Systems and methods for risk-based observability of computing platforms

The system addresses network security challenges by converting and enriching raw data for risk-based observability, enhancing threat management efficiency and reducing costs through unified anomaly detection across diverse environments.

JP2025528855APending Publication Date: 2025-09-02BOOZ ALLEN HAMILTON INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025508897
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-08-17
Filing Date
2023-08-17
Publication Date
2025-09-02

AI Technical Summary

Technical Problem

Large organizations face network security challenges due to disparate data sources, siloed visibility, and inconsistent detection capabilities across on-premises and cloud environments, leading to inefficiencies and vulnerabilities in cybersecurity operations.

Method used

A system and method for risk-based observability that receives raw data from multiple computing environments, converts it into a structured format, enriches it with contextual information, performs risk analysis, applies tags, and transmits prioritized data for enhanced threat management across vendor-agnostic platforms.

Benefits of technology

Enhances threat management by reducing manual processing time and costs, providing unified visibility and efficient anomaly detection across diverse data sources, and enabling rapid response to security incidents.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025528855000001_ABST
    Figure 2025528855000001_ABST
Patent Text Reader

Abstract

Exemplary systems and methods provide risk-based observability of a platform. The method includes receiving data from multiple devices from one or more computing environments on a network, the received data being in a raw data format according to the computing environment or platform from which it is received, converting the received data from the raw format into a structured format, enriching the converted data by adding contextual information related to a corresponding device from the multiple devices, performing a risk analysis on the enriched data based on one or more risk detection rules applied to the network, applying one or more tags to the enriched data based on the results of the risk analysis, and performing data analysis on the enriched data to identify devices from aggregated sources. The method includes transmitting the data to one or more destinations on the network based on the applied tags.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to systems and methods for risk-based observability of computing platforms. [Background technology]

[0002] Organizations use comprehensive endpoint security solutions and endpoint protection platforms that include automated detection. Threat hunting, threat detection, incident response, and forensic activities are known cybersecurity processes that identify and evaluate data for malicious or suspicious activity that previously evaded detection. These threat management activities enable organizations to detect and contain advanced threats without prior warning. These solutions work alongside endpoint security solutions and add advanced technologies to uncover anomalies, unusual patterns, and other indicators of attackers within systems and files that should not be present. Leveraging data analytics, endpoint protection platforms ingest and analyze large volumes of unfiltered endpoint data and use signature analytics, behavioral analytics, and artificial intelligence (AI) to rapidly gain visibility into malicious behavior that may not have been detected initially.

[0003] Large organizations may wish to implement endpoint protection systems and threat management activities related to subnetwork data traffic and activity associated with authorized clients. Endpoint protection platforms and threat management applications are vendor-specific, requiring specified commands, processes, and data formats to implement the desired security solution. This may present organizations with a variety of network security challenges, including: (1) choosing between detecting and visualizing suspicious and / or malicious activity while attempting to accommodate budget constraints and an increasing number of data sources; (2) dealing with large teams and various data and infrastructure ownership models, such as federated networks; (3) dealing with large teams and various data ownership models, which can lead to siloed visibility across architectures and associated infrastructure layers across both on-premises and cloud environments; and (4) dealing with disparate activity detection content models and a lack of common data standards, which can lead to a sense of inequity within security operations teams and inconsistent capabilities to deploy detection content and data enrichment. These issues can make cybersecurity operations and related threat management activities complicated, inefficient, and costly, and can lead to network-wide vulnerabilities. Summary of the Invention

[0004] Disclosed is a system for risk-based observability of a platform, the system comprising: a receiver configured to receive, from a plurality of devices associated with one or more computing environments on a network, data having a raw format according to the associated computing environments; a processor configured to convert the raw format of the received data into a structured format, enrich the converted data by adding contextual information associated with corresponding devices of the plurality of devices, perform a risk analysis of the enriched data based on risk content applied to the network, apply one or more tags to the enriched data based on results of the risk analysis, and perform data analysis on the enriched data to render composite and / or prioritized data for identifying one or more of the plurality of devices from aggregated sources; and a transmitter configured to transmit the rendered composite and / or prioritized data to one or more destinations on the network based on the one or more applied tags.

