Devices, systems, and methods for enhancing security information and event management updates for multiple tenants based on the need for correlation and synergy implementation.
The SIEM management application addresses inefficiencies in managing multiple tenants by providing automated, scalable, and adaptable updates, enhancing network security and reducing costs for MSSPs.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- BLUEVOYANT LLC
- Filing Date
- 2022-06-03
- Publication Date
- 2026-04-23
AI Technical Summary
Existing SIEM tools are customized to individual organizations, leading to inefficiencies, high costs, and vulnerabilities due to manual management across multiple tenants, lacking automation and scalability, and failing to leverage synergies between clients.
A SIEM management application that provides a visually integrated environment for managing client deployments, enabling one-click updates and real-time monitoring across multiple tenants, utilizing automation and correlation to streamline updates and reduce manual intervention.
Enhances network security by allowing MSSPs to efficiently manage and update SIEM applications across hundreds of tenants with minimal staff, reducing costs and vulnerabilities through automated, scalable, and adaptable solutions.
Smart Images

Figure 0007850750000001 
Figure 0007850750000002 
Figure 0007850750000003
Abstract
Description
[Technical Field]
[0001] Cross-references to related applications This application claims priority to U.S. Provisional Patent Application No. 63 / 196,458, filed on 3 June 2021 under 35 U.S.C. § 119(e), entitled “DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS,” the entire disclosure of which is incorporated herein by reference.
[0002] This disclosure generally relates to network security, and more specifically to improved devices, systems, and methods for issuing security information and event management (SIEM) client updates. [Overview of the Initiative]
[0003] The following summary is provided to facilitate understanding of some of the innovative features specific to the embodiments disclosed herein and is not intended to be a complete description. A complete understanding of the various embodiments can be obtained by taking the entire specification, claims, and abstract.
[0004] In various embodiments, methods are disclosed for enhancing network security across multiple tenants configured to host multiple client applications. The methods include providing a SIEM management application hosted by a SIEM provider server communicably coupled to multiple tenants; receiving SIEM status from the multiple tenants; visualizing the SIEM status; filtering the SIEM status based on user input received via a graphical user interface; visualizing the filtered SIEM status; selecting at least one client application from multiple client applications hosted by at least one of the multiple tenants via a graphical user interface and updating it based on the filtered SIEM status; generating updates and update alerts for the client application based on the selection; sending update alerts to at least one tenant; and updating at least one client application based on the update alerts.
[0005] In various embodiments, systems for enhancing network security are disclosed. The system may include a SIEM provider server comprising a plurality of tenants configured to host a plurality of clients, and a Security Information and Event Management (SIEM) provider server communicatively coupled to the plurality of tenants, wherein the SIEM provider server includes a processor and memory, and the memory is configured to store a SIEM management application that, when executed by the processor, causes the processor to receive SIEM status from the plurality of tenants, visualize the SIEM status via a graphical user interface of a SIEM management application illustrated on a display communicatively coupled to the SIEM provider server, at least partially filters the SIEM status based on user input received via the graphical user interface, visualizes the filtered SIEM status via the graphical user interface, determines at least one client among a plurality of clients hosted by at least one of the plurality of tenants, updates at least partially based on the filtered SIEM status, generates an update alert, at least partially based on the determination, sends the update alert to at least one tenant, and causes at least one client application to update at least partially based on the update alert, thereby enhancing network security for at least one tenant when at least one client is updated.
[0006] These and other objects, functions, and characteristics and operating methods of the present invention, the functions of related structural elements, the combination of parts, and the economics of manufacture will become more apparent when considering the appended claims with reference to the following description and the accompanying drawings, all of which form part of this specification, and similar reference numerals indicate corresponding parts in various figures. However, it should be expressly understood that the drawings are for illustrative and explanatory purposes only and are not intended to define the limitations of the present invention. [Brief explanation of the drawing]
[0007] Various features of the embodiments described herein are described in detail in the appended claims. However, various embodiments relating to both the organization and the method of operation, as well as their advantages, can be understood in accordance with the following description and accompanying drawings.
[0008] [Figure 1] Figure 1 shows a diagram of a system configured to enhance security information and event management (SIEM) updates, according to at least one non-limiting aspect of this disclosure.
[0009] [Figure 2] Figure 2 shows a diagram of the system of Figure 1, including a SIEM management application, according to at least one non-limiting aspect of this disclosure. [Figure 13] Continuation of Figure 2.
[0010] [Figure 3] Figure 3 shows a graphical user interface for the SIEM management application of Figure 2, according to at least one non-limiting aspect of this disclosure.
[0011] [Figure 4] Figure 4 shows another graphical user interface for the SIEM management application of Figure 2, according to at least one non-limiting aspect of this disclosure. [Figure 14] Same as above.
[0012] [Figure 5] Figure 5 shows another graphical user interface for the SIEM management application of Figure 2, according to at least one non-limiting aspect of this disclosure.
[0013] [Figure 6]FIG. 6 shows another graphical user interface of the SIEM management application of FIG. 2, according to at least one non-limiting aspect of the present disclosure.
[0014] [Figure 7] FIG. 7 shows another graphical user interface of the SIEM management application of FIG. 2, according to at least one non-limiting aspect of the present disclosure. [Figure 15] Continuation of FIG. 7.
[0015] [Figure 8] FIG. 8 shows another graphical user interface of the SIEM management application of FIG. 2, according to at least one non-limiting aspect of the present disclosure. [Figure 16] Continuation of FIG. 8. [Figure 17] Continuation of FIG. 8. [Figure 18] Continuation of FIG. 8.
[0016] [Figure 9] FIG. 9 shows another graphical user interface of the SIEM management application of FIG. 2, according to at least one non-limiting aspect of the present disclosure.
[0017] [Figure 10] FIG. 10 shows another graphical user interface of the SIEM management application of FIG. 2, according to at least one non-limiting aspect of the present disclosure.
[0018] [Figure 11] FIG. 11 shows a system of FIG. 1 and a method of using the SIEM management application of FIG. 2, according to at least one non-limiting aspect of the present disclosure.
[0019] [Figure 12] FIG. 12 shows another graphical user interface of the SIEM management application of FIG. 2, according to at least one non-limiting aspect of the present disclosure.
[0020] Corresponding reference numerals indicate corresponding parts across several figures. The embodiments described herein illustrate various aspects of the invention in one form, and such embodiments should not be construed as limiting the scope of the invention in any way. [Modes for carrying out the invention]
[0021] The applicant of this application owns the following U.S. provisional patent applications, each of which disclosures are incorporated herein by reference in their entirety. - U.S. Provisional Patent Application No. 63 / 196,991, filed on June 4, 2021, entitled "DEVICES, SYSTEMS, AND METHODS FOR STANDARDIZING & STREAMLINING THE DEPLOYMENT OF SECURITY INFORMATION & EVENT MANAGEMENT ARTIFACTS FOR MULTIPLE TENANTS," - U.S. Provisional Patent Application No. 63 / 294,570, filed on December 29, 2021, entitled "DEVICES, SYSTEMS, AND METHODS FOR PROVISIONING AND UPDATING SECURITY INFORMATION & EVENT MANAGEMENT ARTIFACTS FOR MULTIPLE TENANTS" - U.S. Provisional Patent Application No. 63 / 295,150, filed on December 30, 2021, entitled "DEVICES, SYSTEMS, AND METHODS FOR STREAMLINING AND STANDARDIZING THE INGEST OF SECURITY DATA ACROSS MULTIPLE TENANTS", - U.S. Provisional Patent Application No. 63 / 302,828, filed on January 25, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR REMOTELY MANAGING ANOTHER ORGANIZATION'S SECURITY ORCHESTRATION, AUTOMATION, AND RESPONSE," -Filed on February 24, 2022, U.S. Provisional Patent Application No. 63 / 313,422, entitled "DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTION BASED ON DOMAIN REDIRECTS," - U.S. Provisional Patent Application No. 63 / 341,264, filed on May 12, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR SUMMARIZING ANALYTIC OBSERVATIONS", - U.S. Provisional Patent Application No. 63 / 344,305, filed on May 20, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR INGESTING & ENRICHING SECURITY INFORMATION TO AUTONOMOUSLY SECURE A PLURALITY OF TENANT NETWORKS", and - U.S. Provisional Patent Application No. 63 / 345,679, filed on May 25, 2022, for Devices, Systems, and Methods for Identifying Cyber Assets and Generating Cyber Risk Mitigation Actions Based on a Democratic Matching Algorithm.
