured to have monitoring of multiple respective tenants 10101, 10102, and 1010 n and thus is responsible for monitoring and managing each client application 1012, 1014, and 1016 against threats. As described above, the differences and complexities in the tenant 10101, 10102, and 1010 architectures can complicate this and make it inefficient for the MSSP. Thus, known SOAR tools can leave the tenants 10101, 10102, and 1010 technically exposed to attacks and thus vulnerable. According to non-limiting aspects of the present disclosure, the MSSP provider server 1002 can address these deficiencies technically and practically by enhancing the management capabilities, alert sending capabilities, and client application update capabilities of the MSSP provider server 1002 for multiple tenants based on correlated and synergistic development needs, and execute a SOAR management application (see FIG. 2). Further, the architecture 2000 of FIG. 2 further shows different means of communication between various modules. n Differences and complexities in the tenant 10101, 10102, and 1010 architectures can complicate this and make it inefficient for the MSSP. Thus, known SOAR tools can leave the tenants 10101, 10102, and 1010 technically exposed to attacks and thus vulnerable. According to non-limiting aspects of the present disclosure, the MSSP provider server 1002 can address these deficiencies technically and practically by enhancing the management capabilities, alert sending capabilities, and client application update capabilities of the MSSP provider server 1002 for multiple tenants based on correlated and synergistic development needs, and execute a SOAR management application (see FIG. 2). Further, the architecture 2000 of FIG. 2 further shows different means of communication between various modules. n According to non-limiting aspects of the present disclosure, the MSSP provider server 1002 can address these deficiencies technically and practically by enhancing the management capabilities, alert sending capabilities, and client application update capabilities of the MSSP provider server 1002 for multiple tenants based on correlated and synergistic development needs, and execute a SOAR management application (see FIG. 2). Further, the architecture 2000 of FIG. 2 further shows different means of communication between various modules.

[0032] Referring now to FIG. 2, a block diagram of the functional architecture 2000 of the system 1000 of FIG. 1 is shown in accordance with at least one non-limiting aspect of the present disclosure. According to a non-limiting aspect of FIG. 2, the architecture 2000 may include a content library 2002, a variable store 2004, an automation scheme 2008, and a service operation engine 2012, which are collectively provided via an application stored in the memory 1006 (FIG. 1) of the MSSP provider server 1002. According to some non-limiting aspects, the MSSP provider server 1002 may be remotely located with respect to the MSSP and / or tenant 1010 n . For example, the MSSP provider server 1002 may be cloud-based. When executed by the processor 1004 (FIG. 1), the application's content library 2002, variable store 2004, automation scheme 2008, and service operation engine 2012 may facilitate the simultaneous configuration, management, and / or control of multiple SOAR platforms 2018 for multiple tenants 1010 n , or client organizations, on a large scale and collectively. Further, when executed by the processor 1004 (FIG. 1), the application may support the SOAR platform 2018 of the client organization, either abstractly or dynamically, as described in more detail herein.

[0033] According to some non-limiting aspects, the application introduced by the MSSP provider server 1002 may be configured as an Azure Sentinel Automation Porta (ASAP), such as that disclosed in U.S. Provisional Patent Application No. 63 / 196,458, entitled "DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS", filed on June 3, 2021, the disclosure of which is hereby incorporated by reference in its entirety. For example, according to one non-limiting aspect, the ASAP portal runtime software code may include server middleware that is involved in processing content from the content library 2002, connections to the SOAR platform 2018, and / or other services, as well as service requests for the MSSP provider server 1002 to deploy, update, and / or read. In other words, the application introduced by the MSSP provider server 1002, including the content library 2002, the variable store 2004, and the automation scheme 2008, can provide a unified, simplified view of the introduction for all tenants 1010 1-n along with the ability to work with one or more tenants 1010 1-n (FIG. 1).

[0034] The content library 2002 is where the MSSP provider server 1002 can obtain content for one or more tenants 1010 nconfigured to store various artifacts (e.g., detections, automations, workbooks, alert rules, playbooks, etc.) that can configure and manage the SOAR platform. According to some non-limiting aspects, the content library 2002 of FIG. 2 can be stored locally for an application, which means it is provided via the memory 1006 (FIG. 1) of the MSSP provider server 1002. However, according to other non-limiting aspects, the content library 2002 can be stored on a remote server communicatively coupled to the MSSP provider server 1002. In still other non-limiting aspects, the content library 2002 can be provided by a third-party provider (e.g., GitHub, GitLab, etc.). In summary, the content library 2002, and more specifically, the artifacts stored within the content library 2002, control the rules by which the MSSP provider server 1002 can remotely interface and / or manage the SOAR platform 2018 for the tenant 1010n or client organization. For example, the content library 2002 enables the MSSP provider server 1002 and / or the SOAR platform 2018 to manage the tenant architecture 1010 n store one or more rules and / or templates configured to automate the deactivation of a user account if it is determined that a risk score determined based on all detected variables exceeds a predetermined threshold.

[0035] According to the non-limiting aspects of FIG. 2, for a particular client organization and / or tenant 1010 n tenant 1010, such as variable points specific to the architecture nThe requirements can be provided to the artifacts stored in the content library 2002. The content library 2002 can achieve this according to an introducible artifact template, such as that disclosed in U.S. Provisional Patent Application No. 63 / 196,458, titled "DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS", filed on June 3, 2021, the disclosure of which is hereby incorporated by reference in its entirety. For example, the content library 2002 can include "json" files for defining alert rules, workbooks, playbooks, etc. When new content is added to the content library 2002 or existing content is updated, the changes can be automatically pushed to the SOAR platform 2018 of the tenant 1010 n via the MSSP provider server 1002. In other words, the MSSP provider server 1002 can be configured based on the architecture of each tenant, which changes when introduced, for the 1010 1-n (FIG. 1) specific SOAR needs of each tenant.

[0036] The variable store 2004 can be further configured to customize the interface between the MSSP provider server 1002 and the architecture of the tenant 1010 n or the client organization. For example, the variable store 2004 can enable a user of the MSSP provider server 1002, such as an MSSP, to be detected by the MSSP provider server 1002 for the tenant 1010 nVariables associated with the architecture can be defined and / or linked to various artifacts stored in the content library 2002, thereby enhancing the ability of the MSSP provider server 1002 to automate client-specific executions. According to some non-limiting aspects, the MSSP provider server 1002 can automatically configure the tenant 1010 n in response to variables defined by the user.

[0037] The automation scheme 2008 can be configured to recognize commonalities between various tenants 1010 1-n (see Figure 1) and standardize the execution of the MSSP provider server 1002. This represents a significant technical improvement over conventional SOAR management platforms that are configured to execute for a single client organization or require a large amount of manual labor to execute across multiple tenants 1010 1-n or client organizations. For example, conventional SOAR platforms require an assessment of client-specific environments and needs, which requires the design and execution of custom solutions. The automation scheme 2008 of Figure 2, in conjunction with the content library 2002 and the variable store 2004, enables the MSSP provider server 1002 of Figures 1 and 2 to automatically generate customized SOAR solutions and scale such solutions simultaneously across a number of tenants 1010 1-n or client organizations.

[0038] The application initiated by the MSSP provider server 1002 includes a graphical user interface 2010, such as an API broker 2006, and a display and / or peripheral devices (e.g., keyboard, mouse, touch screen, etc.) communicatively coupled to the MSSP provider server 1002, configured to visually present information and receive user input. For example, the graphical user interface 2010 may be configured to execute a wizard that can control the setup and / or automation of the SOAR platform for one or more tenants 1010 n or client organizations.

[0039] Referring further to FIG. 2, one such tenant 1010 n An example architecture is illustrated in accordance with at least one non-limiting aspect of the present disclosure. The MSSP provider server 1002 is configured to detect variables associated with the tenant 1010 n architecture and to design and introduce a unique configuration for the tenant 1010 including one or more modules shown in FIG. 2. n For example, according to a non-limiting aspect of FIG. 2, the tenant 1010 n architecture may include a remote SOAR platform 2018, a dashboard / reporting module 2022, and one or more security tool application programming interfaces ("APIs") 2020 a~d Each security tool API 2020 a~d may be configured to prevent malicious attacks or misuse against the APIs of the clients introduced to the tenant 1010 n Since APIs are the key to programming web-based interactions, they are a target for hackers. Therefore, the security tool API 2020 a~d can monitor the client APIs and, if suspicious events are detected, send an alert 2030 back to the SOAR platform 2018.

[0040] According to some non - limiting aspects, the dashboard / report module 2022 may include a customizable, visual representation of the cybersecurity of tenant 1010 n . For example, the dashboard / report module 2022 enables employees of the MSSP and / or the client organization to visually see what is happening across the tenant 1010 n network and to take corrective actions to protect the network in response to detected threats. This allows the MSSP and / or the client organization to identify, prevent, mitigate, and / or predict cybersecurity incidents in a significantly more efficient manner. Of course, the unique tenant 1010 n architecture of FIG. 2 is presented for illustrative purposes only. According to other non - limiting aspects, the tenant 1010 n architecture designed and introduced by the MSSP provider server 1002 can alternatively be configured to include alternative types and / or quantities of modules. The capabilities of the MSSP provider server 1002, more specifically, the content library 2002, the variable store 2004, and the automation scheme 2008, enable a customized SOAR - based solution that can be remotely managed instead of tenant 1010 n . Each solution is different depending on the variables detected by the variable store 2004 and the artifacts selected from the content library 2002 based on the detected variables, as introduced by the MSSP provider server 1002

[0041] Furthermore, the architecture 2000 of FIG. 2 further includes various modules of the MSSP provider server 1002 and one or more tenants 1010 nShows different communication means between them. According to some non-limiting embodiments, the TCP / HTTP protocol can be used for communication between layers. According to other non-limiting embodiments, the RPC and / or MQ protocol can be used. Different layers can be used to provide separation between different modules, and each module can have one or many different access points for each layer. For example, an HTTP endpoint can be used for service calls, a file upload method can be used for content, and / or a database access protocol / specification can be used for management.