[0005] Disclosed is a method for risk-based observability of a platform, the method including: a receiver in a computing device receiving data from a plurality of devices associated with one or more computing environments on a network, the data having a raw format according to the associated computing environments; a processor in the computing device converting the raw format of the received data into a structured format; the processor in the computing device enriching the converted data by adding contextual information associated with a source of each data; the processor in the computing device performing a risk analysis on the enriched data based on risk content applied to the network; the processor in the computing device applying one or more tags to the enriched data based on results of the risk analysis; the processor in the computing device performing data analysis on the enriched data to render composite and / or prioritized data for identifying one or more of the plurality of devices from an aggregated source; and a transmitter in the computing device transmitting the rendered composite and / or prioritized data to one or more destinations on the network based on the one or more applied tags.

[0006] 1. A computer-readable medium storing program code for executing a method for risk-based observability of a platform, the program code, when placed in communicative contact with a computing device, causing the computing device to perform operations including: a receiver of the computing device receiving data from a plurality of devices associated with one or more computing environments on a network, the data having a raw format according to the associated computing environments; a processor of the computing device converting the raw format of the received data into a structured format; the processor of the computing device enriching the converted data by adding contextual information associated with a source of each data; the processor of the computing device performing a risk analysis on the enriched data based on one or more risk detection rules applied to the network; the processor of the computing device applying one or more tags to the enriched data using results of the analysis; the processor of the computing device performing data analysis on the enriched data to render composite and / or prioritized data for identifying one or more of the plurality of devices from the aggregated source; and a transmitter of the computing device transmitting the rendered composite and / or prioritized data to one or more destinations on the network based on the one or more applied tags.

[0007] The illustrative embodiments are best understood from the following detailed description when read in conjunction with the accompanying drawings, in which: [Brief explanation of the drawings]

[0008] [Figure 1] FIG. 2 illustrates stages of data flow according to an exemplary embodiment of the present disclosure. [Figure 2A] FIG. 1 illustrates a computing device according to an exemplary embodiment of the present disclosure. [Figure 2B]FIG. 1 illustrates an exemplary computing environment in accordance with an exemplary embodiment of the present disclosure. [Figure 2C] FIG. 2 is a block diagram of a hardware configuration of a computing device 250 according to an exemplary embodiment of the present disclosure. [Figure 3] FIG. 1 illustrates a method for risk-based observability of a platform according to an exemplary embodiment of the present disclosure. [Figure 4] FIG. 1 illustrates a risk-based observability use case according to an exemplary embodiment of the present disclosure. [Figure 5] FIG. 1 illustrates a use case of a Federated Data Streaming model, according to an exemplary embodiment of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0009] Further areas of applicability of the present disclosure will become apparent from the detailed description provided hereinafter, with it being understood that the detailed description of exemplary embodiments is for purposes of illustration only, and is therefore not intended to necessarily limit the scope of the present disclosure.

[0010] An exemplary embodiment of the present disclosure relates to a system and method for risk-based observability of a platform. A network can include multiple edge devices that can manage and correlate data at the edge. The system collects data about all devices on the network and determines the device's importance and / or risk to the network. As the data enters the network, it can be analyzed in real time at the device level. The data is enriched and tagged at the edge, and anomalous data is isolated, filtered, and compressed before being sent elsewhere in the network for further evaluation. The system can receive data in various formats, structure the data in an open format that aligns with organizational priorities and risks, help identify the root cause of threats and / or incidents, categorize related alerts that can be addressed with a single action, and trace them to their source. As a result of this data analysis, the system can examine the entire network and / or application stack to understand the impact of the data and any signature or behavioral anomalies on the organization and prioritize these anomalies in order of response. The system acts as a single agnostic detection system that can search for threat patterns and anomalies in data across multiple data formats. Exemplary embodiments of the present disclosure support a vendor-agnostic approach for Hunt, Incident Response, and Forensics activities by integrating and performing actions required in a multi-vendor environment under one platform.

[0011] FIG. 1 illustrates the stages of data flow according to an exemplary embodiment of the present disclosure.