[0022] Numerous specific details are provided to provide a complete understanding of the overall structure, function, manufacture, and use of the embodiments described herein and illustrated in the accompanying drawings. Well-known functions, components, and elements are not described in detail so as not to obscure the embodiments described herein. The reader will understand that the embodiments described and illustrated herein are non-limiting embodiments. Accordingly, it will be understood that the details of the specific structures and functions disclosed herein may be representative and illustrative. Modifications and changes may be made without departing from the claims. Furthermore, it should be understood that such terms, such as “forward,” “backward,” “left,” “right,” “upward,” “downward,” and similar terms, are terms of convenience and should not be interpreted as limiting terms.
[0023] In the following description, similar reference numerals indicate similar or corresponding parts across several drawings. Furthermore, it should be understood that such terms, such as “front,” “rear,” “left,” “right,” “up,” and “down,” are terms of convenience and should not be interpreted as restrictive terms.
[0024] Before describing in detail the various aspects and methods of the systems disclosed herein, it should be noted that the exemplary aspects are not limited to application or use to the details disclosed in the accompanying drawings and description. Naturally, exemplary aspects may be implemented or incorporated in other aspects, variations, and modifications, and may be practiced or implemented in a variety of ways. Furthermore, unless otherwise suggested, the terms and expressions used herein have been selected for the convenience of the reader to illustrate exemplary aspects and are not intended to limit them. For example, any reference to a particular manufacturer, software suite, application, or development platform disclosed herein should be understood as merely intended to illustrate some of the many aspects of this disclosure. This includes any reference to trademarks. Thus, it should be understood that the devices, systems, and methods disclosed herein can be implemented to enhance any software update according to any intended use and / or user preference.
[0025] As used herein, the term “server” means, or may include, one or more computing devices that are operated or facilitated by communication and processing for multiple parties in a network environment such as the Internet or any public or private network. As used herein, references to “server” or “processor” may refer to previously listed servers and / or processors that perform a previous step or function, different servers and / or processors, and / or combinations of servers and / or combinations of processors.
[0026] As used herein, the term “constant” may refer to one or more SIEM functions that do not change during the issuance of an alert. For example, constants may include, in particular, Azure Sentinel Log Analytics functions. According to some non-limiting aspects, constants may be configured specifically according to the preferences and / or requirements of individual clients. For example, as described herein, alert rules may be the same for all client deployments. However, the use of the devices, systems, and methods disclosed herein may use client-specific constants to “fine-tune” how alerts are managed for each particular client. In other words, each constant may include a whitelist of alert rules that manage those constants separately (e.g., skip them), such as specific protocols or accounts.
[0027] As used herein, the term “platform” includes an ecosystem of software and / or physical resources necessary to enable the technical benefits provided by the software. For example, a platform may include either a standalone software product or a software product configured to integrate with other software or physical resources within the ecosystem necessary to provide its technical benefits. According to some non-limiting aspects, the technical benefits provided by the software are provided to the physical resources of the ecosystem, or to other software employed by physical resources within the ecosystem (e.g., APIs, services, etc.). According to other non-limiting aspects, a platform may include a framework of several software applications intended and designed to work together.
[0028] As used herein, the term “Network” includes the entire enterprise information technology (IT) system deployed by a tenant. For example, a network may include a group of two or more nodes (e.g., devices) connected by any physical and / or wireless connection and configured to communicate and share information with one or more other nodes. However, the term Network is not limited to any particular node or any particular means of connecting those nodes. A network may include any combination of devices (e.g., servers, desktop computers, laptop computers, personal digital assistants, mobile phones, wearables, smart home appliances, etc.) connected to an Ethernet, intranet, and / or extranet and configured to communicate with each other via ad-hoc connections (e.g., Bluetooth®, Near Field Communication (NFC), etc.), local area connections (LANs), wireless local area networks (WLANs), and / or virtual private networks (VPNs), regardless of the physical location of each device. A network may further include any tools, applications, and / or services deployed by devices or utilized by enterprise IT systems such as firewalls, email clients, document management systems, and office systems. In some non-limiting aspects, “Network” may include third-party devices, applications, and / or services that are owned and controlled by a third party but which the tenant is authorized to access the corporate IT systems.
[0029] Security Information and Event Management (SIEM) involves software configured to aggregate and analyze activity from many different resources across the entire information technology (IT) infrastructure. For example, a SIEM can be implemented to aggregate data from multiple systems (e.g., log data, event data, threat intelligence data, etc.) and analyze that data to capture anomalous behavior or potential cyberattacks. For instance, a SIEM can collect security data from network devices, servers, domain controllers, etc. A SIEM can be implemented to store, normalize, aggregate, and apply analysis to that data to detect trends, identify threats, and enable organizations to investigate any alerts. While known SIEM tools offer excellent functionality, such as event monitoring, data collection, and issuing network-wide security alerts, such tools are typically customized to the organization implementing them—more specifically, to the specific network architecture, which can often be complex. Furthermore, existing SIEM domains cannot manage and correlate events across multiple customers. Therefore, SIEM can be expensive, resource-intensive, and often difficult to solve problems using SIEM data.
[0030] One example of a SIEM is Azure Sentinel, a widely used cloud-based tool. However, deploying Azure Sentinel requires advanced skills and is also very time-consuming, making it prone to errors. Each organization requiring a security solution has specific monitoring and alerting needs, including ingested log sources, detection / alert rules, automated responses, and reporting. Microsoft (MSFT) is often used by security service providers (MSSPs) to manage multiple clients, but the complexity of initial configuration, deployment, and ongoing maintenance of artifacts (e.g., alert rules, workbooks, playbooks) has increased significantly. Furthermore, most cloud-based products are subject to various changes determined by the manufacturer, which can simultaneously affect all customers. These changes can be fault fixes or new features / enhancements.
[0031] This can result in higher costs for both MSSPs, who must hire more expensive specialists, and clients, who often bear at least some of the increased expenses. However, there is often overlap between some of the deployment needs of various clients. For example, many organizations may need similar firewall monitoring solutions. In such cases, asset reuse and redeployment (and updating) can lead to significant cost savings and operational simplification. Unfortunately, known SIEM tools are technically incapable of leveraging these synergies. Therefore, MSSPs have limited opportunities for reuse to capture efficiency across multiple clients, from initial provisioning to automated incident response. Thus, there is a need for improved devices, systems, and methods for implementing and publishing SIEM client updates. Such enhancements can improve the technical performance and cost efficiency of the SIEM, including the implementation of detection rules, visibility, investigation workbooks, and ongoing maintenance. Furthermore, such enhancements can accommodate and accelerate the adoption of manufacturer-driven changes and help deploy such changes simultaneously across multiple customers.