[0042] According to other non-limiting embodiments, a specific module such as API broker 2006 can communicate with other modules such as service operation engine 2012, graphical user interface 2010, remote SOAR platform 2018, and dashboard / report module 2022 via service layer 2024. Other modules such as content library 2002, variable store 2004, and API broker 2006 can communicate with tenant 1010 n via management and content delivery layer 2026 with remote SOAR platform 2018 of tenant 1010. Remote SOAR platform 2018 can communicate with one or more security tool APIs 2020 n of tenant 1010 a~c via SOAR communication protocol 2028. One or more security tool APIs send and return alerts to remote SOAR platform 2018 according to rules defined by artifacts 2032 applied from content library 2002 as defined by variables from variable store 2004 via alert protocol 2030. In other words, MSSP provider server 1002 can communicate with user and / or tenant 1010 nIt is possible to provide various visual indicators (e.g., shape, color, icon, etc.) that correlate with each of the various automations available. Non-limiting examples of such visual indicators are provided in U.S. Provisional Patent Application No. 63 / 302,828, filed on January 25, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR REMOTELY MANAGING ANOTHER ORGANIZATIONS SECURITY ORCHESTRATION, AUTOMATION, AND RESPONS", the disclosure of which is incorporated herein by reference in its entirety. In any case, the impact that the artifacts selected from the content library 2002 and the variables detected from the variable store 2004 have on the artifact 2032 is shown in FIG. 2 via corresponding cross-hatching.

[0043] As illustrated in a non-limiting aspect of FIG. 2, the various modules of the architecture of the MSSP provider server 1002 are associated with the tenant 1010 according to a particular artifact 2032 from the content library 2002, which is a self-selected variable determined by and / or previously stored in the variable store 2004. n Thus, the content library 2002 and the variable store 2004, together with the automation scheme 2008, may enable the MSSP provider server 1002 to autonomously generate a custom configuration for integrating with and remotely managing the SOAR platform 2018 of each tenant 1010. For example, the artifact 2032 may cause the API broker 2006 and the service operation engine 2012 of the MSSP provider server 1002 to n communicate with, manage, and control the remote SOAR platform 2018 of the tenant 1010. n nMeans for interfacing with the remote SOAR platform 2018 can be defined. Further, the artifact 2032 can further define the content alerts 2030 and the conditions for their transmission from one or more security tool APIs 2020 a~d to the remote SOAR platform 2018.

[0044] The MSSP provider server 1002, including the content library 2002, the variable store 2004, and the automation scheme 2008, can provide a powerful cloud-based tool that enables the MSSP to remotely manage the client organization's SOAR platform 2018. The primary interface is the graphical user interface 2010, but the API interface 2006 can further enable program control of the SOAR platform 2018 management functions, whereby the user can, via the central interface, introduce content in the form of playbooks, automation, integration, dashboards, and other SOARs to control the code-based content in a remote environment such as the tenant 1010 n etc. Further, the content library 2002, the variable store 2004, and the automation scheme 2008 of the MSSP provider server 1002 enable customization of its content and provide features that enable customized introductions based on the specific needs of the tenant 1010 n In other words, the MSSP provider server 1002 can provide a modular and scalable approach that references a stored library of code and content (e.g., the content library 2002) such that options can be autonomously determined at the time of introduction.

[0045] For example, the user can enable the integration of next-generation antivirus (NGAV) products, email security products, and / or identity protection products, and then automate the detection, investigation, and response phases based on the controls received from the user via the graphical user interface 2010. A series of artifacts stored in the content library 2002, such as playbooks, code, integrations, and / or dashboards, can be deployed. Additionally and / or alternatively, the MSSP provider server 1002 can enable the user to automate a part of the architecture or environment of tenant 1010n. Further, the graphical user interface 2010 can enable the user to "opt-in" and / or "opt-out" of automation features as presented by the automation scheme 2008 via wizard-like tracking, walkthroughs, and application simplification. The user can further customize the reports and / or dashboard functions and preferences to be applied via the dashboard / report module 2022, which can be packaged for introduction along with the automation content.

[0046] According to some non-limiting aspects, the applications launched by the MSSP provider server 1002 may be scalable, i.e., have a SOAR platform 2018 that can be remotely managed (e.g., scalability) for tenant 1010 nIt can be configured with the ability to expand or extend with respect to the number of, and / or the number of SOAR management functions provided. In other words, the application, including the content library 2002, the variable store 2004, and the automation scheme 2008, can be designed to minimize the level of effort required for the MSSP provider server 1002 to be extended for future use. For example, an extension mechanism provided by an application launched by the MSSP provider server 1002, a pluggable add-on configured to enable additional service components and features of the MSSP provider server 1002, can be introduced in the future. For example, according to some non-limiting aspects, the extension mechanism can be provided via a GUI, API, and / or code library that enables a user to expand functions at a predetermined position within the life cycle. As long as the user follows the provided interface / abstraction, the MSSP provider server 1002 transparently invokes custom extensions and / or enables extensions specific to the user and / or tenant 1010 n When the user introduces these add-ons via automation, it triggers the application launched by the MSSP provider server 1002 to enable additional subscription-based services instead of the MSSP, and the security and health monitoring of the tenant 1010 n can be enhanced. Additionally and / or alternatively, the application introduced by the MSSP provider server 1002 can be configured to operate on existing "unmanaged" content that can discover and mildly manage at least some of the previously introduced SOAR assets by the tenant 1010, instead of generating a completely new customized tenant 1010 architecture as illustrated in FIG. 2. n Instead of generating a completely new customized tenant 1010 architecture, as illustrated in FIG. 2, it can be configured to operate on existing "unmanaged" content that can discover and mildly manage at least some of the previously introduced SOAR assets by the tenant 1010 n can be enabled.

[0047] As described above, when executed by the processor 1004 (FIG. 1), the application may be configured to abstractly and / or dynamically manage the SOAR platform 2018 of the client organization. For example, in an abstract implementation, as disclosed in U.S. Provisional Patent Application No. 63 / 196,458, entitled "DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS", filed on June 3, 2021, the MSSP provider server 1002 may employ a generically defined artifact stored in the content library 2002, the disclosure of which is incorporated herein by reference in its entirety. The generically defined artifact may include, for example, a block of executable code. However, a platform-specific implementation can be provided thereafter (e.g., Azure Defender, Crowdstrike, etc.).

[0048] Alternatively, in a dynamic implementation, the MSSP provider server 1002 can dynamically generate new automation types via the content library 2002, which can be automatically detected by the graphical user interface 2010 and displayed for selection for subsequent introduction. Similarly, new automation such as an endpoint monitoring solution (e.g., CarbonBlack, etc.) that blocks the execution of malicious programs detected by the automation (e.g., blocks executable file automation, etc.) can be added to the content library 2002 for a given automation type. Similarly, it becomes automatically available in the GUI and can be deployed to the appropriate client SOAR (which uses these security tools).

[0049] Upon introduction via the MSSP provider server 1002, tenant 1010 n, or the client, certain change points can be detected by the variable store 2004 and correlated with artifacts stored in the content library 2002. For example, the change points can include a specific customer, or tenant 1010, such as the area to which the customer tenant 1010 n belongs, a specific vendor, and / or an enabled extension, etc. Thus, at the time of introduction, the change points can be configured based on the network architecture of tenant 1010 n for the SOAR needs specific to tenant 1010 n . According to one non-limiting aspect, the MSSP provider server 1002 can automate the SOAR platform 2018 to block user accounts upon detection of security events based on the input received by the security tool API 2020 n . For example, the automation can include several steps or conditions, such as approval from the tenant 1010 a~d administrative account. During the introduction, for example, via a wizard presented through the graphical user interface 2010, the automation can request the user to provide information (such as a phone number, a short message service (「SMS」) address, an email address, etc.) associated with one or more administrative accounts of tenant 1010 n . Thus, specific steps and / or conditions, such as contact and / or prompting of actions from the administrative account, can be programmed into the automation via the graphical user interface 2010 n .

[0050] According to one non-limiting aspect, when executing custom automation, the MSSP provider server 1002, more specifically, the custom automation generated by the MSSP provider server 1002, manages the SOAR platform 2018 to interact with one or more security tool APIs 2020 a~dBased on the input / alert received from , it can be determined that it is necessary to detect security events and block user accounts. The MSSP provider server 1002 manages the SOAR platform 2018, notifies the administrative account, and the automation can wait for approval. Once approval is received, it continues to the subsequent steps of the automation and finally, the tenant 1010 n From the network, the suspicious account can be deleted. As described above, this can be abstracted into an automation type using specific implementations for each security tool API 2020 a~d and / or notification methods.

[0051] When introduced by the MSSP provider server 1002, the artifact 2032 (e.g., automation) can exist within the tenant 1010 n architecture. Depending on non-limiting aspects, the MSSP and / or the client can modify the introduced configuration. For example, according to some non-limiting aspects, the client may wish to control the configuration introduced across the tenant 1010 n network. However, according to other non-limiting aspects, the client may wish for the MSSP to have exclusive control of the configuration. In any case, the application introduced by the MSSP provider server 1002 can be configured to automatically detect changes made by the MSSP and / or the client and use them for the management of future introductions and / or updates to the already introduced artifact 2032. According to some non-limiting aspects, such changes can be utilized by the artificial intelligence stored in the memory 1006 (Figure 1) of the MSSP provider server 1002 to adapt one or more artifacts 2032 (e.g., templates, workflows, etc.) within the content library 2002 for extended introductions for similar clients and / or architectures.

[0052] Therefore, when introduced by an application on the MSSP provider server 1002, the content library 2020 can function as a contributing mechanism that can detect updates to both the content library 2002 and the client SOAR platform 2018, abstractly and / or dynamically, along with the graphical user interface 2010 and the API broker 2006. These updates can be managed collectively via the MSSP provider server 1002, which functions as the central console of the system 1000 (FIG. 1), enabling unprecedented scalability and the management of a large number of clients. In this way, the MSSP provider server 1002 can remotely manage another client's SOAR platform 2018 with reliability and consistency. Due to its modular design, as third-party vendor solutions evolve, users and third-party applications can contribute to and / or update existing artifacts 2032, enabling it to be "future-proofed."

