Anomaly Detection Rule Conversion for Richer Threat Characterization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing anomaly detection computing programs are limited by their format, unable to detect anomalies in certain computing applications and unable to determine anomaly characteristics, and lack interfaces to display these characteristics in various configurations.
Innovation Solution
Transforming anomaly detection computing programs from a sigma format to a wazuh format, enabling monitoring of computing applications for anomalies and generating detailed anomaly characteristics data sets, including cybersecurity threat level and attack tactic data, displayed through specialized interfaces.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If anomaly detection computing programs are kept in a single format (sigma format), then the system structure is simple, but the system cannot detect anomalies in certain computing applications and cannot determine anomaly characteristics
Solution Approach 1:
The patent implements a format transformation system that converts anomaly detection computing programs from sigma format to wazuh format, enabling the system to handle multiple computing application types and detect various anomaly characteristics. The transformation system acts as a universal adapter that maintains backward compatibility while extending functionality to new application domains.
2Loss of information
If the system transforms anomaly detection programs to a new format (wazuh format), then the system can detect anomalies and determine characteristics, but the device complexity increases
Solution Approach 1:
The patent introduces a format transformation system as an intermediary component that bridges sigma format anomaly detection programs and wazuh format processing pipelines. This intermediary preserves the original program logic while translating it into a format that enables comprehensive anomaly characteristic extraction, thereby preventing information loss without requiring complete system redesign.
3Reliability
If the system monitors computing applications using transformed anomaly detection programs, then comprehensive anomaly detection is achieved, but the processing time and computational resources increase
Solution Approach 1:
The patent implements preliminary format transformation of anomaly detection computing programs from sigma to wazuh format before deployment. This advance preparation ensures that the detection programs are optimized for the target processing pipeline, enabling efficient real-time anomaly detection without requiring complex runtime format conversion and reducing processing delays during actual monitoring operations.
Data Source
AI summary
Systems, apparatuses, methods, and computer program products are provided herein. For example, a computer-implemented method may include identifying a first plurality of anomaly detection computing programs. In some embodiments, the computer-implemented method may include transforming the first plurality of anomaly detection computing programs into a second plurality of anomaly detection computing programs. In some embodiments, the computer-implemented method may include monitoring one or more computing applications using the second plurality of anomaly detection computing programs. In some embodiments, the computer-implemented method may include detecting that a first computing application of the one or more computing applications is affected by an anomaly. In some embodiments, the computer-implemented method may include generating an anomaly characteristics data set for the anomaly based at least in part on the anomaly.