[0032] This disclosure envisions such devices, systems, and methods, all of which offer more technical advantages than traditional MSSP and SIEM platforms. For example, traditional MSSP devices, systems, and methods lack the automation, artifacts, and interfaces necessary to seamlessly scale an MSSP platform to provide SIEM services to hundreds (if not thousands) of tenant networks. Rather, traditional MSSP devices, systems, and methods require manual integration and management, meaning they are inefficient and more expensive. Furthermore, traditional MSSP devices, systems, and methods require each tenant network to share manual resources employed by the MSSP, reducing the security of each tenant network. In contrast, the devices, systems, and methods disclosed herein are highly automated and therefore configured to allow an MSSP to continuously monitor tenant networks and clients in real time. Not only are traditional MSSP devices, systems, and methods technically unable to perform such automation, but it is highly impractical, if not impossible, for an MSSP to manually monitor hundreds, if not thousands, of tenant networks in real time. The devices, systems, and methods disclosed herein are also technically configured to be adaptable. Combined with their high scalability, this adaptability allows the MSSP to track changes across a large number of tenant deployments, monitor responses to those changes, and autonomously implement them for any suitable tenant deployment that could similarly benefit. In other words, conventional MSSP devices, systems, and methods are inherently more vulnerable to security events and are therefore less technically secure than the devices, systems, and methods disclosed herein.
[0033] For example, this disclosure provides a simple visual integration environment that enables simple management of client deployments, including, for example, (1) a catalog of various artifacts (alert rules, playbooks, workbooks, etc.), (2) the ability to select desired artifacts and deploy them to a client's target Sentinel environment with a single click, (3) the ability to visualize all client deployments, such as what is being deployed and what is obsolete (e.g., alert rules have newer versions), and the ability to visualize differences and quickly deploy desired updates, and (4) the ability to change multiple customers simultaneously and in bulk. Such a visual integration environment may provide different functionalities depending on the specific SIEM implementation. For example, according to a non-limiting aspect, if the SIEM implementation is a product such as Splunk, the visual integration environment can be used to integrate and manage various correlations, dashboards, lookups, apps, and / or technology add-ons configured to adapt ingested data to different schemes for improved analytics, among other Splunk functionalities. In non-limiting embodiments where the SIEM implementation is a product such as Sentinel, a visually integrated environment can be used to integrate and manage various parsers, particularly other Sentinel functions. Naturally, Splunk and Sentinel are provided for illustrative purposes only, and the devices, systems, and methods disclosed herein can be implemented in conjunction with any SIEM implementation to enhance network security more efficiently and at scale.
[0034] Referring here to Figure 1, a diagram of a system 1000 configured to enhance SIEM updates according to at least one non-limiting aspect of this disclosure is shown. According to the non-limiting aspect of Figure 1, the system 1000 may include a SIEM provider server 1002 having memory 1006 configured to store a SIEM management application 102 and a processor 1004 configured to run the stored SIEM management application 102, as will be further discussed with reference to Figure 2. For example, the SIEM provider server 1002 may be a computing resource owned or leased by an MSSP. The SIEM provider server 1002 can be communicably coupled to a plurality of tenants 1010a, 1010b-1010n via a network 1008. Each of the plurality of tenants 10101, 10102-1010 n This can represent a customer (e.g., an organization) that has a contract with the MSSP. According to the non-limiting aspect of Figure 1, network 1008 may include any various wired, long-range wireless, and / or short-range wireless networks. For example, network 1008 may include internal networks, local area networks (LANs), Wi-Fi®, cellular networks, near-field communication (NFC), etc.
[0035] Furthermore, referring to Figure 1, 、 Multiple tenants 10101, 10102-1010 n It can host one or more instances of clients 1012, 1014, 1016. For example, the first tenant 10101 can host one or more client applications 10121, 10122~1012 n The second tenant 10102 may include one or more machines that implement the second tenant 10102, one or more client applications 10141, 10142-1014 n This may include one or more machines that implement and / or a third tenant 1010 n This refers to one or more client applications 10161, 10162~1016 nmay include one or more machines that implement it. Each tenant 10101, 10102, and 1010 n can include an intranet by each machine that implements a client application. For example, each tenant 10101, 1010 2、 and 1010 n can each represent a customer such as an organization that has contracted with an MSSP for security services. Thus, the SIEM provider server 1002 can be configured to have monitoring of multiple each tenant 10101, 10102, and 1010 n and is therefore responsible for monitoring and managing each client application 1012, 1014, and 1016 against threats. As described above, the differences and complexities in the tenant 10101, 10102, and 1010 n architecture can complicate this and make it inefficient for the MSSP. Thus, known SIEM tools can leave the tenant 10101, 10102, and 1010 n technologically exposed to attacks and thus vulnerable. According to non-limiting aspects of the present disclosure, the SIEM provider server 1002 can address these deficiencies technically and practically by enhancing the SIEM provider server 1002's management capabilities and alert transmission capabilities for multiple tenants, as well as the update capabilities of client applications, based on correlation and synergistic development needs, and implement a SIEM management application 102.
[0036] Referring here to Figure 2, a diagram of the system 100 of Figure 1 is shown, in accordance with at least one non-limiting aspect of this disclosure, including a SIEM management application 102, i.e., a visualization tool. According to certain non-limiting aspects, the system 100 of Figure 2 can provide a visually integrated environment that enables the management of client deployments, including, for example, (1) a catalog of various artifacts (e.g., alert rules, playbooks, workbooks, etc.), (2) the ability to select desired artifacts and deploy them with one click to the client's target Sentinel environment, and (3) the ability to visualize all client deployments, such as what is being deployed and what is obsolete (e.g., alert rules have newer versions), and the ability to visualize differences and quickly deploy desired latest updates.
[0037] The Visual Tools / System 100 is a computer security system software product and service that combines security information management and security event management, providing real-time analysis of security alerts generated by applications and network hardware. System 100, for example, as discussed earlier, can access one or more tenants 10101, 10102, 1010 nThe SIEM management application 102 may include a SIEM management application 102 running on a SIEM provider server 1002 (see Figure 1) that communicates with one or more client applications 104 which may be hosted by (see Figure 1). For example, according to one non-limiting embodiment, the client application 104 may include the software configuration of the SIEM application 110, and the management for viewing and / or deploying multiple alert rules and constants 112 associated with one or more automated playbooks 116, the deployment, monitoring, and updating of workbooks 114 for dashboards, the management of fine-tuning alerts via constants, and incidents 118. Furthermore, for example, a mechanism for detecting, visualizing differences, and updating outdated alert rules 112 across the deployment of one or more SIEM applications 110 and SIEM implementations provided by other vendors. The SIEM management application 102 may be monitored by a security engineer / analyst 106. In one embodiment, the SIEM application 110 is an Azure Sentinel software application, for example, without prejudice the possibility of using other SIEM applications.
[0038] One or more client applications 104 interface with various clouds 128, firewalls 130, and servers 132 via connectors 120. One or more security engineers / analysts / content engineers 138 interface with client applications 104 to create / edit assets. Each commit is pushed to an application server, such as a content repository 140 (GitHub / GitLab, etc.), which contains deployable artifact templates. Those skilled in the art will understand that GitHub can be used as a basic code repository, issue tracker, documentation, and wiki. Similar to GitHub, GitLab is a repository manager that enables teams to collaborate on code and can provide similar functionality to GitHub for issue tracking and project management.
[0039] In one non-definitive embodiment, the content repository 140 may include a "json" file for defining alert rules, workbooks, playbooks, etc. When new content is added or updated, the changes are automatically pushed to the SIEM management application 102. In one embodiment, the SIEM management application 102 may be configured, for example, as an Azure Sentinel Automation Portal (ASAP). In one embodiment, the ASAP portal runtime software code may include server middleware responsible for processing content from the content repository 140, connecting to the SIEM application 110, and other services, as well as service requests to client applications 104 for deploying, updating, and reading content between the SIEM application 110 and the server. In one embodiment, the client application 104 provides a unified, simplified view of all client deployments and the ability to work with one or more clients 104 simultaneously.
[0040] The SIEM management application 102 allows security analysts 106 to not only see everything that has been deployed, but also to update a single artifact on a single client 104, or multiple artifacts, across multiple clients 104, in a simple interaction.