[0053] Referring now to FIG. 3, an onboarding architecture 3000 employed by the system 1000 of FIG. 1 is shown in accordance with at least one non-limiting aspect of the present disclosure. According to a non-limiting aspect of FIG. 3, a user 3002 (e.g., an MSSP) can initiate the provisioning and / or updating of SIEM for a plurality of tenants 1010 1~n (FIG. 1) via a plurality of widgets 3006 a~e 、3008 a~eIt is possible to access the MSSP system 3004, which includes a graphical user interface. The MSSP system 3004 can be stored in the memory 1006 of the MSSP provider server 1002 (FIG. 1) and, when executed by the processor 1004 (FIG. 1) of the MSSP provider server 1002 (FIG. 1), the graphical user interface can be presented on a display communicatively coupled to the MSSP provider server 1002 (FIG. 1). According to some non-limiting aspects, the MSSP system 3004 of FIG. 3 may be similar to that disclosed in U.S. Provisional Patent Application No. 63 / 196,458, entitled "DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS", filed on June 3, 2021. However, the MSSP system 3004 of FIG. 3 may include alternative mechanisms to facilitate the provisioning, management, and updating of enhanced SIEM, as described in more detail herein. In other words, the MSSP management system 3004 1~n (FIG. 1) may include a visual representation, i.e., a "dashboard", configured to display data, trends, and / or anomalies associated with security activities and events across multiple tenants 1010. Different communication lines 3022, 3024 between the system components of the architecture are further illustrated.

[0054] According to a non-limiting aspect of FIG. 3, the MSSP provider server 1002 (FIG. 1) can be communicatively coupled to a content repository 3010 that can be accessed by a user 3002 via the MSSP system 3004. The content repository 3010 can enable the user 3002 to search for and obtain such content via the MSSP management platform 3004. Further, the content repository 3010 can be configured to actively interface with the MSSP management system 3004 such that the MSSP system 3004 can autonomously access, correlate, and execute content within the repository 3010 for tenant-specific execution. Together with the MSSP system 3004 and the content repository 3010, tenant 1010 1-n (FIG. 1) can visualize artifacts available for a particular SIEM implementation, changes available for a SIEM implementation, and various other implementation tasks. According to some non-limiting aspects, the content repository 3010 can be client-specific. However, according to other non-limiting aspects, the content repository 3010 can be provided via a third party (e.g., Splunk, Sentinel, GitHub, etc.). In any case, the content repository 3010 can be a database configured to store digital content such as artifacts and / or SIEM execution and management solutions (e.g., resource groups, log analysis workspaces, data connectors, alert rules, playbooks, workbooks, etc.).

[0055] For example, the content repository 3010 can store a workbook, and the workbook can assist in visualizing data associated with each of a plurality of tenants 1010 1~n (FIG. 1) clients 1012 a~n 、1014 a~n 、1016 a~n . Additionally and / or alternatively, the content repository 3010 can respond to security events and / or alerts to the MSSP provider server 1002 and / or tenant 10101~n (FIG. 1) can save a playbook or protocol that can be executed in the direction of the MSSP system 3004. Generally, the SIEM configuration 3018 is for tenant 1010 1~n Instead of each of (FIG. 1), it can be configured to protect the network. For example, the SIEM configuration 3018 can monitor the network for security events and take measures to protect the network. According to some non-limiting aspects, the actions can be for the MSSP user 3002 and / or tenant 1010 1~n (FIG. 1), and may include issuing alerts to the management account for. However, according to some non-limiting aspects, the SIEM configuration 3018 is based on one or more artifacts for tenant 1010 n~1 From the network, suspicious accounts can be detected and removed.

[0056] As described above, the MSSP management system 3004 allows the user 3002 to manage multiple tenants 1010 1~n (FIG. 1) to start SIEM provisioning and / or updating for a plurality of widgets 3006 a~e 、3008 a~e and may include a graphical user interface. For example, according to some non-limiting aspects, the graphical user interface of the MSSP management system 3004 in FIG. 3 is similar to any of the graphical user interfaces disclosed in U.S. Provisional Patent Application No. 63 / 196,991, entitled "DEVICES, SYSTEMS, AND METHODS FOR STANDARDIZING AND STREAMLINING THE DEPLOYMENT OF SECURITY INFORMATION AND EVENT MANAGEMENT ARTIFACTS FOR MULTIPLE TENANTS", filed on June 4, 2021. According to the non-limiting aspect of FIG. 3, the graphical user interface includes a first plurality of widgets 3006 a~ecan include the first plurality of widgets 3006 a~e Each widget 3006 a~e corresponds to a plurality of tenants 1010 1~n (FIG. 1) tenants 1010 1~n (FIG. 1). Further, the graphical user interface can include a second plurality of widgets 3008 a~e Each widget 3008 of the second plurality of widgets 3008 a~e corresponds to a plurality of tenants 1010 a~e (FIG. 1) each tenant 1010 1~n (FIG. 1) corresponds to the SIEM configuration and / or SIEM status for (FIG. 1). 1~n (FIG. 1).

[0057] Referring further to FIG. 3, the MSSP management system 3004 and the MSSP provider server 1002 can be configured to provision the SIEM configuration 2018 to the tenant network 3020 of one or more new tenants 1010 1~n (FIG. 1). For example, according to the non-limiting aspect of FIG. 3, the MSSP management system 3004 can prompt the user 3002 to select and / or create a desired tenant 1010 1~n (FIG. 1) profile and specific artifacts (such as alert rules, playbooks, workbooks, etc.) to be introduced from the content repository 3010 for execution on the selected tenant 1010 1~n (FIG. 1). Upon receiving input from the user 3002, the MSSP management system 3004 can autonomously generate the necessary scripts, customized content, and any other necessary artifacts and aggregate them in the tenant-specific repository 3012. The use of the tenant-specific repository 3012 is to actually introduce the content directly from the repository 3010 to the tenant 1010 1~n (FIG. 1) Instead, the tenant 1010 1~n (FIG. 1) has its own tenant 1010 1~nTo distinguish the MSSP provider server 1002 and the MSSP management system 3004 from conventional MMSP tools, the MSSP management system 3004 extracts content that has been intelligently and autonomously curated by the MSSP management system 3004 from the tenant-specific repository 3012. Alternatively, the MSSP management system 3004 can push content to (FIG. 1), and may include a script engine configured to do so. In other words, the MSSP management system 3004 can autonomously introduce the initial SIEM configuration 3018 instead of (FIG. 1), or provide the SIEM configuration 3018 to the tenant-specific repository 3012 for the tenant 1010 (FIG. 1) to introduce spontaneously according to the preferences of (FIG. 1). In any case, the MSSP management system 3004 can generate a custom SIEM configuration 3018 for the specific tenant 1010 (FIG. 1) provisioned to (FIG. 1). In particular, the MSSP management system 3004 and the MSSP provider server 1002 in FIG. 3 can facilitate the provisioning of the SIEM configuration 3018 for a new tenant 1010 (FIG. 1) without the user 3002 having to write a new script or modify an existing script to match the specific environment and / or introduction needs of the tenant 1010 (FIG. 1). 1~n To (FIG. 1), it may include a script engine configured to push content. In other words, the MSSP management system 3004 can 1~n Instead of (FIG. 1), autonomously introduce the initial SIEM configuration 3018, or 1~n According to the preferences of (FIG. 1), provide the SIEM configuration 3018 to the tenant-specific repository 3012 for the tenant 1010 1~n To introduce spontaneously. In any case, the MSSP management system 3004 can 1~n Provisioned to (FIG. 1), the specific tenant 1010 1~n For (FIG. 1), generate a custom SIEM configuration 3018. In particular, the MSSP management system 3004 and the MSSP provider server 1002 in FIG. 3 can 1~n Without the user 3002 having to write a new script or modify an existing script to match the specific environment and / or introduction needs of the tenant 1010 1~n (FIG. 1), facilitate the provisioning of the SIEM configuration 3018 for a new tenant 1010 (FIG. 1).

[0058] Furthermore, the architecture 3000 in FIG. 3 may further include a SIEM update engine 3014 of the MSSP management system 3004, and the MSSP provider server 1002 in FIG. 3 may be configured to update artifacts stored in the tenant-specific repository 3012 and / or the content repository 3010. According to a non-limiting aspect of FIG. 3, the update engine 3014 evaluates the existing SIEM configuration 3018 and for one or more tenants 1010 1~nCompare one or more SIEM configurations 3018 introduced across (FIG. 1), notify the MSSP, and be configured to autonomously determine whether to retain or reject any proposed changes to the existing tenant-specific SIEM configuration 3018. When the content is updated, the changes are registered via the MSSP management system 3004 and displayed via the graphical user interface and / or by a job scheduling engine 3016 such as a cron command line utility or equivalent. In some non-limiting embodiments, the job scheduling engine 3016 may be provided by a third party. Thus, the MSSP management system 3004 and the MSSP provider server 1002 ensure that the tenant-specific repository 3012 has the latest SIEM configuration 3018 for the environment specific to tenant 1010 1~n (FIG. 1) and / or the introduction needs, and can autonomously ensure that the tenant-specific repository 3012 is prepared for future SIEM configurations 3018 and / or provisioning of updates.

[0059] Referring further to FIG. 3, the MSSP provider server 1002 can be configured to monitor the tenant-specific repository 3012 and / or the content repository 3010 for content changes via custom callbacks. For example, according to some non-limiting aspects, the MSSP management server 1002 autonomously initiates periodic webhooks and / or queries for content changes within the tenant-specific repository 3012 and / or the content repository 3010, correlates any detected changes for applicability to each tenant-specific repository 3012, evaluates them, and when it is determined that the detected changes are applicable to the tenant-specific repository 3012, can easily programatically push each change to the applicable tenant-specific repository 3012. What further distinguishes the MSSP management system 3004 and the MSSP provider server 1002 from conventional devices is the ability to update the tenant-specific repository 3012 without requiring custom code. Further, the MSSP management system 3004 and the MSSP provider server 1002, as further described in U.S. Provisional Patent Application No. 63 / 196,458, filed on June 3, 2021, entitled "DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS", for a number of tenants 1010 1~n (FIG. 1), regardless of their specific environment and deployment needs, provide a simultaneous "one-click" SIEM update process over the scalability of the system 1000 (FIG. 1), the disclosure of which is hereby incorporated by reference in its entirety.