[0012] The data flow 100 of FIG. 1 can occur within one or more computing devices on a network. The computing device can be a local computing device configured to operate as desired within a distributed computing environment, including a local endpoint, an on-premises data center, cloud computing, an air-gapped computing deployment, or other computing deployment. According to another exemplary embodiment, the computing device can be a local device configured to operate within an enterprise network environment. In either implementation, the computing device can include any number of applications and / or tools that generate data and / or capture data from endpoints within a network, cloud, or edge computing device. According to exemplary embodiments, the endpoint device can include a sensor, a smart device, a laptop computing device, a desktop computing device, a tablet, or any other suitable endpoint device or network location, as desired.

[0013] As shown in data flow 100 of FIG. 1 , data is received or ingested at a computing device from one or more other computing devices on a network (Step 1). The network may include computing devices deployed and / or configured to operate as a virtual data center, such as a private data center, a managed data center, and / or a cloud. According to an exemplary embodiment, the data may be received as streaming data or batch data over the network. The platform provides several improvements and value over known systems by its ability to receive streaming data that can be received in a raw format according to the computing environment of a corresponding one of the devices. For example, the raw data format may include proprietary data structures associated with a vendor-specific application or platform (e.g., Amazon Web Services, Google Cloud Platform). The computing device may receive the data through any suitable receiving device, which may be a combination of hardware and software components, as described in further detail. The received data may be sourced from at least one of signature-based alerts categorized by application, device, and user, host-based logs, network-based logs, cyber compliance audits, and network user activity. According to an exemplary embodiment, meta tags can be applied to the data to identify its source inline (or while the data is being streamed and processed). Meta tags can also be used to specify the data type of the received data. The computing device can include a processor that normalizes the received data by converting the raw format of the received data into a structured or standardized format (e.g., a common schema) (stage 2).For example, the raw format of the received data may be converted or mapped to the data structure of the enterprise computer system that received the data. The conversion may include extracting specified fields (e.g., date, hostname, message, IP address, etc.) from the data received from the multiple computer devices according to a common schema. The processor may enrich the normalized data by adding contextual information related to a corresponding one of the multiple devices (Step 3). According to an exemplary embodiment, the processor may insert supplemental data and data derived from other sources. For example, the inserted data may include one or more objects related to the enterprise computer system. Additionally, the enriching data may include geographic lookup host or IP addresses, bad IP addresses, port to server service server process mapping, common vulnerabilities and exposures (CVE) standards including those in the national vulnerability database (NVD), industry standard attack enumeration and behavior models (e.g., MITRE ATT&K, MITRE D3FEND), or any other suitable location-based information, as desired. In another exemplary embodiment, the enriching data may include data correlation, data counters, data aggregation, or other suitable data operations (e.g., data analysis) performed by the computing device or network, as desired. In yet another exemplary embodiment, the enriching data may include contextual data related to a process or computing event. The contextual data may be stored in a cache memory or a database.The processor may also generate traces for data observability during the hardening operations. The trace data may be used to measure or evaluate performance or behavior between services and / or components in the network.

[0014] After the data is enriched, the processor may perform a risk analysis based on one or more risk content, which may include risk detection rules or models, such as threat content or analysis, applied to the network. The processor analyzes the data to identify normal data traffic and data traffic that is anomalous or may contain anomalies. Based on the results of the risk analysis, one or more tags are applied to the enriched data (step 4). For example, these tags serve as indicators to identify factors necessary for data routing and further analysis. The processor applies data analytics to render synthetic data and / or prioritized data to identify and persist device / asset inventory from aggregated sources. According to exemplary embodiments, the prioritized data may include asset or device inventory data, priority score data, or other suitable data, as desired. The processor also filters the normal data so that only anomalous data remains. The anomalous data is compressed and stored in the memory of the computing device. Based on the one or more applied tags, a transmitter on the computing device transmits the enriched data to one or more destinations on the network (step 5). According to an example embodiment, the data can be routed to an organizational team or group that can address or resolve threats and / or incidents associated with the anomalous data. These actions provide an enhanced threat management response process that can reduce the manual time and cost security teams spend processing data.

[0015] FIG. 2A illustrates a computing device according to an exemplary embodiment of the present disclosure.

