Advanced Intelligence Engine for Cross-System Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional SEM solutions are limited in scope and complexity, failing to detect sophisticated intrusions and insider threats due to their reliance on pre-filtered logs and pattern-based correlation, which limits their analysis capabilities and misses important data patterns across multiple systems and time periods.
Innovation Solution
A single platform that processes and analyzes structured data across multiple systems and devices, using rule blocks and linking relationships to detect events in real-time, accommodating out-of-order data processing and mitigating false alarms through historical adjustments and fine-tuning.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional SEM solutions use pre-filtered logs and pattern-based correlation, then device complexity is reduced and ease of operation is improved, but measurement precision and reliability of intrusion detection deteriorate
Solution Approach 1:
The system segments the detection process into multiple rule blocks (first rule block, second rule block, etc.) that can independently evaluate different aspects of log data. Each rule block can be configured with specific conditions and actions, allowing complex detection logic to be divided into manageable, independently testable units that improve both precision and maintainability
Solution Approach 2:
The system implements dynamic rule evaluation where rule blocks can be added, removed, or modified without reconfiguring the entire system. The processing engine dynamically evaluates log data against multiple rule blocks and combines results, allowing the detection system to adapt to new threats while maintaining operational simplicity
2Reliability
If traditional SEM solutions process logs against multiple rules, then detection capability is improved, but processing time and loss of time increase
Solution Approach 1:
The system performs preliminary actions by pre-configuring multiple rule blocks with specific detection conditions before log data arrives. The processing engine is pre-prepared to evaluate data against these rules, and can immediately begin detection without sequential processing delays, improving both reliability and reducing processing time
Solution Approach 2:
The system maintains continuous detection by having the processing engine evaluate log data against multiple rule blocks in parallel or overlapping sequences. Rather than completing one rule evaluation before starting the next, the system maintains continuous analysis flow, ensuring no detection gaps while minimizing processing time
3Device complexity
If traditional SEM solutions are limited to pre-designated events, then device complexity is reduced, but adaptability and versatility deteriorate
Solution Approach 1:
The system implements universality by designing rule blocks that can handle multiple types of log data and detection scenarios through a common evaluation framework. The same rule block structure can detect different event types by configuring different conditions and criteria, allowing the system to analyze various data sources and threat types without increasing fundamental system complexity
Solution Approach 2:
The system achieves adaptability through dynamic rule configuration where new rule blocks can be added to detect emerging threats. The processing engine dynamically incorporates new rules without requiring system redesign, enabling the system to adapt to new attack vectors, data formats, and analysis requirements while maintaining a consistent underlying architecture
Data Source
AI summary
An advanced intelligence engine (AIE) for use in identifying what may be complex events or developments on one or more data platforms or networks from various types of structured or normalized data generated by one or more disparate data sources. The AIE may conduct one or more types of quantitative, correlative, behavioral and corroborative analyses to detect events from what may otherwise be considered unimportant or non-relevant information spanning one or more time periods. Events generated by the AIE may be passed to an event manager to determine whether further action is required such as reporting, remediation, and the like.