[0060] Tenant 1010 of the SIEM configuration 3018 1~nSimilar to the initial provisioning to (Figure 1), when the content and / or artifacts within the tenant-specific repository 3012 are updated, the introduction of the system 1000 (Figure 1) can be configured to update the artifacts for any of the previously provisioned SIEM configurations 3018 for a plurality of tenants 1010 1~n of any tenant 1010 1~n Specifically, tenant 1010 1~n (Figure 1) can retrieve intelligent and autonomously updated content from the tenant-specific repository 3012 via the update engine 3014 of the specific tenant 1010 1~n (Figure 1). Alternatively, the MSSP management system 3004 can include a script engine configured to push the updated content from the tenant-specific repository 3012 to tenant 1010 1~n (Figure 1). In other words, the MSSP management system 3004 can autonomously update the SIEM on behalf of tenant 1010 1~n (Figure 1), or can be specifically configured to provide the SIEM configuration 3018 to the tenant-specific repository 3012 for tenant 1010 1~n (Figure 1) to introduce spontaneously according to the preference of tenant 1010 1~n (Figure 1). According to some non-limiting aspects, the update to the SIEM configuration 3018 can be managed according to the lifecycle management of tenant 1010 1~n (Figure 1), which means that 1010 1~n (Figure 1) can approve the changes that are first pushed to the tenant-specific repository 3012 before the SIEM configuration 3018 itself is introduced to tenant 1010 1~n (Figure 1). In any case, the MSSP management system 3004 can customize and introduce the updates to the SIEM configuration 3018 for the specific tenant 1010

[0061] For example, according to some non-limiting aspects, the MSSP management server 1002 generates scripts (e.g., repository command references, repository "commit" commands, etc.) that autonomously initiate queries for periodic webhooks and / or content changes in the tenant-specific repository 3012 and / or the content repository 3010, and may include a script engine configured to correlate and evaluate any detected changes for applicability to each tenant-specific repository 3012. Upon determining that a detected change is applicable to a tenant-specific repository 3012, the MSSP management server 1002 can programmatically push each change to the applicable tenant-specific repository 3012. To further enhance this approach, tenant 1010 having a similar environment and / or introduction needs 1~n can share the tenant-specific repository 3012 among the groups of (FIG. 1).

[0062] According to some non-limiting aspects, tenant 1010 1~n (FIG. 1) may want to make changes in its own environment. For example, tenant 1010 1~n (FIG. 1) may choose to change and / or remove the introduced alert rules, workbooks, etc. The job scheduling engine 3016, e.g., a regular cron job, can detect profile changes initiated by tenant 1010 1~n (FIG. 1) and notify the MSSP via the MSSP management system 3004. Next, the MSSP can determine whether to retain the changes initiated by tenant 1010 1~n (FIG. 1) by providing input via a graphical user interface. Further, the MSSP management system 3004 can enable the MSSP to lock the changes initiated by tenant 1010 1~n (FIG. 1) from automatic updates, or publicly reject them such that future executed updates to the SIEM configuration 3018 override the changes initiated by tenant 1010 1~n (FIG. 1).

[0063] Referring further to FIG. 3, the architecture 3000 and the system 1000 (FIG. 1) in which it is implemented enable a user 3002 to perform large-scale introductions and updates of the SIEM configuration 3018 and, via the tenant-specific repository 3012, across multiple tenants 1010 1~n (FIG. 1), to monitor changes to the SIEM configuration 3018 introduced thereacross. The disclosure of U.S. Provisional Patent Application No. 63 / 196,458, filed Jun. 3, 2021, entitled "DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS", among other SIEM portals, is hereby incorporated by reference in its entirety and can provide the user 3002 with full management of the introduced SIEM configuration 3018. However, the architecture 3000 of FIG. 3 provides further enhancements and integrates a portal and user interface with an encrypted approach that enables updates without user 3002 intervention. According to some non-limiting aspects, the approach can be audited by tenants 1010 1~n (FIG. 1). Thus, the user 3002 can track per-introduction changes and / or roll back previously introduced changes in a much more efficient and scalable manner than conventional systems.

[0064] Additionally and / or alternatively, the architecture 3000 and the system 1000 (FIG. 1) in which it is implemented enable a tenant 1010 1~n (FIG. 1) to control its own SIEM configuration 3018 and change artifacts introduced by the MSSP management system 3004. However, the MSSP management system 3004 is for tenants 1010 1~nDetect changes started in ([Figure 1]), capture them in the tenant-specific repository 3012, generate and maintain the update history of the SIEM configuration 3018, while user 3002 is tenant 1010 1~n Changes started in ([Figure 1]) can be made easily reviewable and lockable.

[0065] Currently, when substantially all introductions are performed manually or via code (e.g., scripts), the MSSP needs to update the code with client-specific information. This makes conventional system errors more likely to occur and requires a high level of skill and understanding of the content being updated. As described above, the initial provisioning of SIEM via a conventional SIEM platform requires the MSSP to manually enter client-specific information such as the introduction location, certificates, and introduction content (e.g., alert rules, etc.). However, while conventional SIEM platforms provide the client with a graphical user interface through which the initial SIEM provisioning and configuration are performed, the MSSP platform 3004 of FIG. 3 can autonomously generate custom introduction scripts (e.g., via ARM templates, Terraform, PowerShell, etc.) to perform the initial SIEM provisioning and configuration programmatically.

[0066] Tenant 1010 monitored and managed by the system 100 of FIG. 1 via the architectures 2000, 3000 of FIGS. 2 and 3 1-n Since the quantity in ([Figure 1]) is highly scalable, the MSSP server 1002 (Figure 1) can handle multiple tenants 1010 1-nThere is a need for devices, systems, and methods that can ingest and enrich large amounts of security information from multiple sources, including the various sources distributed according to (FIG. 1). Specifically, such devices, systems, and methods need to interface with various APIs and enrich their data sources via one or more automated processes. Referring now to FIG. 4, a platform 4000 configured to ingest and enrich a highly scalable amount of security information via automation is shown in accordance with at least one non-limiting aspect of the present disclosure. According to some non-limiting aspects, the platform 4000 is cloud-based and includes an MSSP server 1002 and / or a plurality of tenants 1010 1-n It can be configured to remotely ingest and enrich security information for sources of such information, such as (FIG. 1). According to the non-limiting aspect of FIG. 4, the platform 4000 may include a job manager 4010 and a workflow engine 4012. In summary, the job manager 4010 and the workflow engine 4012 enable the platform 4000 to quickly ingest, enrich, and transform large-scale, scalable security information that is qualified for improved case management and collection of extensive analytical use cases, significantly exceeding the technical capabilities of conventional platforms.

[0067] The job manager 4010 can be configured to effectively and autonomously scale the ingestion of new data sources, such as the data sources 4002, 4004, 4006, 4008 shown in FIG. 4. For example, the job manager 4010 can interface with data sources, such as a configuration database 4002, that accommodate one or more security tools, including an endpoint detection and response (EDR) tool 4004 (e.g., Sentinel, Carbon Black, Singularity, Falcon, Defender, Trend Micro XDR, etc.), a detection as a service (DaaS) tool 4006 (e.g., Splunk, Mixpanel, Sentry, etc.), and / or a vendor management (VMS) tool 4008 (e.g., Tenable, TripWire, Alert logic, etc.). According to some non-limiting aspects, VMS can be achieved via a slightly different process separate from the overall system. It should be considered a side process. The job manager 4010 can be configured to execute one or more "fetch jobs" that obtain security information (e.g., security alerts, device information, vulnerability data, user information, various security metadata, vendor-related metadata, etc.) obtained from various sources 4002, 4004, 4006, 4008. As used herein, a "job" can include a unit of work for a system to fetch data of a particular configuration within the job manager, and the manager may be responsible for sending various jobs.

[0068] According to some non-limiting aspects, such sources 4002, 4004, 4006, 4008 can be hosted by third parties and contracted via an MSSP. Thus, the job manager 4010 can simultaneously execute "n" fetch jobs, each corresponding to "n" data sources, to collect the security information required by the architecture MSSP (e.g., architectures 2000, 3000 of FIGS. 3 and 4), for multiple tenants 1010 1-nEach tenant 1010 of (FIG. 1) 1-n (FIG. 1) can be continuously monitored and protected. The job manager 4010 can achieve this by performing an exhaustive scan of the configuration database 4002 and / or various other data sources 4004, 4006, 4008 according to one or more fetch jobs. As described in more detail herein, the platform 4000 can then normalize the security information it receives from the data sources 4002, 4004, 4006, 4008 into a common standard format for processing via the workflow engine 4012.

[0069] Referring further to FIG. 4, the security information obtained by the job manager 4010 from each source 4002, 4004, 4006, 4008 can be sent to a workflow engine 4012 that can include an alert enrichment tool 4014 and a response and synchronization tool 4026. The alert enrichment tool 4014 can include a plurality of modules 4016, 4018, 4020, 4022, 4024 collectively configured to enrich the security information collected by the job manager 4010 according to an automated playbook in response to the detected type (e.g., EDR security alert, SIEM / DaaS security alert, ICC data, etc.) associated with each particular piece of the security information collected by the job manager 4010. Each of these "types" will have a specific playbook for analyzing and contextualizing the data. In some cases, the automation of the playbook can also call another playbook.

[0070] For example, the workflow engine 4012 may include a security alert enrichment module 4016, an Indicator of Compromise (IOC) extraction module 4018, a data normalization module 4020, a Security Operations Center (SOC) automation module 4022, and / or an enrichment post-automation module 4024. When the workflow engine 4012 receives security information from the job manager 4010, the enrichment module 4016 can enrich information such as security alerts based on various processes (e.g., simple lookups, analysis, contextualization, etc.) that are predefined by specific automation playbooks and considered applicable by the SOC automation module 4022. Depending on the data type, the information can be contextualized through lookups in appropriate sources or correlated with existing data already present in the system. As used herein, "analysis" can refer to the normalization of data, and for each data type, since it can originate from multiple sources, the information is integrated into a "common schema". In other words, the enrichment module 4016, the IOC extraction module 4018, and the data normalization module 4020 can, in some non-limiting ways, use additional data and / or metadata to classify and / or contextualize the collected security information for further analysis and / or investigation that is performed through the SOC automation module 4022 and the enrichment post-automation module 4024.