[0016] As shown in Figure 2A, an example system 200 relevant to the present disclosure may include a distributed computing environment having multiple edge devices 202. Each of the multiple edge devices may be connected to an enterprise network 204 having at least one server 206. Each of the multiple edge devices 202 and server 206 may be configured to perform one or more of the operations described in Figure 1. According to an example embodiment, each edge device 202 may be configured to route tagged anomaly data to the server 206 for further analysis, evaluation, and / or resolution of the threat or incident.

[0017] FIG. 2B illustrates an exemplary computing environment 225 according to an exemplary embodiment of the present disclosure.

[0018] As shown in FIG. 2B , a computing environment 225 according to an exemplary embodiment of the present disclosure can include multiple data sources 227 that provide streaming data to be evaluated. As previously described, the multiple data sources 227 can include one or more endpoint computing devices, cloud computing devices, or edge computing devices 202a-202n. According to an exemplary embodiment, the endpoint devices can include sensors, smart devices, desktop computers, tablet computers, laptop computers, or any other suitable endpoint device or network location, as desired. The cloud computing devices can include one or more computing devices of content providers that provide data content, which can include data related to video and audio files, one or more computing devices forming a database or data lake, or any other suitable computing device or combination of computing devices, as desired. The streaming data can be received at one or more of the computing devices 202a-202n or server 206 to perform operations for risk-based observability of the platform. The computing devices 202a-202n or server 206 can generate alerts, which can include observability information related to anomalous data identified from the streaming data. The alerts may be routed to one or more teams or groups within an organization or subsystems of an enterprise network or computer device to resolve and / or address the cyber threat or incident.For example, the subsystems may include a Security Information and Event Management (SIEM) system 229, a data lake 231, a Security Orchestration, Automation and Response (SOAR) system 233, or any suitable system (e.g., case management, ticket management, or communication or collaboration tools), network locations, and organizational teams or groups, as desired.

[0019] 2C is a block diagram of a hardware configuration of a computing device 250 according to an exemplary embodiment of the present disclosure. As shown in FIG. 2C, computing device 250 includes memory 252, a receiver 254, a processor 256, and a transmitter 258, as described above with respect to FIG. 1. Computing device 250 further includes one or more input devices 260, a network interface 262, an internal communications infrastructure 264, and an input / output (I / O) interface 266.

[0020] According to exemplary embodiments of the present disclosure, one or more input devices 260 may be configured to receive commands and / or enable a user to interact with the computing device (e.g., input data and / or commands). The one or more input devices 260 may include one or more of a physical or virtual keyboard, a touchpad, a mouse or stylus, a microphone, a camera, or any other suitable input device, as desired. The receiver 254 may include any combination of hardware and software components configured to receive streaming data from one or more other computing devices connected to the network and / or at the edge, a data lake, a cloud, or any other suitable component on the network, as desired. According to exemplary embodiments, the receiver 254 may include hardware components such as an antenna, a network interface (e.g., an Ethernet card), a communications port, a PCMCIA slot and card, or any other suitable component or device, as desired. The receiver 254 may be connected to other devices via a wired or wireless network, or via a wired or wireless direct link or peer-to-peer connection without an intermediate device or access point. The hardware and software components of receiver 254 may be configured to receive data (e.g., streaming data) according to one or more communication protocols and data formats. Receiver 254 may be configured to communicate over a network such as a local area network (LAN), a wide area network (WAN), a wireless network (e.g., Wi-Fi), a cellular communication network, a satellite network, the Internet, fiber optic cable, coaxial cable, infrared, radio frequency (RF), another suitable communication medium, or an enterprise network, which may include any combination thereof, as desired.During a receiving operation, the receiver 254 may be configured to identify portions of the received data via headers and parse the data signals and / or data packets into smaller frames (e.g., bytes, words) or segments for further processing in the processor 256. It should be understood that the receiver 254 may be configured as a stand-alone device or may have circuitry and components integrated with the network interface 262.

[0021] Processor 256 can be a special-purpose or general-purpose processing device encoded with program code or software for performing the example functions and / or features disclosed herein. According to an example embodiment of the present disclosure, processor 256 can include a central processing unit (CPU). Processor 256 can be connected to a communication infrastructure 264, including a bus, message queue, or network, multi-core message-passing scheme, for communication with other components of computing device 250, such as memory 252, one or more input devices 260, network interface 262, and I / O interface 266. Processor 256 can include one or more processing devices, such as a microprocessor, microcomputer, programmable logic unit, or any other suitable hardware processing device, as desired.

