Anomaly Detection Rule Conversion for Richer Threat Characterization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing anomaly detection computing programs are limited by their format, unable to detect anomalies in certain computing applications and unable to determine anomaly characteristics, and lack interfaces to display these characteristics in various configurations.

Innovation Solution

Transforming anomaly detection computing programs from a sigma format to a wazuh format, enabling monitoring of computing applications for anomalies and generating detailed anomaly characteristics data sets, including cybersecurity threat level and attack tactic data, displayed through specialized interfaces.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If anomaly detection computing programs are kept in a single format (sigma format), then the system structure is simple, but the system cannot detect anomalies in certain computing applications and cannot determine anomaly characteristics

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidsystem structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a format transformation system that converts anomaly detection computing programs from sigma format to wazuh format, enabling the system to handle multiple computing application types and detect various anomaly characteristics. The transformation system acts as a universal adapter that maintains backward compatibility while extending functionality to new application domains.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Loss of information

If the system transforms anomaly detection programs to a new format (wazuh format), then the system can detect anomalies and determine characteristics, but the device complexity increases

Engineering Contradiction:
Improveanomaly characteristics informationVSAvoidtransformation system
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent introduces a format transformation system as an intermediary component that bridges sigma format anomaly detection programs and wazuh format processing pipelines. This intermediary preserves the original program logic while translating it into a format that enables comprehensive anomaly characteristic extraction, thereby preventing information loss without requiring complete system redesign.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the system monitors computing applications using transformed anomaly detection programs, then comprehensive anomaly detection is achieved, but the processing time and computational resources increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary format transformation of anomaly detection computing programs from sigma to wazuh format before deployment. This advance preparation ensures that the detection programs are optimized for the target processing pipeline, enabling efficient real-time anomaly detection without requiring complex runtime format conversion and reducing processing delays during actual monitoring operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12568100B2Systems, apparatuses, methods, and computer program products for anomaly detection computing programs
Publication Date: 2026.03.03 HONEYWELL INTERNATIONAL INC
  • US12568100B2 patent drawing
  • US12568100B2 patent drawing
  • US12568100B2 patent drawing

AI summary

Systems, apparatuses, methods, and computer program products are provided herein. For example, a computer-implemented method may include identifying a first plurality of anomaly detection computing programs. In some embodiments, the computer-implemented method may include transforming the first plurality of anomaly detection computing programs into a second plurality of anomaly detection computing programs. In some embodiments, the computer-implemented method may include monitoring one or more computing applications using the second plurality of anomaly detection computing programs. In some embodiments, the computer-implemented method may include detecting that a first computing application of the one or more computing applications is affected by an anomaly. In some embodiments, the computer-implemented method may include generating an anomaly characteristics data set for the anomaly based at least in part on the anomaly.