[0071] Specifically, the SOC automation module 4022 of the workflow engine 4012 in FIG. 4 can be configured to execute an automated playbook that performs a series of automated analyses, additional enrichments, etc. according to the enriched and detected type of security information. Therefore, the SOC automation module 4022 enables the workflow engine 4012 to respond quickly and autonomously to risks detected based on the security information collected by the job manager 4012, and respond to those risks through a plurality of well-prepared use cases. The playbook adopted by the SOC automation module 4022 is a predefined template through machine learning and / or artificial intelligence algorithms adopted by the workflow engine 4012, and can be customized and / or updated autonomously. In this way, the SOC automation module 4022 enables the workflow engine 4012 to respond to security alerts at unprecedented speeds and accuracies. The post-enrichment automation module 4024 can execute automated actions associated with assets distributed across the network in Tenant 1010 1-n (FIG. 1) According to some non-limiting aspects, the enrichment can be based on a correlation between new incoming data and previously collected existing data. For example, according to such aspects, an alert can be associated with a computer asset, and the MSSP provider server 1002 can enable an automated response that includes actions dependent on the tenant 1010 n , the unique asset location, and / or the unique vendor. One of such actions can include remotely isolating a suspicious asset from the client network via an automated mechanism.

[0072] For example, the post-enrichment automation module 4024 enables the workflow engine 4012 to perform asset discovery scans, asset linking, classification activities, and target prioritization, and the MSSP to perform its monitoring and / or the tenant 1010 1-n(FIG. 1) The effort for network penetration can be made to be autonomously operable. In other words, the workflow engine 4012, and in particular, the various modules 4016, 4018, 4020, 4022, 4024, can enhance the individual security of each of a relatively large number of tenants 1010 as compared with conventional devices, systems, and methods. 1-n The individual security of each can be enhanced.

[0073] Referring further to FIG. 4, the workflow engine 4012 may include a security tool automation module 4028 configured to generate a security output based on security information collected by the job manager 4010 and processed by the modules 4016, 4018, 4020, 4022, 4024 of the alert enrichment tool 4014. For example, the output may include a ticket prompting an action from the tenant 1010 1-n (FIG. 1), and / or any other means of disposing of the security information processed via the tenant security management system 4030 communicatively coupled to the workflow engine 4012. According to some non-limiting aspects, the tenant security management system 4030 is for the tenant 1010 1-nIt may be a server inside (Figure 1), or it may be a server configured to manage third parties, information technology service management providers, especially security-based workflows (e.g., ServiceNow, SysAid, etc.). In any case, the tenant security management system 4030 may be configured to start a workflow based on the output received from the workflow engine 4012, and the workflow may include a plurality of steps executed by one or more modules 4032, 4034, 4036, 4038 of the tenant security management system 4030. For example, the tenant security management system 4030 may include its own SOC automation module 4032, workflow and communication module 4034, SOC action module 4036, and / or post-processing automation module 4038. Specifically, the SOC action module 4036 and the post-processing automation module 4038 may be configured to interface with and interact with the response of the workflow engine 4012, which may include a security tool automation module 4028, and the synchronization back tool 4026. The security tool automation module 4028 may execute a series of security actions across the tenant 1010 1-n across the infrastructure, and may be configured to change those actions based on the input received from the SOC action module 4036 and the post-processing automation module 4038. In other words, the workflow engine 4012 and the tenant security management system 4030 may be configured to interact with each other, so that the workflow engine 4012 can autonomously generate and execute security actions that can be changed in real time in response to the feedback provided by the tenant security management system 4030.

[0074] Referring now to FIG. 5, a logical flow diagram of a method 5000 for ingesting and enriching security information to autonomously protect multiple tenant networks using the platform 4000 of FIG. 4 is shown in accordance with at least one non-limiting aspect of the present disclosure. According to a non-limiting aspect of FIG. 5, the method 5000 may include periodically executing a plurality of fetch jobs 5002 via a job manager 4010 (FIG. 4), each job monitoring a corresponding tenant 1010 1-n (FIG. 1) of the plurality of tenants 1010 1-n (FIG. 1) for configuration or integration (FIG. 1). For example, the job manager 4010 (FIG. 4) may periodically execute each fetch job once in a predetermined period, which may include a desired number of seconds, minutes, or amount of time. According to some non-limiting aspects, each of the plurality of tenants 1010 1-n (FIG. 1) may have its own tenant-specified period during which the job manager 4010 (FIG. 4) executes the fetch job. According to some non-limiting aspects, the configuration may require tenant-specific certificates for each respective configuration environment. As described above, each fetch job can contextualize the security information monitored against the information provided by sources 4002, 4004, 4006, 4008, and the security information is associated with each of the plurality of tenants 1010 1-n (FIG. 1) of each tenant 1010 1-n (FIG. 1). In other words, the information collected via the fetch process may trigger a specific alert, which generates a job of the workflow manager 4012 (FIG. 4) associated with the alert.

[0075] Referring further to FIG. 5, the job manager 4010 (FIG. 4) provides 1-n fetch instructions (or jobs associated with a set of security information and / or alerts) to the workflow engine 4012 (FIG. 4). The method 5000 further includes querying 5004 the instructions via the workflow engine 4012 (FIG. 4), and as a result, queuing 5006 the fetched instructions that need to be processed via the workflow engine 4012 (FIG. 4). According to some non-limiting aspects, the query 5004 may be implemented on a first-in, first-out basis. According to other non-limiting aspects, the query 5004 may be implemented based on priority criteria. In still other non-limiting aspects, any queue 5012 may be generated for jobs of similar priority and / or type. In any case, the fetch 5002 and query 5004, and the resulting queue 5006 allow the MSSP to easily scale the ingestion of security information based on the queue 5006 size, for each tenant 1010 1-nIn order to strengthen its network security, it can surely receive the necessary attention from the workflow engine 4012 (FIG. 4). Then, as described above, the workflow engine 4012 (FIG. 4) can process 5008 the security information of the queue 5006 and generate 5010 outputs such as tickets. Specifically, the workflow engine 4012 (FIG. 4) receives tenant-specific alerts from the sources 4002, 4004, 4006, 4008 and can perform enrichment, lookup, and analysis using the standard model, or the Common Information Model (CIM), via the modules 4016, 4018, 4020, 4022, 4024 (FIG. 4) as described above. The output can include a main handler and / or a vendor handler that can process the output. The handler can dispose of each tenant-specific output individually or can dispose of multiple outputs based on common tasks. For example, the handler can interact with a ticket issuance platform and a data source to synchronize data between the two. According to some non-limiting instructions, the alert can be output to a platform queue (e.g., ServiceNow), and the handler can handle the alert (e.g., close the alert as a "confirmed defect"). The end of the alert is resynchronized with the source of the alert (e.g., Crowdstrike, SIP, etc.) and can be used for more efficient resolution of future generated alerts.

[0076] Referring now to FIG. 6, the framework 6000 of the job manager 4010 of the platform 4000 of FIG. 4 is shown in accordance with at least one non-limiting aspect of the present disclosure. According to a non-limiting aspect of FIG. 6, the framework 6000 can include a job manager 4010 that is configured to interface with and interact with a queue 6008 of a workflow engine 4012 (FIG. 4) for orchestrating parallel jobs fetched by bolts 6018, a fetch job database 6006, a configuration manager 6004, and the job manager 4010 itself. The configuration manager 6004 polls each tenant 1010 1-n (FIG. 1) for network changes and monitors each tenant 1010 1-n (FIG. 1) and can be configured to add rows to the network and / or tenant-specific data sources. Thus, the configuration manager 6004 can update existing data with new polling intervals and / or connection information, and thus can update the fetch job data it collects and aggregates in the fetch job database 6006, which can store and maintain all appropriate parameters and configurations for each job type (e.g., for each data source 6012 1-n from which data is fetched). The fetch job database 6006 can further store and maintain status logs written by the job manager 4010, which can be consumed by a troubleshooting interface. The configuration manager may be configured to maintain the accuracy of the fetch job database 6006, ensuring that the respective configuration of each tenant 1010 1-n (FIG. 1) is maintained for the corresponding database of each tenant 1010 1-n data source 6012 1-n .

[0077] According to a non-limiting aspect of FIG. 6, the job manager 4010 has a plurality of each tenant 1010 1-nIt can be further configured to create a fetch job for (Figure 1), and call job parameters that determine how the job manager 4010 operates. Further, the job manager 4010 can provide a status API configured to return a JavaScript Object Notation (JSON) snapshot of the job table for troubleshooting the user interface. In other words, the job manager 4010 can generate fetch requests or jobs at appropriate intervals defined by each data source 6012 1-n and is responsible for starting the job based on the parameters specified in the fetch job database 6006. For example, in one non-limiting aspect, the parameters may require the job manager 1010 to fetch security information from the CarbonBlack cloud-based API every five minutes.

[0078] The job manager 4010 can further start the fetch process by executing one or more fetch jobs 6010 1-n configured to access one or more data sources 6012 1-n corresponding to each tenant 1010 of the plurality of tenants 1010. For example, each fetch job 6010 executed by the job manager 4010 1-n can fetch security information including the data source 6012 1-n configuration and / or authentication information from the vault 6018. The vault 6018 can store and maintain the relevant authentication information and configuration necessary to fetch the correct, up-to-date security information from a data source 6012 1-n such as, for example, the SentinelOne cloud-based API. Each fetch job 6010 1-n can fetch security information from each respective data source 6012 1-n 1-n 1-n ​​It can be queried and the relevant security information can be sent to the queue 6008 for processing via the workflow engine 4012 (Figure 4). The queue 6008 can be a highly scalable cluster configured to support and maintain each fetch job across all data sources 6012 for each tenant 1010 1-n For each tenant 1010 1-n It can be a highly scalable cluster configured to support and maintain each fetch job across all data sources 6012 (Figure 1). When the job manager 4010 starts a fetch job, it can be instantiated within the queue 6008, which can execute the fetch and output the fetched security information to the workflow engine 4012 (Figure 4). The job manager 4010 can then update the security status (e.g., record error, timestamp, etc.) and record any metrics (e.g., size, fetch time, success / failure status, etc.) in the fetch job database 6006.

[0079] According to one non-limiting aspect, the queue 6008 may be configured to host an Argo workflow, RabbitMQ may be used as a listener to trigger jobs within the Argo workflow, Hashicorp Vault may be used as the vault 6018, the PostGres database may be used as the fetch job database 6006, and Kubernetes may be used as the configuration manager 6004. However, of course, any equivalent tools can be configured in a similar way to achieve similar results.