[0022] I / O interface 266 can be configured to receive signals from processing device 256 and generate suitable output for peripheral devices via a direct wired or wireless link. I / O interface 266 can include any combination of hardware and software, as desired, such as a processor, circuit card, or any other suitable hardware device encoded with program code, software, and / or firmware for communicating with peripheral devices such as a display device, a printer, an audio output device, or other suitable electronic device or output type. I / O interface 266 can also be configured to connect to and / or communicate with other hardware components, or to provide functionality of various types of integrated and / or peripheral input devices described herein in combination with other hardware components.

[0023] The transmitter 258 may be configured to receive data from the processor 256 and / or memory 252 and assemble the data into data signals and / or data packets according to the specified communication protocol and data format of the peripheral or remote device to which the data is to be transmitted. The transmitter 258 may include any one or more hardware and software components for generating data signals and communicating the data signals to the peripheral or remote device via the internal communication infrastructure 264 and / or a direct wired or wireless link. The transmitter 258 may be configured to transmit information according to one or more communication protocols and data formats, such as those described in connection with the receiver 254. According to an exemplary embodiment, the receiver 254 and the transmitter 258 may be integrated into a single device and / or housing, or may be configured as separate, standalone devices. According to another exemplary embodiment, the receiver 254 and the transmitter 258 may be configured as shared circuitry and components and further integrated with the network interface 262.

[0024] According to the exemplary embodiments described herein, the combination of memory 252 and processor 256 can store and / or execute computer program code for performing the specific functions described herein. It should be understood that the program code can be stored in a non-transitory computer-readable medium, such as a memory device of computing device 250, which can be a memory semiconductor (e.g., DRAM, etc.) or other tangible, non-transitory means for providing software to computing device 250. For example, the program code can be deployed (e.g., streaming and / or downloading) remotely from a computing device located on a local or wide area network via any known or suitable service or platform, and / or in a cloud computing deployment or environment using source control (e.g., git, gitops, etc.) and a container orchestration process. Computer programs (e.g., computer control logic) or software can be stored in memory 252 resident on / within computing device 250. Such computer programs or software, when executed, can enable computing device 250 to perform the methods and exemplary embodiments described herein. Such a computer program may therefore represent a controller of computing device 250. If the present disclosure is implemented using software, the software may be stored on a computer program product or non-transitory computer-readable medium and loaded into computing device 250 using any one or combination of a removable storage drive, an interface for internal or external communication, and, if necessary, a hard disk drive.

[0025] In the context of exemplary embodiments of the present disclosure, a processor may include one or more modules or engines configured to perform the functions of the exemplary embodiments described herein. Each of the modules or engines may be implemented using hardware, or in some cases, may utilize software corresponding to program code and / or programs stored in memory. In such cases, the respective processor (e.g., a compilation module or engine) may interpret or compile the program code before execution. For example, the program code may be source code written in a programming language that is translated into a low-level language, such as assembly language or machine code, for execution by one or more processors and / or any additional hardware components. The compilation process may include the use of lexical analysis, preprocessing, syntactic analysis, semantic analysis, syntax-directed translation, code generation, code optimization, and any other techniques suitable for translating program code into a low-level language suitable for controlling the components of the computing device 250 and / or enterprise network 204 to perform the functions disclosed herein. It will be apparent to those skilled in the relevant art that the result of such a process is that computing device 250 and / or components of enterprise network 204 become specially configured computing devices that are uniquely programmed to perform the functions of the exemplary embodiments described herein.