[0041] This functionality allows the MSSP to scale to hundreds or thousands of clients 104 with minimal staff and required skills. Produced or updated content, such as new alert rules 112 that verify the presence of new malware, can be immediately pushed to all clients 102. Furthermore, in one aspect, many of these operations, including "content changes," can be automated on a schedule. For example, the moment an artifact (e.g., an alert rule, workbook) is updated in the content repository, that change can automatically trigger a webhook configured to automatically push to all relevant tenants or clients (e.g., tenants where the updated artifact is deployed and / or configured). Similarly, new artifacts, not just updated ones, can also be automatically pushed (and configured) to all appropriate tenants or clients. For example, if several alert rules have been previously configured in some tenant networks or clients to detect unusual behavior in the Office 365 activity logs, and then new alert rules are created in the content repository to apply to the Office 365 logs, the SIEM management application 102 can automatically deploy them to all relevant tenants or clients, as it only needs to supplement the list of detections appropriate for the client's Office 365 environment.
[0042] In one embodiment, the SIEM management application 102 can display all changes, for example, new or updated versions of those introduced in the content repository 140, to the SIEM application 110 of each client 104, evaluate what the changes were, and push changes, updates, or new artifacts very quickly.
[0043] Furthermore, in one embodiment, user interface (UI) commands that implement various deployments may also be captured as scripts, checked into the client's 104 repository for verification, and later automatically updated.
[0044] In one embodiment, the hosted cloud SIEM management application 102 provides "one-click automation." For example, the SIEM management application 102 provides automation for creating, configuring, and implementing SIEM applications 110, including alert rules 112, constants, parsers, data connectors 120, playbooks 116, workbooks 114, etc. In one embodiment, the SIEM management application 102 also provides deployment management across all clients 104. The SIEM management application 102 provides visibility into all deployments of client 104, what, and where, to update existing alerts 112, playbooks 116, etc., across any number of clients 104, and to deploy newly added alert rules 112 and other assets.
[0045] The SIEM management application 102 enables one-click automation 134 such as REST APIs, alerts 112, and playbooks 116. Those skilled in the art will understand that a REST API, also known as a RESTful API, is an application programming interface (API or web API) that conforms to the constraints of the REST architectural style and enables interaction with RESTful web services. An API (Application Programming Interface) is a set of definitions and protocols for building and integrating application software. The SIEM management application 102 provides real-time data integration, such as REST APIs, alerts 112, and playbooks 116, to a flexible server relational cloud database 146 service, such as an Azure Postgres SQL database. The SIEM management application 102 interfaces with a resource provider and a normalizer 136. The resource provider and normalizer 136 interfaces with a log analysis workspace 142, Microsoft Graph, and Microsoft resource manager 144. This system 100 includes Microsoft Azure, and Azure Government 152, a mission-critical cloud, delivers groundbreaking innovations accessible only to U.S. government customers and the U.S. government, state governments, local governments, tribal governments, and their partners, in an operation managed by screened U.S. citizens. Microsoft Azure and Azure Government 152 interface to node 150. React 148 provides an interactive UI to account 108. Referring further to Figure 2, in one embodiment, the SIEM management application 102 provides a quick view across all deployments and statuses, as well as the ability to directly manipulate where and what state a given alert is deployed.
[0046] Referring here to Figure 3, the graphical user interface 200 of the SIEM management application 102 in Figure 2 is illustrated in accordance with at least one non-limiting aspect of this disclosure. According to the non-limiting aspect of Figure 3, the graphical user interface 200 can be displayed when an engineer / analyst 106 selects various deployment views and statuses of My Sentinel 202, Current Sentinel 204, Bundles 206, and Alerts 208 from the SIEM management application 102. To display the quick view screen 200 shown in Figure 3, the engineer / analyst 106 selects the "by tenant" button 210 from the My Sentinel 202 menu on the left side of the screen 200 to display information by tenant. Furthermore, the graphical user interface 200 can provide guided deployments. For example, the graphical user interface 200 can detect what log sources (e.g., data connectors, source types, etc.) are configured for a SIEM implementation (e.g., Sentinel, Splunk, etc.) and can show specific alert rules and / or correlations available for analyzing the data ingested from these logs, as will be explained in more detail with reference to Figure 12.
[0047] The My Sentinel 202 menu allows users to enable other display screens by selecting the "By Tenant" 210 (see Figure 3), "By Alert" 212 (see Figures 4-5), or "By Connectors" 214 (see Figure 6) buttons. Returning to Figure 3 from the current Sentinel 204 menu, engineers / analysts 106 can select deployment views and statuses by alert 216 (see Figure 7), data connectors 218 (see Figure 10), playbooks 220, dependencies 222 (see Figure 9), MITRE 224 (see Figure 8), and dashboards 226. Furthermore, the My Sentinel 202 menu frees users who need to locate, copy, and / or paste various identifiers associated with the target location of artifact deployments (e.g., tenant identifier, subscription identifier, resource group identifier, workspace identifier, etc.). In My Sentinel 202 and / or other aspects of the menus and user interface, the correct identifiers are automatically ported on behalf of the user.
[0048] Referring again to Figure 3, the graphical user interface 200, or the “Quick View” screen, is displayed by selecting the “By Tenant” button 210 from the My Sentinel 202 menu on the left side of screen 200. The “By Tenant” Quick View screen 200 displays information about tenants such as the first tenant 228, Big Tech, the second tenant 230, Big Software, and the third tenant 232, Big Info Tech. For each of these example tenants 228, 230, and 232, the Quick View screen 200 displays text boxes containing information about each network connected to System 100, such as the number of assets deployed, the number of assets deprecated, the number of assets automatically disabled, and the number of assets requiring updates. This disclosure refers to the Sentinel SIEM for brevity and clarity of disclosure, but the scope of this disclosure is not limited to this context, and any appropriate SIEM may be used.
[0049] For example, for the first tenant 228, text box 234 indicates that the network contains 77 deployed SIEMs. For the second tenant 230, the text boxes for each network 236, 238, 240, 242, 244, 246, 248, and 250 show the number of deployed, deprecated, disabled, and SIEMs requiring updates. As shown, a similar text box 252 is displayed for the third tenant 232. Naturally, Quick View 200 can be zoomed to display any number of tenants and their associated text boxes to show the deployment, deprecation, disabled, and update status of SIEM applications running on each client of one of the various networks.
[0050] Referring here to Figure 4, another graphical user interface 300 of the SIEM management application 102 of Figure 2 is shown in accordance with at least one non-limiting aspect of this disclosure. According to the non-limiting aspect of Figure 4, the graphical user interface 300 can be displayed by selecting the “By Alert” button 212 from the My Sentinel 202 menu. The screen 300 displays where a given alert is deployed and its status. A list of alert rules 302 is displayed on the left side of the menu, moving to the right of the menu portion. To see where an alert rule is deployed, the engineer / analyst 106 selects an alert rule 304 from the list 302, and a detail view 304' of the selected alert rule 304' is displayed on the right side of the screen 300. The detail view 304' displays information about a specific tenant 306, workspace 308, where the alert rule 304 is deployed 310, active 312, and synchronized 314 status.
[0051] Referring here to Figure 5, another graphical user interface 350 of the SIEM management application 102 of Figure 2 is shown in accordance with at least one non-limiting aspect of this disclosure. According to the non-limiting aspect of Figure 5, the graphical user interface 350 can be displayed where a selected alert rule 304 has not yet been deployed, allowing for the deployment of a new alert to multiple clients. One or more client workspaces 318, 320 can be selected where the alert rule 304 of the selected rule can be deployed. A new screen 316 to the right of screen 350 shows the selected client workspaces 318, 320, where the alert rule 304 has not yet been deployed and provides an option to deploy the alert rule 304 with or without the playbook 324.