[0080] The workflow engine 4012 (Figure 4) can enrich security information fetched during the execution of each job in the queue 6008. As described above, for each type passed by the job manager 4010, the security information can be normalized into a common standard format, and playbooks can be executed to enrich the data with additional context data and / or metadata. Thus, the job manager 4010 and the workflow engine 4012 (Figure 4) can rationalize the investigations conducted by SOC staff members. According to other non-limiting aspects, the workflow engine 4012 (Figure 4) can be further configured to perform additional forms of enrichment, including graph-based links of events and / or data types, and can further enrich security via threat intelligence feeds. For example, according to some non-limiting aspects, the workflow engine can be further configured to enrich data in various contexts. In other words, the workflow engine can perform a user and entity behavior analysis (UEBA) process on all incoming artifacts and attempt to detect specific anomalies in behavior or device usage.

[0081] As described above, the workflow engine 4012 (Figure 4) can be further configured to automate responses and synchronization from the data source 6012 1-n For example, according to one non-limiting aspect, alerts can flow from Splunk correlations and trigger playbooks within the workflow engine 4012 (Figure 4), which can return commands to the Splunk application and automatically execute an additional series of searches to contextualize the initial alert.

[0082] Referring now to FIG. 7, a method 7000 for ingesting and enriching a highly scalable amount of security information is illustrated in accordance with at least one non-limiting aspect of the present disclosure. According to a non-limiting aspect of FIG. 7, method 7000 may be implemented by SIEM provider server 1002 (FIGS. 1 and 2) via platform 4000 of FIG. 4. Specifically, MSSP management system 2004 (FIG. 2) stored in memory 1006 (FIG. 1) may cause processor 1004 (FIG. 1) of SIEM provider server 1002 (FIGS. 1 and 2) to implement method 3000. Referring now to FIG. 6, in one aspect of method 7000, configuration manager 6004 (FIG. 6) may periodically monitor 7002 each tenant 1010 1-n network for configuration changes. Configuration manager 6004 (FIG. 6) may autonomously update 7004 job data and aggregate it in fetch job database 6006 (FIG. 6). Next, job manager 4010 (FIGS. 4 and 6) may generate 7006 one or more fetch jobs to collect security information from data sources 6012 1-n (FIG. 6), where each data source 6012 1-n (FIG. 6) corresponds to at least one tenant 1010 1-n (FIG. 1). Job manager 4010 (FIGS. 4 and 6) may further store each fetch job in queue 6008 (FIG. 6) and execute 7008 one or more fetch jobs to collect security information from each data source 6012 1-n . Thereafter, workflow engine 4012 (FIGS. 4 and 6) may enrich the security information, generate an output, and transmit the output to tenant security management system 4030, which is configured to process the output and enhance network security.

[0083] Referring now to FIG. 8, a scalable security information and event management framework computer system 500 is illustrated as originally described in U.S. Patent No. 10,708,123, entitled "SCALABLE SECURITY INFORMATION AND EVENT MANAGEMENT (SIEM) FRAMEWORK," filed Apr. 24, 2019, the disclosure of which is incorporated herein by reference in its entirety. Specifically, FIG. 8 shows a schematic diagram of a computer system 500 in which embodiments described in the present disclosure may be implemented and executed. According to one non-limiting aspect, computer system 500 may include a bus 502 (i.e., an interconnect), one or more processors 504, main memory 506, read-only memory 508, removable storage media 510, mass storage device 512, and one or more communication ports 514. As should be understood, components such as removable storage media are optional and not required in all systems. Communication port 514 may be connected to one or more networks through which computer system 500 may receive and / or transmit data. As used herein, "processor" means one or more microprocessors, central processing units (CPUs), computing devices, microcontrollers, digital signal processors, or similar devices, or any combination thereof, regardless of architecture. The apparatus for implementing a process may include, for example, a processor and those devices such as input devices and output devices suitable for implementing the process. Processor(s) 504 may be any known processor, such as, but not limited to, a processor manufactured and / or sold by INTEL®, AMD®, or MOTOROLA®, which are generally well known to those skilled in the art and clearly defined in the literature. Communication port(s) 514 may be any of, for example, an RS-232 port for use in a modem-based dial-up connection, a 10 / 100 Ethernet port, a Gigabit port using copper or fiber, or a USB port.The communication port(s) 514 can be selected according to the network, such as a local area network (LAN), a wide area network (WAN), a CDN, or any network to which the computer system 500 is connected. The computer system 500 may communicate with peripheral devices (e.g., a display screen 516, input device(s) 518) via an input / output (I / O) port 520. The main memory 506 may be a random access memory (RAM) or any other dynamic storage device(s) commonly known in the art. The read-only memory 508 may be any static storage device(s), such as a programmable read-only memory (PROM) chip, for storing static information such as instructions for the processor 504. The mass storage device 512 can be used to store information and instructions. For example, a hard disk, an optical disk, an array of disks such as a redundant array of independent disks (RAID) of the Adaptec® family of RAID drives, or any other mass storage device, such as an Adaptec® family of Small Computer System Interface (SCSI) drives, can be used. The bus 502 communicatively couples the processor(s) 504 to the other memory, storage, and communication blocks. The bus 502 can be, for example, a PCI / PCI-X, SCSI, or a Universal Serial Bus (USB)-based system bus (or others) depending on the storage devices used. The removable storage medium 510 can be any kind of external hard drive, floppy drive, Iomega® Zip drive, compact disc read-only memory (CD-ROM), compact disc rewritable memory (CD-RW), digital versatile disc read-only memory (DVD-ROM), etc.

[0084] Accordingly, the job manager 4010 (Figs. 4 and 6), the workflow engine 4012 (Fig. 4), and the method 7000 (Fig. 7) can be executed via cloud-hosted technology configured to ingest and enrich data at any scale through automation. In summary, the job manager 4010 (Figs. 4 and 6), and the workflow engine 4012 (Fig. 4) can ingest and enrich security information from any data source 6012 1-n type, and can scale MSSP support for single and / or multiple ("n") tenants 1010 1-n (Fig. 1), as well as corresponding source 6012 1-n effectively and efficiently, with respect to the conventional devices, systems, and methods. Further, the devices, systems, and methods disclosed herein are vendor agnostic and can adjust efficient response actions (e.g., take any action against any tool within the client environment if the appropriate API is in place) regardless of whether the tenant 1010 1-n uses custom or third-party source 6012 1-n . Further, the job manager 4010 (Figs. 4 and 6), and the workflow engine 4012 (Fig. 4) can separate data ingestion, as well as workflow orchestration and automation, from ticket issuance, and case management tools and processes. Finally, the job manager 4010 (Figs. 4 and 6), and the workflow engine 4012 (Fig. 4) can facilitate security information collection for scalable analytics use cases (e.g., correlation of cases between clients, and / or correlation of case data with external threat and vulnerability sets, large-scale trend analysis, and statistical analysis model analysis, etc.).

[0085] Various aspects of the subject matter described herein are set forth in the following numbered clauses.

[0086] Clause 1: A Security Information and Event Management (「SIEM」) provider server configured to enhance network security instead of a tenant network by autonomously ingesting and enriching security information associated with the tenant network, the SIEM provider server comprising a processor and a memory, the memory configured to store a job manager and a workflow engine, the job manager and the workflow engine, when executed by the processor, causing the processor to periodically monitor the tenant network for configuration changes via a configuration manager of the job manager, detect configuration changes within the tenant network via the configuration manager, update fetch job parameters stored in a job database based on the detected configuration changes within the tenant network via the configuration manager, generate a fetch job for the tenant network based on the updated fetch job parameters stored in the job database via the job manager, store the generated fetch job in a queue, execute the generated fetch job via the job manager such that the job manager obtains security information from a data source associated with the tenant network, enrich the obtained security information via the workflow engine, and generate an output configured to enhance the security of the tenant network via the workflow engine.

[0087] Clause 2: The tenant network is one of a plurality of tenant networks, the tenant-specific SIEM execution is one of a plurality of tenant-specific SEIM executions generated by the SIEM provider server, and the SIEM provider server is configured to simultaneously introduce and update each SEIM execution of the plurality of SEIM executions in place of each tenant network of the plurality of tenant networks. The SIEM provider server according to Clause 1.

[0088] Clause 3: The SIEM provider server is communicatively coupled to a tenant security management system configured to discard the output from the SIEM provider server, and the method further includes transmitting the output to the tenant security management system for the discard via the workflow engine. The SIEM provider server according to Clause 1 or 2.

[0089] Clause 4: Discarding the output includes autonomously removing suspicious accounts from the tenant network. The SIEM provider server according to any one of Clauses 1 to 3.

[0090] Clause 5: The workflow engine includes a plurality of modules, and the plurality of modules include an enrich module, an Indicator of Compromise (「IOC」) extraction module, a normalization module, a Security Operations Center (「SOC」) automation module, and an enrich-after automation module. The SIEM provider server according to any one of Clauses 1 to 4.

[0091] Clause 6: When the workflow engine is executed by the processor, the processor is caused to detect the type of security information associated with the acquired security information, and enriching the acquired security information includes enriching the acquired security information based on the detected type of security information via the enrich module. The SIEM provider server according to any one of Clauses 1 to 5.

[0092] Clause 7: The SIEM provider server according to any one of Clauses 1 to 6, wherein the type of the detected security information is a security alert associated with the tenant network.

[0093] Clause 8: When the workflow engine is executed by the processor, the processor further detects an applicable automation playbook based on the type of the detected security information via the SOC automation module, and enriches the acquired security information via the enrichment module, the SIEM provider server according to any one of Clauses 1 to 7, which is further based on the detected automation playbook.

[0094] Clause 9: The SIEM provider server according to any one of Clauses 1 to 8, further comprising converting the acquired security information into a standard format via the normalization module.

[0095] Clause 10: A method for enhancing network security on behalf of a tenant network by autonomously ingesting and enriching security information associated with the tenant network via a Security Information and Event Management (SIEM) provider server, wherein the SIEM provider server comprises a processor and a memory configured to store a job manager and a workflow engine, the method comprising: periodically monitoring the tenant network for configuration changes via a configuration manager of the job manager; detecting configuration changes within the tenant network via the configuration manager; updating fetch job parameters stored in a job database based on the detected configuration changes within the tenant network via the configuration manager; generating a fetch job for the tenant network based on the updated fetch job parameters stored in the job database via the job manager and storing the generated fetch job in a queue; executing the generated fetch job via the job manager such that the job manager obtains security information from a data source associated with the tenant network; enriching the obtained security information via the workflow engine; and generating an output configured to enhance the security of the tenant network via the workflow engine.