[0026] FIG. 3 illustrates a method 300 for risk-based observability of a platform, according to an exemplary embodiment of the present disclosure. As illustrated in FIG. 3, operations performed by edge or distributed computing devices 202a-202n and / or server 206 include a receiver in the edge device 202a-202n and / or server 206 receiving data from a plurality of devices on a network, the data having a raw format according to a configuration of a corresponding device in the network or the plurality of devices on the federated network (step 302). A processor in the edge device 202a-202n and / or server 206 converts the raw format of the received data into a structured format (step 304). The processor in the edge device 202a-202n and / or server 206 then enriches the converted data by adding contextual information related to the source of the respective data (step 306). The method further includes a processor in the edge device 202a-202n and / or server 206 performing a risk analysis on the enriched data based on the risk content applied to the network (step 308) and applying one or more tags to the enriched data based on the results of the risk analysis (step 310). The processor in the edge device 202a-202n and / or server 206 performs data analysis on the enriched data to render composite and / or prioritized data capable of identifying device / asset inventory from aggregated sources (step 312). A transmitter in the edge device 202a-202n and / or server 206 transmits the rendered composite and / or prioritized data to one or more destinations on the network 204 based on the one or more applied tags (step 314).

[0027] FIG. 4 illustrates a first use case 400 of risk-based observability in accordance with an exemplary embodiment of the present disclosure.

[0028] As shown in FIG. 4, the computing devices 202a-202n and / or the server 206 ingest (e.g., receive) raw, unstructured streaming data from a data source (step 402). The streaming data includes log entries indicating failed login attempts from a Russian IP address. The data is raw and unstructured. The computing devices 202a-202n and / or the server 206 structure the streaming data and convert it into a common schema (step 404). For example, fields of the streaming data are extracted and mapped to a common schema so that common processing can be applied to the data regardless of its source. The normalized data is then enriched data (step 406) to provide context and meaning to the extracted data fields. In this example, geography identifiers are added to specify that the data is from Moscow, Russia. The enriched data is then tagged to identify security risks and incidents based on rules customizable for each deployment (step 408). Tags can be identified within the rules and can follow a schema specified for each organization or computing environment. According to an exemplary embodiment, a single rule can apply multiple tags. The computing devices 202a-202n perform data analytics on the enriched data to render composite and / or prioritized data capable of identifying device / asset inventory from aggregated sources (step 410). The computing devices 202a-202n and / or the server 206 then route the data to a destination for assessment and action appropriate to the identified risks (step 412). The routing operations are performed based on contextual security information and rules that determine whether the data should be routed to a specified network destination for further system or human processing. As shown in step 412, both the contextual security information and the rules are satisfied, thus transmitting the data record to the local SIEM system and the enterprise SIEM system for further processing.According to an exemplary embodiment, tags and routing criteria can be configured using a rule tree language that determines how records are tagged based on their content and context.

[0029] FIG. 5 illustrates a use case 500 of a federated data streaming model, according to an exemplary embodiment of the present disclosure.

[0030] As shown in FIG. 5, the system 500 can include multiple computing environments 502a-502c. Each computing environment 502a-502c can include a combination of software and hardware components configured to perform operations for risk-based observability 100 according to FIG. 1. According to an exemplary embodiment of the present disclosure, the computing environments 502a-502b can be on-premise, cloud, or hybrid environments. When performing risk-based observability operations 100, the computing environments 502a-502c can be configured to tag and route data to different destinations to implement a user or platform security "playbook." The computing environment 502c can include a server 206 in the enterprise network that receives previously processed data records (including tags, enrichment, and normalization) from the computing environments 502a and 502b. After receiving the data, the server 206 can perform further analysis 231, route analysis results or decisions to a SIEM system or an incident response team 233, or execute customer-specific business logic 229.

[0031] Those skilled in the art will recognize that the present invention may be embodied in other specific forms without departing from its spirit or essential characteristics. The presently disclosed embodiments are therefore to be considered in all respects as illustrative and not restrictive. The scope of the present disclosure is indicated by the appended claims, rather than the foregoing description, and all changes that come within the meaning, range, and equivalency of the claims are intended to be embraced within their scope. [Explanation of symbols]

[0032] 100 Data Flow

Claims

1. 1. A system for risk-based observability of a platform, comprising: a receiver configured to receive data from a plurality of devices associated with one or more computing environments on a network, the data having a raw format according to the associated computing environments; converting the raw format of the received data into a structured format; Enhancing the transformed data by adding contextual information related to a corresponding device of the plurality of devices; performing a risk analysis of the enriched data based on risk content applied to the network; applying one or more tags to the enriched data based on the results of the risk analysis; performing data analytics on the enriched data to render composite and / or prioritized data for identifying one or more of the plurality of devices from aggregated sources; a processor configured to: a transmitter configured to transmit the rendered composite and / or prioritized data to one or more destinations on the network based on the one or more applied tags; A system comprising:

2. The received data is Signature-based alerts categorized by application, device and user, host-based logging, Network-based logs, Cyber ​​compliance audits, and network user activity, 10. The system of claim 1, wherein the power supply is supplied from at least one of:

3. the structured format includes a common schema; The system of claim 1 .