[0052] Referring here to Figure 6, another graphical user interface 400 of the SIEM management application 102 in Figure 2 is shown in accordance with at least one non-limiting aspect of this disclosure. According to the non-limiting aspect of Figure 6, the graphical user interface 400 can be displayed by selecting the "By Connector" button 214 from the My Sentinel 202 menu. Screen 400 displays a list of data connectors 402 on the left side of Screen 400. Screen 400 allows the engineer / analyst 106 to update all alerts associated with a data connector 402 (i.e., for a log source) in one or more clients. Screen 400 also visualizes which alerts are outdated in each client. Thus, the engineer / analyst 106 can select a data connector 404 from the left side of Screen 400 to view all locations where there are outdated versions of the alert rules for the selected data connector 404. The engineer / analyst 106 may select one or more client workspaces 406 where the alert rules are out of sync 408 and update them to their latest versions. The sync button 410 is selected to update the alert rules for the selected data connector 404.
[0053] Referring here to Figure 7, another graphical user interface 500 of the SIEM management application 102 of Figure 2 is shown in accordance with at least one non-limiting aspect of this disclosure. According to the non-limiting aspect of Figure 7, the graphical user interface 500 can be displayed by selecting the alert button 216 from the current Sentinel 204 list. When working with a particular client (i.e., a particular Sentinel workspace), the engineer / analyst 106 can select the deploy button 502 and all radio buttons 504 to observe all deployed alert rules and extended details of a particular alert rule. Deployed rules and alerts are identified by name 506, category 508, synchronization status 510, active status 512, and playbook 514.
[0054] Referring here to Figure 8, another graphical user interface 600 of the SIEM management application 102 in Figure 2 is shown in accordance with at least one non-limiting aspect of this disclosure. According to the non-limiting aspect of Figure 8, the graphical user interface 600 can be displayed by selecting the MITRE button 224 from the current Sentinel 204 list. The MITRE screen 600 maps alerts to the MITRE ATT&CK framework and displays MITRE values that visualize coverage, etc. In the example shown in Figure 7, the MITRE ATT&CK coverage is 21.3%. In other words, the SIEM management application 102 (see Figure 2) can provide visibility that helps cybersecurity teams evaluate the effectiveness of their security operations center (SOC) processes and defensive measures to identify areas for improvement. With respect to MITRE ATT&CK, in particular, the SIEM management application 102 (see Figure 2) can evaluate the implemented MITRE ATT&CK technologies against the available MITRE ATT&CK technologies and provide recommendations and / or visual indicators of significant gaps. For example, in some non-limiting embodiments, a SIEM management application 102 (see Figure 2) can employ a color-coding scheme, where each color serves as an indicator of a gap to be introduced or a recommended MITRE ATT&CK technique. One such scheme is shown in a non-limiting embodiment in Figure 8.
[0055] Referring here to Figure 9, another graphical user interface 700 of the SIEM management application 102 of Figure 2 is shown in accordance with at least one non-limiting aspect of this disclosure. According to the non-limiting aspect of Figure 9, the graphical user interface 700 can be displayed by selecting the dependency button 222 from the current sentinel 204 list. The screen 700 provides the ability to fine-tune alert rules. An alert rule may have one or more constants, so that the alert rule is deployed exactly the same to multiple clients, but then various client-specific values can be set via constants (e.g., machine, user whitelist, etc.). Constants can be displayed by selecting the constant button 702. Constants are identified by name 706, category 708, deployment status 710, and alert 712. Constants may be updated by selecting the update button 704. In other words, the SIEM management application 102 (see Figure 2) may include a rule editor that can be used to specifically customize constants and / or rules that manage alerts issued for a particular tenant. Furthermore, the SIEM management application 102 (Figure 2) can be configured to integrate with another platform (e.g., GitLab), which can then update the SIEM management application 102 (Figure 2), more specifically, the server hosting the SIEM management application 102 (Figure 2), with new and / or updated rules for alerts. Thus, the SIEM management application 102 (see Figure 2) can enable new deployments and / or synchronize deployments to the latest version published to one or more tenants.
[0056] Referring now to Figure 10, another graphical user interface 800 of the SIEM management application 102 of Figure 2 is shown in accordance with at least one non-limiting aspect of this disclosure. According to the non-limiting aspect of Figure 10, the graphical user interface 800 can be displayed by selecting the data connector 218 button and the deploy (preview) button 802 from the current sentinel 204 list. The screen 800 displays the managed Sentinel connectors.
[0057] The internal model has various associations (similar to the MITRE method described above, but also associations with log sources / data connectors that alerts query for searches). Associations with data connectors allow all alerts to be quickly deployed for a given data connector, without the need to manually select each one. Essentially, this is a convenient semantic group construct that raises the level of abstraction that makes up the SIEM, so that once the connector is configured, alerts are deployed with a single click, as the SIEM focuses on ingesting data through a given data connector. Furthermore, it is possible to easily update these specific alerts later, on future dates, or add newly added alerts for data connectors.
[0058] Referring here to Figure 11, a method of using the system 1000 of Figure 1 and the SIEM management application 102 of Figure 2 according to at least one non-limiting aspect of the present disclosure. According to the non-limiting aspect of Figure 11, the method can enhance network security across multiple tenants configured to host multiple clients. Method 1100 may include providing a SIEM management application configured to be hosted by a SIEM provider server, which is communicably coupled to multiple tenants 1102. Method 1100 further includes receiving SIEM status from multiple tenants 1104 via the SIEM provider server and visualizing the SIEM status 1106 via a graphical user interface of the SIEM management application. Furthermore, Method 1100 includes filtering the SIEM status via the SIEM management application, at least in part, based on user input received via a graphical user interface 1108, and then visualizing the filtered SIEM status 1110 via the graphical user interface. Next, Method 1100 requires selecting at least one client from a plurality of clients hosted by at least one tenant among a plurality of tenants via a graphical user interface and updating it at least partially based on the filtered SIEM status 1112. The Method may further include generating a client update alert via a SIEM management application at least partially based on the selection 1114 and sending the client update alert to at least one tenant 1116 via the SIEM management application. Finally, Method 1100 may also include updating at least one client via at least one tenant at least partially based on the client update alert 1118, so that at least one client enhances the network security of at least one tenant.
[0059] Referring here to Figure 12, another graphical user interface 900 is illustrated according to at least one non-limiting aspect of this disclosure. According to the non-limiting aspect of Figure 12, the graphical user interface 900 can provide a user with guided deployment to simultaneously and seamlessly deploy updated and / or new artifacts 906, such as alerts or correlations, to a number of tenants. For example, the graphical user interface 900 can detect which log sources (e.g., data connectors, source types, etc.) are configured for a particular SIEM implementation (e.g., Sentinal, Splunk, etc.). Thus, a particular window 902 of the user interface 900 can enumerate new and / or updated artifacts 906 applicable to a particular SIEM implementation, from which the user can select and deploy them. A widget 904 may further, at a high level, show a certain number of artifacts 906 available for deployment. Thus, the user only needs to check the artifacts 906 they want to push for a particular SIEM implementation, and those selected artifacts 906 can be efficiently deployed to a number of SIEM implementations.
[0060] In other non-limiting embodiments, system 1000 (see Figure 1) may be configured to manage a previously configured SIEM without using a user interface, since system 1000 may be configured to detect the state of a particular SIEM implementation and / or client without human intervention. This autonomy facilitates and stimulates the intelligence underlying the aforementioned user interface and facilitates a certain degree of user feedback and control. However, in these non-limiting embodiments, system 1000 (see Figure 1) can independently apply the underlying intelligence without human intervention, apply the latest changes to artifacts, add artifacts to the content repository, and / or update the SIEM implementation for a large number of clients without relying on user input received through the aforementioned user interface.
[0061] Various aspects of the subject matter described herein are described in the following numbered sections.
[0062] Section 1 A method for enhancing network security across multiple tenants configured to host multiple client applications, comprising: providing a SIEM management application configured to be hosted by a Security Information and Event Management (SIEM) provider server that is communicably coupled to the multiple tenants; receiving SIEM status from the multiple tenants via the SIEM provider server; visualizing the SIEM status via a graphical user interface of the SIEM management application; filtering the SIEM status via the SIEM management application, at least partially based on user input received via the graphical user interface; visualizing the filtered SIEM status via the graphical user interface; selecting at least one client application from among multiple client applications hosted by at least one of the multiple tenants, and updating it at least partially based on the filtered SIEM status via the graphical user interface; generating client application updates and update alerts via the SIEM management application, at least partially based on the selection; sending update alerts to at least one tenant via the SIEM management application; and updating at least one client application via at least one tenant, at least partially based on the update alert, wherein updating at least one client application enhances network security for at least one tenant.
[0063] According to other non-limiting aspects, managing a previously configured SIEM without a UI allows the system to apply the latest changes added to artifacts in the content repository because it already knows the client's state.
[0064] Section 2 The method described in paragraph 1, wherein the SIEM status includes at least one of the tenant name, client name, and client application version for each tenant of multiple tenants, or a combination thereof.
[0065] Section 3 The method described in paragraph 1 or 2, wherein user input includes at least one of the following for each tenant of multiple tenants: tenant name, client name, and client application version, or a combination thereof.
[0066] Section 4 The method according to any one of paragraphs 1 to 3, wherein the selection of at least one client application is further based on a second user input received via a graphical user interface, the second user input includes at least one of the tenant name associated with at least one client application, the client name associated with at least one client application, and the client application version associated with at least one client application, or a combination thereof.
[0067] Section 5 The SIEM provider server has memory configured to store multiple rules associated with the deployment needs for each tenant of multiple tenants, and the method of any of paragraphs 1 to 4 generates update alerts based at least in part on at least one rule out of multiple rules associated with at least one tenant.
[0068] Section 6 The method according to any of paragraphs 1 to 5, further comprising correlating multiple rules into multiple playbooks, at least in part, based on the deployment needs for each tenant of multiple tenants, via a SIEM management application.
[0069] Section 7 The method according to any one of paragraphs 1 to 6, wherein the graphical user interface includes a playbook widget, and the selection of at least one client application is further based on user interaction with the playbook widget via the graphical user interface, and the generation of update alerts is at least partially based on at least one playbook out of multiple playbooks associated with at least one tenant.
[0070] Section 8 The requirement for deployment to at least one tenant is one of the methods described in paragraphs 1 through 7, including a firewall monitoring protocol.
[0071] Section 9 The system described in any of paragraphs 1 to 8, further comprising storing generated client application updates in memory, and updating at least one client application further comprising retrieving generated client application updates from memory via at least one tenant.
[0072] Section 10 The system described in any of paragraphs 1 through 9 further configures memory to store artifact templates and generates update alerts based on the stored artifact templates.
[0073] Section 11 The stored artifact template includes a writable js.on file, as described in any of paragraphs 1 through 10.
[0074] Section 12 The method according to any one of paragraphs 1 to 11, further comprising generating a new template that includes at least one of a new rule, a new workbook, and a new playbook, or a combination thereof, based on the SIEM status, and storing the new template in memory.
[0075] Section 13 The method described in any of paragraphs 1 through 12, wherein the SIEM status includes several deployed client applications, several deprecated client applications, and several disabled client applications, or a combination thereof, for each tenant of multiple tenants.
[0076] Section 14 A system described in any of paragraphs 1 through 13, in which multiple tenants are located remotely from the SIEM provider server.
[0077] Section 15 A system for enhancing network security, comprising: multiple tenants configured to host multiple clients; a Security Information and Event Management (SIEM) provider server communicatively coupled to the multiple tenants, wherein the SIEM provider server includes a processor and memory, and the memory is configured to store a SIEM management application that, when executed by the processor, causes the processor to receive SIEM status from the multiple tenants, visualize the SIEM status via a graphical user interface of a SIEM management application illustrated on a display communicatively coupled to the SIEM provider server, at least partially filter the SIEM status based on user input received via the graphical user interface, visualize the filtered SIEM status via the graphical user interface, decide at least partially to update at least one client among multiple clients hosted by at least one of the multiple tenants based at least partially on the filtered SIEM status, at least partially generate an update alert based on the decision, send the update alert to at least one tenant, and at least partially update at least one client application based on the update alert, thereby enhancing network security for at least one tenant when at least one client is updated.
[0078] Section 16 The memory is further configured to store multiple rules associated with the deployment needs for each tenant of multiple tenants, and when executed by the processor, the SIEM management application causes the processor to further generate update alerts based on at least one of the multiple rules associated at least partially with at least one tenant, as described in Section 15 of the system.
[0079] Section 17 When executed by the processor, the SIEM management application further correlates multiple rules to multiple playbooks, at least partially based on the deployment needs for each tenant of multiple tenants, as described in Section 15 or 16 of the system.
[0080] Section 18 The system described in any of paragraphs 15 to 17, wherein the graphical user interface includes a playbook widget, and the decision of at least one client generates an update alert based at least in part on at least one playbook out of multiple playbooks associated with at least one tenant, further based on user interaction with the playbook widget via the graphical user interface.
[0081] Section 19 A system according to any of paragraphs 15 to 18, further comprising, at least in part, generating predictions relating to the future behavior of a reactor based on determined conditions inside the reactor vessel and diagnostic conclusions associated with the reactor.
[0082] All patents, patent applications, publications, or other disclosure materials described herein are incorporated herein by reference in whole, as if each individual reference were expressly incorporated by reference. All references and any material, or any part thereof, that are said to be incorporated herein by reference are incorporated herein only insofar as the incorporated material does not conflict with any existing definitions, descriptions, or other disclosure materials described herein. Therefore, and to the extent necessary, the disclosures expressed herein supersede any conflicting material incorporated herein by reference, and the disclosures expressly described within the scope of this application.
[0083] Various exemplary and illustrative embodiments are described. The embodiments described herein are understood to provide exemplary features of various details of various embodiments of the Disclosure, and therefore, unless otherwise specified, one or more features, elements, components, ingredients, raw materials, structures, modules, and / or embodiments of the Disclosure may be combined, separated, replaced, and / or rearranged with or to one or more other features, elements, components, ingredients, raw materials, structures, modules, and / or embodiments of the Disclosure, as far as possible, without departing from the scope of the Disclosure. Accordingly, a person skilled in the art will recognize that various substitutions, modifications, or combinations of any of the exemplary embodiments can be made without departing from the claimed subject matter. Furthermore, a person skilled in the art can recognize or confirm many equivalents to various embodiments of the Disclosure by re-examining this specification using only routine experiments. Accordingly, the Disclosure is not limited by the description of various embodiments, but is limited only by the claims.
[0084] Those skilled in the art will generally recognize that the terms used herein, and in particular in the appended claims (e.g., the text of the appended claims), are intended to be generally “unrestrictive” terms (e.g., the term “including” should be interpreted as “including but not limited,” the term “having” should be interpreted as “having at least,” and the term “includes” should be interpreted as “including but not limited,” etc.). Those skilled in the art will further understand that where a particular number of introduced claims enumerations are intended, such intentions are explicitly enumerated in the claims, and where such enumerations are absent, such intentions are not present. For example, for the sake of understanding, the following appended claims may include the use of the introductory phrases “at least one” and “one or more” to introduce the enumeration of claims. However, the use of such phrases should not be interpreted as implying that the introduction of a claim enumeration with the indefinite article "a" or "an" implies that any particular claim containing such introduced claim enumeration is limited to a claim that contains only one such enumeration, even if the same claim contains the introductory phrase "one or more" or "at least one" and an indefinite article such as "a" or "an" (for example, "a" and / or "an" should generally be interpreted as meaning "at least one" or "one or more"), and the same applies to the use of the definite article used to introduce a claim enumeration.