[0096] Clause 11: The method according to Clause 10, wherein the workflow engine comprises a plurality of modules, the plurality of modules comprising an enrichment module, an Indicator of Compromise (IOC) extraction module, a normalization module, a Security Operations Center (SOC) automation module, and a post-enrichment automation module.

[0097] Clause 12: The method according to clause 10 or 11 further includes detecting, via the workflow engine, a type of security information associated with the obtained security information, and enriching the obtained security information includes enriching the obtained security information based on the detected type of security information via the enrichment module.

[0098] Clause 13: The method according to any one of clauses 10 to 12 further includes detecting, via the SOC automation module, an applicable automation playbook based on the detected type of security information, and enriching the obtained security information via the enrichment module is further based on the detected automation playbook.

[0099] Clause 14: The method according to any one of clauses 10 to 13 further includes transmitting, via the workflow engine, the output to a tenant security management system communicably coupled to the SIEM provider server for discard.

[0100] Clause 15: The method according to any one of clauses 10 to 14 includes discarding the output includes autonomously removing a suspicious account from the tenant network.

[0101] Clause 16: A system comprising a plurality of tenant networks and a Security Information and Event Management (SIEM) provider server communicatively coupled to the plurality of tenant networks, the SIEM provider server comprising a processor and a memory, the memory configured to store a job manager and a workflow engine, the job manager and the workflow engine, when executed by the processor, causing the processor to periodically monitor the plurality of tenant networks for configuration changes, detect a configuration change in a first tenant network of the plurality of tenant networks, update fetch job parameters stored in a job database based on the detected configuration change within the first tenant network, generate a fetch job for the tenant network based on the updated fetch job parameters stored in the job database, store the generated fetch job in a queue, execute the generated fetch job such that the job manager obtains security information from a data source associated with the tenant network, enrich the obtained security information, and generate an output configured to enhance the security of the tenant network.

[0102] Clause 17: The system of clause 16, wherein the SIEM provider server is communicatively coupled to a tenant security management system configured to discard output from the SIEM provider server, and the job manager and the workflow engine, when executed by the processor, cause the processor to further transmit the output to the tenant security management system for discard via the workflow engine.

[0103] Clause 18: The system of clause 16 or 17, wherein discarding the output includes autonomously removing a suspect account from the tenant network.

[0104] Clause 19: The system according to any one of Clauses 16 to 18, wherein the workflow engine comprises a plurality of modules, and the plurality of modules comprise an enrichment module, an Indicator of Compromise (IOC) extraction module, a normalization module, a Security Operations Center (SOC) automation module, and an automation module after enrichment.

[0105] Clause 20: The system according to any one of Clauses 16 to 19, wherein the type of the detected security information is a security alert associated with the tenant network.

[0106] All patents, patent applications, publications, or other disclosure materials described in this specification are hereby incorporated by reference in their entirety as if each individual reference were explicitly incorporated by reference. All references, and any materials, or portions thereof, that are said to be incorporated by reference in this specification are incorporated in this specification only to the extent that the incorporated materials do not conflict with existing definitions, descriptions, or other disclosure materials described in this disclosure. For that purpose, and to the extent necessary, the disclosure set forth in this specification prevails over any conflicting materials incorporated by reference in this specification, and the disclosure is described explicitly within the management of this application.

[0107] Various illustrative and exemplary aspects are described. The aspects described herein are to be understood as providing illustrative features of various details of various aspects of the present disclosure, and thus, unless otherwise specified, without departing from the scope of the present disclosure, as far as possible, one or more features, elements, components, ingredients, materials, structures, modules, and / or aspects of the aspects of the present disclosure may be combined, separated, exchanged, and / or rearranged with one or more other features, elements, components, ingredients, materials, structures, modules, and / or aspects of the aspects of the present disclosure. Accordingly, those skilled in the art will recognize that various substitutions, modifications, or combinations of any of the illustrative aspects can be made without departing from the claimed subject matter. Further, those skilled in the art can, by a review of this specification, recognize, or confirm, many equivalents to the various aspects of the present disclosure using only routine experimentation. Accordingly, the present disclosure is not limited by the descriptions of the various aspects, but only by the claims.

[0108] Those skilled in the art will generally recognize that terms used herein, and particularly in the appended claims (e.g., the body of the appended claims), are generally intended to be terms such as “unrestricted” (e.g., the term “including” should be construed as “including but not limited to,” the term “having” should be construed as “having at least,” the term “includes” should be construed as “including but not limited to,” etc.). It will be further understood by those skilled in the art that where a specific number of introduced claim limitations is intended, such intent will be explicitly recited in the claims, and where no such recitation is present, no such intent exists. For example, by way of illustration, the following appended claims may include the use of introductory phrases such as “at least one” and “one or more” to introduce claim limitations. However, the use of such phrases should not be construed as implying that the introduction of a claim limitation by the indefinite article “a” or “an” limits any particular claim that includes such introduced claim limitation to a claim scope that includes only one such limitation, and the same holds for the use of definite articles used to introduce claim limitations even when the same claim includes introductory phrases such as “one or more” or “at least one” and indefinite articles such as “a” or “an” (e.g., “a” and / or “an” should generally be construed as meaning “at least one” or “one or more”).

[0109] Furthermore, even if a specific number of the recited introduced claims is explicitly recited, one of ordinary skill in the art will recognize that such a recitation should typically be construed to mean at least the recited number (e.g., a mere recitation of "two recitations" would normally be understood to mean at least two recitations or two or more recitations without other qualifying language). Further, in these instances where a convention similar to "at least one of A, B, and C" applies, generally, such a construction is intended in the sense that one of ordinary skill in the art understands the convention (e.g., "a system having at least one of A, B, and C" includes, but is not limited to, a system having A alone, B alone, C alone, a system having A and B together, a system having A and C together, a system having B and C together, and / or a system having A, B, and C together). In instances where a convention similar to "at least one of A, B, or C" is used, generally, such a construction is intended in the sense that one of ordinary skill in the art understands the convention (e.g., "a system having at least one of A, B, or C" includes, but is not limited to, a system having A alone, B alone, C alone, a system having A and B together, a system having A and C together, a system having B and C together, and / or a system having A, B, and C together). It will be further understood by those of skill in the art that in any of the description, claims, or drawings, disjunctive and / or phrases presenting two or more alternative terms will typically be understood to contemplate the possibility of including one of the terms, any of the terms, or both terms, unless the context indicates otherwise. For example, the phrase "A or B" will typically be understood to include the possibility of "A" or "B" or "A and B".

[0110] Regarding the appended claims, one of ordinary skill in the art will understand that the operations recited therein may generally be performed in any order. Also, although the claims are presented in a sequential (plural) order, it should be understood that the various operations may be performed in other orders than those described, or simultaneously. Examples of such alternative orders include, unless the context otherwise indicates, repetition, interleaving, interruption, reordering, incrementing, preparation, supplementation, simultaneity, reversal, or other variant orders. Further, unless the context otherwise indicates, terms such as "responding," "relating," or other past-tense adjectives generally do not intend to exclude such variants.

[0111] It should be noted that any reference to "one aspect," "aspect," "exemplification," "an exemplification," and the like means that the particular features, structures, or characteristics described in connection with the aspect are included in at least one aspect. Thus, the appearances of the phrases "in one aspect," "in an aspect," "in an exemplification," and "in an exemplification" at various places throughout this specification do not necessarily all refer to the same aspect. Further, the particular features, structures, or characteristics may be combined in any suitable manner in one or more aspects.

[0112] As used herein, unless the context clearly indicates otherwise, the singular forms "a," "an," and "the" include plural references. For example, but not limited to, directional terms used herein such as up, down, left, right, below, above, front, back, and variations thereof relate to the orientation of the elements shown in the accompanying drawings and are not limiting with respect to the claims unless otherwise explicitly stated. As used herein, the terms "about" or "approximately" mean an acceptable error for a particular value as determined by one of ordinary skill in the art, which depends in part on how the value is measured or determined. In certain embodiments, the terms "about" or "approximately" mean within 1, 2, 3, or 4 standard deviations. In certain embodiments, the terms "about" or "approximately" mean within 50%, 200%, 105%, 100%, 9%, 8%, 7%, 6%, 5%, 4%, 3%, 2%, 1%, 0.5%, or 0.05% of a given value or range.

[0113] As used herein, unless otherwise indicated, all numerical parameters are to be understood as being preceded by the term "about," which in all cases means that the numerical parameter has the inherent variability of the measurement technique used to determine the value of the parameter. At a minimum, and not as an attempt to limit the application of the doctrine of equivalents to the claims, each numerical parameter herein is to be construed in light of the reported significant digits and by applying ordinary rounding techniques.

[0114] Any numerical range recited herein includes all sub-ranges subsumed within the recited range. For example, a range from 1 to 100 includes all sub-ranges between (and including) the recited minimum value of 1 and the recited maximum value of 100, i.e., all sub-ranges having a minimum value of 1 or more and a maximum value of 100 or less. Also, all ranges recited herein include the endpoints of the recited range. For example, a range from 1 to 100 includes the endpoints 1 and 100. Any maximum numerical limitation recited herein is intended to include all lower numerical limitations subsumed therein, and any minimum numerical limitation recited herein is intended to include all higher numerical limitations subsumed therein. Accordingly, Applicants reserve the right to amend this specification, including the claims, to expressly recite sub-ranges expressly within the ranges expressly recited herein. All such ranges are inherently described herein.

[0115] Any patent application, patent, non-patent publication, or other disclosure material mentioned in this specification and / or listed in any application data sheet is incorporated herein by reference, provided that the incorporated material is not inconsistent with this specification. Accordingly, and to the extent necessary, the disclosure explicitly set forth in this specification prevails over any conflicting material incorporated herein by reference. Although said to be incorporated herein by reference, any material or portion thereof that conflicts with an existing definition, statement, or other disclosure material set forth in this specification is incorporated only to the extent that no conflict arises between the incorporated material and the existing disclosure material.

[0116] The terms "comprise" (and any form of comprise such as "comprises", "comprising", etc.), "have" (and any form of have such as "has", "having", etc.), "include" (and any form of include such as "includes", "including", etc.), and "contain" (and any form of contain such as "contains", "containing", etc.) are open-ended conjunctive verbs. As a result, a system that "comprises", "has", "includes", or "contains" one or more elements possesses those one or more elements, but is not limited to possessing only those one or more elements. Similarly, an element of a system, device, or apparatus that "comprises", "has", "includes", or "contains" one or more features possesses those one or more features, but is not limited to possessing only those one or more features.