4. the processor is configured to extract designated fields from the data received from the plurality of devices according to the common schema to convert the raw data format of the received data. The system of claim 3.

5. the context information includes at least geographic IP information; The system of claim 1 .

6. the risk analysis identifying security risks and incidents according to the risk content of the network; The system of claim 1 .

7. the processor is configured to apply the one or more tags to the enriched data according to a common schema of the structured data format. The system of claim 6.

8. The processor: determining whether the rendered composite and / or prioritized data with the one or more applied tags identifies a risk requiring further evaluation; determining whether a particular response action is mapped to the identified risk; The system of claim 1 configured to:

9. the rendered composite and / or prioritized data is transmitted to the one or more destinations when further evaluation is required and the specific response action is identified; The system of claim 8.

10. the network is an enterprise network having a plurality of distributed computing devices; The system of claim 1 .

11. 1. A method for risk-based observability of a platform, comprising: receiving, at a receiver in the computing device, data from a plurality of devices associated with one or more computing environments over a network, the data having a raw format according to the associated computing environments; a processor of the computing device converting the raw format of the received data into a structured format; the processor of the computing device enhancing the transformed data by adding contextual information related to the source of each of the data; the processor of the computing device performing a risk analysis on the enriched data based on a risk content applied to the network; applying, by the processor of the computing device, one or more tags to the enriched data based on the results of the risk analysis; the processor of the computing device performing data analytics on the enriched data to render composite and / or prioritized data for identifying one or more of the plurality of devices from an aggregated source; a transmitter of the computing device transmitting the rendered composite and / or prioritized data to one or more destinations on the network based on the one or more applied tags; A method comprising:

12. The received data is Signature-based alerts categorized by application, device and user, host-based logging, Network-based logs, Cyber ​​compliance audits, and network user activity, The method of claim 11 , comprising at least one of:

13. the structured format includes a common schema; The method of claim 11.

14. converting the raw format of the received data includes the processor of the computing device extracting designated fields from the data received from the plurality of devices according to the common schema. The method of claim 13.

15. the context information includes at least geographic IP information; The method of claim 11.

16. performing the risk analysis includes the processor of the computing device identifying security risks and incidents according to the risk content of the network; The method of claim 11.

17. the processor of the computing device applying the one or more tags to the enriched data according to a common schema of the structured data format.

17. The method of claim 16.

18. the processor of the computing device: whether the rendered composite and / or prioritized data with the one or more applied tags identifies a risk requiring further evaluation; and Whether specific response actions are mapped to the identified risks; and The method of claim 11 , comprising determining:

19. and when the identified risk requires further assessment and a specific response is mapped to the identified risk, the transmitter of the computing device transmits the enriched data to the one or more destinations on the network.

20. The method of claim 18.

20. the network is an enterprise network having a plurality of distributed computing devices; The method of claim 1.

21. 1. A computer-readable medium storing program code for executing a method for risk-based observability of a platform, the program code, when placed in communicative contact with a computing device, comprising: receiving, at a receiver in the computing device, data from a plurality of devices associated with one or more computing environments over a network, the data having a raw format according to the associated computing environments; a processor of the computing device converting the raw format of the received data into a structured format; the processor of the computing device enhancing the transformed data by adding contextual information related to the source of each of the data; the processor of the computing device performing a risk analysis on the enriched data based on one or more risk detection rules applied to the network; applying, by the processor of the computing device, one or more tags to the enriched data using results of the analysis; and the processor of the computing device performing data analytics on the enriched data to render composite and / or prioritized data for identifying one or more of the plurality of devices from an aggregated source; a transmitter of the computing device transmitting the rendered composite and / or prioritized data to one or more destinations on the network based on the one or more applied tags; 22. A computer-readable medium for causing the computing device to perform operations including: