A data management platform for security incidents
The integration of WAF with an SQL database for real-time data management addresses data management challenges in WAF systems, ensuring secure, timely, and accurate analysis of cybersecurity incidents.
Patent Information
- Application Number
- PCT/TR2025/050139
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-12-26
AI Technical Summary
Existing web application firewall (WAF) systems face challenges in managing, storing, and analyzing collected data, leading to data loss, delays, inaccurate analysis, and increased error risk due to manual intervention, especially in log file-based monitoring systems.
A data management platform integrating WAF with an SQL database for real-time data collection, transfer, and storage, eliminating manual processes and ensuring data integrity and faster analysis through a data transfer and storage module.
Enables secure, real-time data recording and analysis, reducing errors and delays, and facilitating quick response to cybersecurity threats by maintaining data integrity and enabling efficient reporting.
Smart Images

Figure TR2025050139_26122025_PF_FP_ABST
Abstract
Description
[0001] A DATA MANAGEMENT PLATFORM FOR SECURITY INCIDENTS
[0002] Technological Field:
[0003] This invention is related to a data management platform for security incidents, which may be adopted by large-scale enterprises, government agencies, financial institutions and healthcare providers and may be used in security operations centers to meet the needs of institutions and organizations in cybersecurity, network management and data analytics.
[0004] State of the Art:
[0005] Today, web applications are becoming vulnerable to cyberattacks, and therefore security measures are critical. Web Application Firewalls (WAF), in this context, are a widely used technology to protect web applications. By analyzing the incoming traffic, WAFs detect and block malicious requests, and record attack data during this process. However, the existing systems face several challenges in managing, storing, and analyzing the collected data. Conventional WAF solutions often focus only on attack detection and do not offer adequate mechanisms to securely store the collected data in a central data repository. This leads to problems such as data loss, delays, and inaccurate analysis results. In addition, the existing systems often require manual intervention in data transfer processes, which increases the risk of errors and increases the intervention time to the incidents.
[0006] The patent application No. US9432335B1 describes "Cloud-Based Multi-Layered Security Architecture with Firewalled Virtual Network Partitions". The invention includes a virtual network, a web application firewall (WAF) portion to receive network traffic for one or more other portions of the virtual network; a first firewall connected to the WAF; web server portion, connected to the first firewall, to receive web traffic; a second firewall connected to the web server portion; an application server portion, connected to the second firewall, to perform application services for one or more servers of the web server portion; a third firewall connected to the application server portion; a database server portion connected to the third firewall; a fourth firewall connected to the database server portion, the application server portion, and the web server portion; an active directory portion, connected to the fourth firewall, to perform authentication of one or more access requests associated with the virtual network; and a utility portion, connected to the first firewall and the fourth firewall.
[0007] The patent application no. CN117971866A describes "WAF Rule Engine Optimization Method and Device Based on Lexical Analysis". The invention describes a WAF rule engine optimization method based on lexical analysis. The method includes the following steps: decoding a user claim to obtain a user input parameter value; converting the parameter value entered by the user into a token string; and performing lexical analysis on the token string and determining whether the user request is a malicious one based on the result of the lexical analysis. Thanks to the WAF rule engine optimization based on lexical analysis, the false alarm rate of the WAF is reduced at a low cost, and only lexical analysis is required instead of complete grammatical analysis, so the workload is small and the analysis difficulty is low.
[0008] The above describes web application firewalls (WAFs) with various designs. These applications prevent and record various attacks. This recorded data is transmitted to log file-based monitoring systems and manual data recording methods. These data are usually recorded in log files, then processed manually. These manual processes are time-consuming and error-prone, making it difficult to properly analyze and securely store data. In addition, there are manual data entry options provided by Excel or simple database applications. In such manual processes, the possibility of human error in the recorded data is high and analysis and reporting may be disrupted.
[0009] Definition of the Invention:
[0010] The present invention is a data management platform for security incidents capable of overcoming the disadvantages mentioned above, and characterized by integrated operation of WAF and SQL database, real-time analysis and storage of data, being very fast compared to primitive methods, providing easy reporting, being low cost, and easy to use.
[0011] The invention is a platform that enables real-time detection and recording of attacks on web applications and the secure analysis and reporting of this data. Thanks to the integration of WAF and SQL database, attack data is continuously collected and transferred securely with the data transfer module, thus eliminating errors and delays that may occur in manual processes. Storing data in a central SQL database not only maintains data integrity, but also speeds up analysis and reporting. Furthermore, the cost-effective and user-friendly nature of this system makes it viable even for small and medium-sized businesses. Thanks to the storage module, data can be stored in an orderly and organized manner and analyzed in the long term and contribute to the creation of an effective defense strategy against security vulnerabilities. In this way, institutions can take quick and proactive measures against cyberattacks and increase data security.
[0012] Description of the Drawings:
[0013] The invention will be described with reference to the accompanying figures, so that the features of the invention will be more clearly understood and appreciated, however it is not intended to limit the invention to these particular embodiments. On the contrary, it is intended all alternatives, modifications and equivalences that may be included in the field of the invention as defined by the accompanying claims are within the scope. It should be understood that the details shown are for the sole purpose of illustrating preferred embodiments of the present invention and are intended to provide the most useful and easily understandable description of both the embodiment of the methods and the rules and conceptual features of the invention. In the drawings;
[0014] Figure 1 is a schematic view of the components of the system.
[0015] The figures which will help understand this invention are numbered as indicated in the accompanying drawing and are given below with their names.
[0016] Description of the References:
[0017] 1. WAF
[0018] 2. SQL Database
[0019] 3. Data Transfer Module
[0020] 4. Storage Module
[0021] Description of the Invention: The invention consists of WAF (1), which detects attacks by monitoring web applications and records these attacks with timestamps and types, SQL database (2) where data collected by WAF (1) is organized, data transfer module (3) where the data collected by the WAF (1) is securely transmitted in real time to the SQL database (2) via a data transfer interface where the format and transfer protocols are managed, and storage module (4) where data organized in SQL database (2) is stored for analysis and reporting.
[0022] Detailed Description of the Invention:
[0023] The constituent parts of the invention are essentially: WAF (1), SQL database (2), data transfer module (3), and storage module (4).
[0024] The present invention is a system that detects attacks by monitoring web applications and enables data on these attacks to be securely recorded, analyzed, and reported. The system includes the WAF (1) (Web Application Firewall) component, which primarily detects potential threats and attacks on web applications. WAF (1) captures all types of cyberattacks on web applications, along with timestamps and attack types. This attack data is transferred into SQL database (2), the core data management element of the system, to be stored securely and consistently in a central data repository. This attack data collected by WAF (1) is transmitted to SQL database (2) via the data transfer module (3) for secure and efficient transportation and organization of data. This module (3) manages the format and transfer protocols of the collected data, enabling the data to be transferred in real-time and securely. This eliminates delays and errors that arise in manual processes, providing a quick solution for timely analysis of data. Within SQL Database (2), incoming data is organized via a storage module (4) and stored for analysis. This module (4) enables the structuring and organization of the collected data so that the data can be easily integrated into the analysis and reporting processes. The storage module (4) preserves data integrity, making it possible to store data for long periods of time and report it when necessary. The integrity of this system enables attacks to be detected, monitored, and managed more quickly and effectively, allowing institutions to respond more quickly and efficiently to cybersecurity risks.
Claims
CLAIMS1 . A data management platform for security incidents, characterized in that it comprises: - a WAF (1) which detects attacks by monitoring web applications and records these attacks with timestamps and types thereof,- a SQL database (2) where the data collected by WAF (1) is organized,- a data transfer module (3) where data collected by WAF (1) is securely transmitted in real time to SQL database (2) via a data transfer interface where the format and transfer protocols are managed, and- a storage module (4) in which the data organized in the SQL database(2) are stored for the analyzing and reporting processes.
Citation Information
Patent Citations
Web traffic logging system and method for detecting web hacking in real time
CN109845228A
Web application firewall system architecture
CN112134844A
Whole-flow processing system and method based on network security alarm event
CN117614717A