[0117] The foregoing detailed description has described various forms of devices and / or processes by use of block diagrams, flowcharts, and / or examples. Where such block diagrams, flowcharts, and / or examples include one or more functions and / or operations, those skilled in the art will understand that each function and / or operation within such block diagrams, flowcharts, and / or examples can be implemented individually and / or collectively by a wide variety of hardware, software, firmware, or substantially any combination thereof. Those skilled in the art will recognize that some aspects of the forms disclosed herein can be implemented as one or more computer programs operating on one or more computers (e.g., as one or more programs operating on one or more computer systems), as one or more programs operating on one or more processors (e.g., as one or more programs operating on one or more microprocessors), as firmware, or substantially any combination thereof, and that all or part of the equivalent integrated circuit can be executed, and that the circuit design, and / or the description of the software code, and / or the firmware are within the scope of the skills of those skilled in the art in light of the present disclosure. Further, those skilled in the art will understand that the mechanisms of the subject matter described herein can be distributed in various forms as one or more program products, and that the exemplary forms of the subject matter described herein apply regardless of the particular type of signal-bearing medium used to actually carry out the distribution.

[0118] The instructions used to program the logic to implement the various disclosed aspects may be stored in memory within the system, such as dynamic random access memory (DRAM), cache, flash memory, or other storage devices. Further, the instructions may be distributed via a network or via other computer-readable media. Accordingly, a machine-readable medium is any mechanism, but not limited to, floppy disks, optical disks, compact disks, read-only memory (CD-ROM), and magneto-optical disks, read-only memory (ROM), random access memory (RAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic or optical cards, flash memory, or tangible machine-readable storage devices used to transmit information over the Internet via electrical, optical, acoustic, or other forms of propagated signals (e.g., carrier waves, infrared signals, digital signals, etc.). Accordingly, a non-transitory computer-readable medium includes any type of tangible machine-readable medium suitable for storing or transmitting electronic instructions or information in a form readable by a machine (e.g., a computer).

[0119] When used in any aspect of this specification, the term "control circuit" can refer to, for example, a wired circuit, a programmable circuit (e.g., a computer processor with one or more individual instruction processing cores, a processing unit, a processor, a microcontroller, a microcontroller unit, a controller, a digital signal processor (DSP), a programmable logic device (PLD), a programmable logic array (PLA), or a field programmable gate array (FPGA), a state machine circuit, firmware that stores instructions executed by a programmable circuit, and any combination thereof). The control circuit can be embodied, collectively or individually, as part of a larger system, such as an integrated circuit (IC), an application specific integrated circuit (ASIC), a system on chip (SoC), a desktop computer, a laptop computer, a tablet computer, a server, a smartphone, etc. Thus, as used herein, "control circuit" includes, but is not limited to, an electrical circuit having at least one discrete electrical circuit, an electrical circuit having at least one integrated circuit, an electrical circuit having at least one application specific integrated circuit, an electrical circuit forming a general purpose computing device configured by a computer program (e.g., a general purpose computer configured by a computer program that at least partially executes a process, and / or a device described herein, or a microprocessor configured by a computer program that at least partially executes a process, and / or a device described herein), an electrical circuit forming a memory device (e.g., in the form of a random access memory), and / or an electrical circuit forming a communication device (e.g., a modem, a communication switch, or an optoelectronic device). One of ordinary skill in the art will recognize that the subject matter described herein can be implemented in analog or digital fashion or some combination thereof.

[0120] When used in any aspect of this specification, the term "logic" may refer to an application, software, firmware, and / or circuitry configured to perform any of the foregoing operations. The software may be embodied as a software package, code, instructions, instruction sets, and / or data recorded in a non-transitory computer-readable storage medium. The firmware may be embodied as code, instructions, or instruction sets, and / or data hard-coded (e.g., non-volatile) in a memory device.

[0121] When used in any aspect of this specification, terms such as "component", "system", "module", etc. may refer to a computer-related entity, hardware, a combination of hardware and software, software, or software in execution.

[0122] When used in any aspect of this specification, "algorithm" refers to a self-consistent order of steps that yields a desired result, and "step" refers to an operation on a physical quantity and / or a logical state that can take the form of an electrical or magnetic signal that need not necessarily be so but can be stored, transferred, combined, compared, and otherwise manipulated. These signals are commonly referred to as bits, values, elements, symbols, characters, terms, numbers, etc. These and similar terms may be associated with appropriate physical quantities and are merely convenient labels applied to these quantities and / or states.

Claims

1. A security information and event management (“SIEM”) provider server configured to enhance network security in place of the tenant network by autonomously ingesting and enriching security information associated with the tenant network, the SIEM provider server comprising a processor and a memory, the memory configured to store a job manager and a workflow engine, the job manager and the workflow engine, when executed by the processor, causing the processor to, periodically monitor the tenant network for configuration changes via a configuration manager of the job manager, detect configuration changes within the tenant network via the configuration manager, update fetch job parameters stored in a job database based on the detected configuration changes within the tenant network via the configuration manager, generate a fetch job for the tenant network based on the updated fetch job parameters stored in the job database via the job manager, store the generated fetch job in a queue, execute the generated fetch job via the job manager such that the job manager obtains security information from a data source associated with the tenant network, enrich the obtained security information via the workflow engine, generate an output configured to enhance the security of the tenant network via the workflow engine, SIEM provider server.

2. The tenant network is one of a plurality of tenant networks, the SIEM provider server of claim 1, configured to simultaneously monitor each tenant network of the plurality of tenant networks for configuration changes.

3. The SIEM provider server is communicatively coupled to a tenant security management system configured to discard output from the SIEM provider server, The SIEM provider server according to claim 1, wherein when the job manager and the workflow engine are executed by the processor, the processor further causes the output to be sent to the tenant security management system for deletion via the workflow engine.

4. The SIEM provider server according to claim 3, wherein discarding the output includes autonomously removing suspicious accounts from the tenant network.

5. The workflow engine comprises a plurality of modules, The SIEM provider server according to claim 1, wherein the plurality of modules include an enrichment module, an Indicator of Compromise (「IOC」) extraction module, a normalization module, a Security Operations Center (「SOC」) automation module, and a post-enrichment automation module.

6. The SIEM provider server according to claim 5, wherein when the workflow engine is executed by the processor, the processor further causes the type of security information associated with the acquired security information to be detected, and enriching the acquired security information includes enriching the acquired security information based on the detected type of security information via the enrichment module.

7. The SIEM provider server according to claim 6, wherein the detected type of security information is a security alert associated with the tenant network.

8. The SIEM provider server according to claim 6, wherein when the workflow engine is executed by the processor, the processor further causes an applicable automation playbook to be detected based on the detected type of security information via the SOC automation module, and enriching the acquired security information via the enrichment module is further based on the detected automation playbook.

9. The SIEM provider server according to claim 5, further comprising converting the acquired security information into a standard format via the normalization module.

10. A method for enhancing network security on behalf of a tenant network by autonomously ingesting and enriching security information associated with the tenant network via a security information and event management (SIEM) provider server, wherein the SIEM provider server comprises a processor and a memory configured to store a job manager and a workflow engine, the method comprising: periodically monitoring the tenant network for configuration changes via a configuration manager of the job manager; detecting configuration changes within the tenant network via the configuration manager; updating fetch job parameters stored in a job database based on the detected configuration changes within the tenant network via the configuration manager; generating a fetch job for the tenant network based on the updated fetch job parameters stored in the job database via the job manager and storing the generated fetch job in a queue; executing the generated fetch job via the job manager such that the job manager obtains security information from a data source associated with the tenant network; enriching the obtained security information via the workflow engine; generating an output configured to enhance the security of the tenant network via the workflow engine. Claim 11 The workflow engine comprises a plurality of modules. The plurality of modules comprise an enrichment module, an indicator of compromise (IOC) extraction module, a normalization module, a security operations center (SOC) automation module, and a post-enrichment automation module. The method according to claim 10. Claim 12 The method according to claim 11, further comprising detecting, via the workflow engine, a type of security information associated with the acquired security information, and enriching the acquired security information includes enriching the acquired security information based on the detected type of security information via the enrichment module.

13. The method according to claim 11, further comprising detecting, via the SOC automation module, an applicable automation playbook based on the detected type of security information, and enriching the acquired security information via the enrichment module is further based on the detected automation playbook.

14. The method according to claim 10, further comprising transmitting, via the workflow engine, the output to a tenant security management system communicably coupled to the SIEM provider server for discard.

15. The method according to claim 14, wherein discarding the output includes autonomously removing a suspicious account from the tenant network.

16. A system comprising: a plurality of tenant networks; and a security information and event management ("SIEM") provider server communicably coupled to the plurality of tenant networks, the SIEM provider server comprising a processor and a memory, the memory being configured to store a job manager and a workflow engine; when the job manager and the workflow engine are executed by the processor, the processor is caused to periodically monitor the plurality of tenant networks for configuration changes; detect a configuration change in a first tenant network of the plurality of tenant networks; update fetch job parameters stored in a job database based on the detected configuration change within the first tenant network; generate a fetch job for the tenant network based on the updated fetch job parameters stored in the job database, and store the generated fetch job in a queue; Execute the generated fetch job so that the job manager obtains security information from a data source associated with the tenant network, Enrich the obtained security information, A system that generates an output configured to enhance the security of the tenant network.

17. The SIEM provider server is communicatively coupled to a tenant security management system configured to discard the output from the SIEM provider server, The system according to claim 16, wherein when the job manager and the workflow engine are executed by the processor, the processor further causes the output to be sent to the tenant security management system for discard via the workflow engine.

18. The system according to claim 17, wherein discarding the output includes autonomously removing suspicious accounts from the tenant network.

19. The workflow engine comprises a plurality of modules, The system according to claim 16, wherein the plurality of modules comprise an enrichment module, an Indicator of Compromise ("IOC") extraction module, a normalization module, a Security Operations Center ("SOC") automation module, and a post-enrichment automation module.

20. The type of the detected security information is a security alert associated with the tenant network, the SIEM provider server according to claim 19.