[0085] Furthermore, even if a specific number of claims enumerated is explicitly listed, a person skilled in the art will recognize that such enumeration should typically be interpreted as meaning at least the number listed (for example, a mere enumeration such as “two enumerations” usually means at least two enumerations or two or more enumerations without other modifiers). Moreover, in these examples where a similar convention to “at least one of A, B, and C, etc.” is used, such construction is generally intended in the sense that a person skilled in the art will understand the convention (for example, “a system having at least one of A, B, and C” includes, but is not limited to, a system having A alone, B alone, C alone, a system having A and B together, a system having A and C together, a system having B and C together, and / or a system having A, B, and C together, etc.). Where a similar convention to "at least one of A, B, or C, etc." is used, such a structure is generally intended to be understood by a person skilled in the art (for example, "a system having at least one of A, B, or C" includes, but is not limited to, A alone, B alone, C alone, a system having A and B together, a system having A and C together, a system having B and C together, and / or a system having A, B, and C together). In any description, claims, or drawings, any separating words and / or phrases that typically present two or more alternative terms will be understood by a person in the art to be intended to include the possibility of including one of those terms, either of those terms, or both, unless the context indicates otherwise. For example, the phrase "A or B" will typically be understood to include the possibilities of "A" or "B" or "A and B".
[0086] With respect to the attached claims, those skilled in the art will understand that the actions enumerated therein may generally be performed in any order. Furthermore, while the claims are presented sequentially, it should be understood that various actions may be performed in other orders than those described, or simultaneously. Examples of such alternative orders include, unless otherwise indicated by the context, overlapping, interleaving, interrupting, reordering, incremental, preparing, supplementing, simultaneous, reversed, or other variant orders. Moreover, unless otherwise indicated by the context, terms such as “responding,” “related,” or other past tense adjectives are generally not intended to exclude such variants.
[0087] It should be noted that any reference to “one aspect,” “aspect,” “example,” “one example,” and similar terms means that a particular feature, structure, or characteristic described in relation to an aspect is included in at least one aspect. Therefore, the appearances of the phrases “in one aspect,” “in a certain aspect,” “in a certain example,” and “one example” in various places throughout this specification do not necessarily all refer to the same aspect. Furthermore, a particular feature, structure, or characteristic may be combined in any suitable manner in one or more aspects.
[0088] As used herein, unless the context explicitly indicates otherwise, the singular forms "a," "an," and "the" include multiple references.
[0089] For example, but not limited to, directional terms used herein, such as up, down, left, right, downward, upward, front, back, and variations thereof, relate to the orientation of elements shown in the accompanying drawings and are not limited to the claims unless otherwise explicitly stated.
[0090] As used in this disclosure, the terms “about” or “approximately” mean, unless otherwise specified, an acceptable error in a particular value as determined by a person skilled in the art, which depends in part on how the value is measured or determined. In certain embodiments, the terms “about” or “approximately” mean within 1, 2, 3, or 4 standard deviations. In certain embodiments, the terms “about” or “approximately” mean within 50%, 200%, 105%, 100%, 9%, 8%, 7%, 6%, 5%, 4%, 3%, 2%, 1%, 0.5%, or 0.05% of a given value or range.
[0091] In this specification, unless otherwise indicated, all numerical parameters are understood to be predicated, and in all cases, numerical parameters should be understood to be modified by the term “approximately,” having the inherent variability characteristics of the underlying measurement technique used to determine the numerical value of the parameter. At least, not as an attempt to limit the application of the principle of equivalence to the claims, each numerical parameter described herein shall be interpreted in light of at least the number of significant figures reported and by applying the usual method of rounding.
[0092] Any numerical range enumerated herein includes all subranges contained within the enumerated range. For example, the range from 1 to 100 includes all subranges between (and including) the enumerated minimum value of 1 and the enumerated maximum value of 100, i.e., all subranges having a minimum value of 1 or greater and a maximum value of 100 or less. Also, all ranges enumerated herein include the endpoints of the enumerated range. For example, the range from 1 to 100 includes the endpoints 1 and 100. Any maximum numerical limit enumerated herein is intended to include all lower numerical limits contained within it, and any minimum numerical limit enumerated herein is intended to include all higher numerical limits contained within it. Accordingly, the applicant reserves the right to modify this specification to explicitly enumerate subranges contained within explicitly enumerated ranges, including the claims. All such ranges are essentially described herein.
[0093] Any patent application, patent, non-patent publication, or other disclosure material referred to herein and / or enumerated in any application data sheet is incorporated herein by reference, provided that the incorporated material does not conflict with this specification. Therefore, and to the extent necessary, the express disclosures expressed herein supersede any conflicting material incorporated herein by reference. Any material or any part thereof that is said to be incorporated herein by reference but conflicts with existing definitions, statements, or other disclosure materials expressed herein is incorporated only to the extent that it does not create any conflict between the incorporated material and the existing disclosure material.
[0094] The terms “comprise” (and any form of “comprise,” such as “comprises” and “comprising”), “have” (and any form of “have,” such as “has” and “having”), “include” (and any form of “include,” such as “includes” and “including”), and “contain” (and any form of “contains” and “containing”) are open-ended linking verbs. As a result, a system that “comprises,” “haves,” “includes,” or “contains” one or more elements possesses, but is not limited to possessing only, those one or more elements. Similarly, an element of a system, device, or apparatus that “comprises,” “haves,” “includes,” or “contains” one or more features possesses, but is not limited to possessing only, those one or more features.
[0095] The detailed descriptions above describe various forms of devices and / or processes using block diagrams, flowcharts, and / or embodiments. Where such block diagrams, flowcharts, and / or embodiments include one or more functions and / or operations, a person skilled in the art will understand that each function and / or operation in such block diagrams, flowcharts, and / or embodiments can be implemented individually and / or collectively by a wide range of hardware, software, firmware, or substantially any combination thereof. A person skilled in the art will recognize that some aspects of the forms disclosed herein can be implemented in whole or in part equivalently on an integrated circuit as one or more computer programs running on one or more computers (e.g., as one or more programs running on one or more computer systems), as one or more programs running on one or more processors (e.g., as one or more programs running on one or more microprocessors), as firmware, or substantially any combination thereof, and that designing the circuits, and / or writing the code for the software, and / or the firmware are within the scope of the skills of a person skilled in the art in light of this disclosure. Furthermore, those skilled in the art will understand that the mechanisms of the subject matter described herein can be distributed as one or more program products in various forms, and that the exemplary forms of the subject matter described herein are applicable regardless of the specific type of signal-carrying medium used to actually carry out the distribution.
[0096] Instructions used to program logic and implement various disclosed embodiments may be stored in the system's memory, such as dynamic random access memory (DRAM), cache, flash memory, or other storage devices. Furthermore, instructions may be distributed over a network or other computer-readable medium. Thus, machine-readable medium is any mechanism for storing or transmitting information in a form readable by a machine (e.g., a computer), and may include, but is not limited to, floppy diskettes, optical disks, compact disks, read-only memory (CD-ROMs), and magneto-optical disks, read-only memory (ROMs), random access memory (RAMs), erasable programmable read-only memory (EPROMs), electrically erasable programmable read-only memory (EEPROMs), magnetic or optical cards, flash memory, or tangible machine-readable storage devices used when transmitting information over the Internet via electrical, optical, acoustic or other forms of propagated signals (e.g., carrier waves, infrared signals, digital signals, etc.). Therefore, non-temporary computer-readable media include any type of tangible machine-readable medium suitable for storing or transmitting electronic instructions or information in a form readable by a machine (e.g., a computer).
[0097] Where used in any aspect of this specification, the term “control circuit” can mean, for example, wired circuits, programmable circuits (e.g., computer processors, processing units, processors, microcontrollers, microcontroller units, controllers, digital signal processors (DSPs), programmable logic devices (PLDs), programmable logic arrays (PLAs), or field-programmable gate arrays (FPGAs) having one or more individual instruction processing cores, state-machine circuits, firmware storing instructions executed by programmable circuits, and any combination thereof. Control circuits can be embodied collectively or individually as circuits forming part of a larger system, such as an integrated circuit (IC), an application-specific integrated circuit (ASIC), a system-on-a-chip (SoC), a desktop computer, a laptop computer, a tablet computer, a server, a smartphone, etc. Therefore, where used in this specification, “control circuit” can mean This includes, but is not limited to, electrical circuits having at least one discrete electrical circuit, electrical circuits having at least one integrated circuit, electrical circuits having at least one application-specific integrated circuit, electrical circuits forming a general-purpose computing device configured by a computer program (e.g., a general-purpose computer configured by a computer program that performs at least part of a process, and / or a device described herein, or a microprocessor configured by a computer program that performs at least part of a process, and / or a device described herein), electrical circuits forming a memory device (e.g., in the form of random access memory), and / or electrical circuits forming a communication device (e.g., a modem, a communication switch, or an optical electrical device). Those skilled in the art will recognize that the subject matter described herein may be implemented in analog or digital form or in some combination thereof.
[0098] Where used in any aspect of this specification, the term “logic” may mean an application, software, firmware, and / or circuitry configured to perform any of the operations described above. Software may be embodied as a software package, code, instructions, instruction sets, and / or data recorded on a non-temporary computer-readable storage medium. Firmware may be embodied as code, instructions, or instruction sets, and / or (e.g., non-volatile) data hardcoded within a memory device.
[0099] Where used in any aspect of this specification, the terms “component,” “system,” “module,” etc., may refer to computer-related entities, hardware, combinations of hardware and software, software, or running software.
[0100] Where used in any aspect of this specification, “algorithm” refers to a self-consistent sequence of steps that yield a desired result, and “step” refers to the manipulation of physical quantities and / or logical states that may, though not necessarily, take the form of electrical or magnetic signals that can be stored, moved, combined, compared, and otherwise manipulated. These signals are commonly referred to as bits, values, elements, symbols, characters, terms, digits, etc. These and similar terms may also be associated with appropriate physical quantities and are simply convenient codes applied to these quantities and / or states.
Claims
1. A method for simultaneously monitoring and enhancing network security across multiple tenants configured to host multiple client applications, To provide a security information and event management (SIEM) provider server, wherein the SIEM provider server is communicably coupled to the plurality of tenants, and a SIEM management application is configured to be hosted by the SIEM provider server. The SIEM provider server receives SIEM status from the multiple tenants, To visualize the SIEM status through the graphical user interface of the SIEM management application, The SIEM status is filtered, at least partially, based on user input received via the graphical user interface, through the SIEM management application. Visualizing the filtered SIEM status via the graphical user interface, Selecting at least one client application from among the multiple client applications hosted by a subset of the multiple tenants via the graphical user interface, and updating at least partially based on the filtered SIEM status, The SIEM management application generates updates to the client application and update alerts, at least partially based on the selection. Sending the update alert to the subset of the multiple tenants via the SIEM management application, A method comprising updating, at least partially, the at least one client application via the subset of the plurality of tenants based on the update alert, thereby enhancing the network security for the subset of the plurality of tenants by updating the at least one client application.
2. The method according to claim 1, wherein the SIEM status includes at least one of the tenant name, client name, and client application version, or a combination thereof, for each tenant of the plurality of tenants.
3. The method according to claim 2, wherein the user input includes at least one of the tenant name, client name, and client application version, or a combination thereof, for each tenant of the plurality of tenants.
4. The method according to claim 2, wherein the selection of the at least one client application is further based on a second user input received via the graphical user interface, the second user input includes at least one of the tenant name associated with the at least one client application, the client name associated with the at least one client application, and the client application version associated with the at least one client application, or a combination thereof.
5. The method according to claim 1, wherein the SIEM provider server has memory configured to store a plurality of rules associated with the deployment needs for each of the plurality of tenants, and the generation of the update alert is at least in part based on at least one of the plurality of rules associated with the subset of the plurality of tenants.
6. The method of claim 5, further comprising correlating the plurality of rules into a plurality of playbooks via the SIEM management application, at least in part, based on the implementation needs for each of the plurality of tenants.
7. The method according to claim 6, wherein the graphical user interface includes a playbook widget, and the selection of the at least one client application is further based on user interaction with the playbook widget via the graphical user interface, and the generation of the update alert is at least in part based on at least one playbook among the plurality of playbooks associated with the subset of the plurality of tenants.
8. The method according to claim 6, wherein the need for deployment to the subset of the plurality of tenants includes a firewall monitoring protocol.
9. The method according to claim 5, further comprising storing the generated client application update in the memory, and updating the at least one client application further comprising retrieving the generated client application update from the memory via the subset of the plurality of tenants.
10. The method according to claim 5, wherein the memory is further configured to store artifact templates, and the generation of the update alert is further based on the stored artifact templates.
11. The method according to claim 10, wherein the stored artifact template includes a writable JSON file.
12. Based on the aforementioned SIEM status, generate a new template that includes at least one of the following: a new rule, a new workbook, and a new playbook, or a combination thereof. The method according to claim 10, further comprising storing the new template in the memory.
13. The method according to claim 1, wherein the SIEM status includes several deployed client applications, several deprecated client applications, and several disabled client applications for each of the multiple tenants, or a combination thereof.
14. The method according to claim 1, wherein the plurality of tenants are located remotely from the SIEM provider server.
15. A system for enhancing network security, Multiple tenants configured to host multiple clients, A security information and event management (SIEM) provider server that is communicably connected to the aforementioned multiple tenants, Equipped with, The SIEM provider server comprises a processor and memory, The memory is configured to store the SIEM management application. When the SIEM management application is executed by the processor, the processor will: The system continuously and simultaneously receives SIEM status from the aforementioned multiple tenants. The SIEM status is visualized via the graphical user interface of the SIEM management application, which is shown on a display that is communicably connected to the SIEM provider server. The SIEM status is filtered based at least partially on user input received via the graphical user interface. The filtered SIEM status is visualized via the graphical user interface. It is decided to update at least one of the multiple clients hosted by the subset of the multiple tenants, at least partially, based on the filtered SIEM status. At least partially, based on the above decision, an update alert is generated, The update alert is sent to the subset of the multiple tenants, At least partially, based on the update alert, the update of at least one client, A system that enhances network security for the subset of tenants by updating at least one of the clients.
16. The system according to claim 15, wherein the memory is further configured to store a plurality of rules associated with the deployment requirements for each of the plurality of tenants, and when executed by the processor, the SIEM management application causes the processor to further generate the update alerts based at least in part on at least one of the plurality of rules associated with the subset of the plurality of tenants.
17. The system according to claim 16, wherein, when executed by the processor, the SIEM management application further causes the processor to correlate the plurality of rules into a plurality of playbooks, at least in part, based on the deployment needs for each of the plurality of tenants.
18. The system according to claim 17, wherein the graphical user interface includes a playbook widget, the decision of the at least one client is further based on user interaction with the playbook widget via the graphical user interface, and the generation of the update alert is at least partially based on at least one playbook among the plurality of playbooks associated with the subset of the plurality of tenants.
Citation Information
Patent Citations
System and method for classifying security events as targeted attacks
JP2017530479A
Correlation-Driven Threat Assessment and Remediation
JP2020521383A
Enterprise Cyber Security Risk Management and Resource Planning
JP2020524870A
Mobile application for an information technology (IT) and security operations application
US20210117251A1
Information management system
WO2018134865A1