Card System Framework for Security Investigation Data Organization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Security analysts face challenges in organizing, documenting, and sharing large amounts of data related to security alerts across multiple sources, leading to inefficiencies in investigation and data reuse.
Innovation Solution
A card system framework that organizes data in a reusable card format, allowing users to interactively request details, document investigation history, and share findings, with content tiles that can be reused across different contexts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If security analysts manually organize and document security alert data from multiple sources, then investigation completeness can be achieved, but time consumption and operational complexity increase significantly
Solution Approach 1:
The patent segments security investigation data into discrete, standardized cards representing different data types (alerts, indicators, entities, etc.). Each card is an independent unit that can be individually managed, retrieved, and reused, eliminating the need to manually organize entire investigation datasets while maintaining completeness through systematic categorization.
Solution Approach 2:
The system performs preliminary organization and structuring of security data into standardized card formats before investigations begin. By pre-defining card templates and data relationships, the system prepares the investigative framework in advance, allowing analysts to quickly assemble complete investigations without manual organization during the actual investigation process.
2Loss of information
If security analysts access multiple different data sources to find relevant data, then data comprehensiveness is improved, but device complexity and operational difficulty increase
Solution Approach 1:
The patent creates a universal card-based framework that can represent multiple types of security data (alerts, indicators, entities, investigations) using a single standardized structure. This multi-functional card system eliminates the need for separate data source interfaces while maintaining comprehensive data representation through type-specific card templates.
Solution Approach 2:
The card system acts as an intermediary layer between multiple data sources and the analyst. Instead of directly accessing complex multiple data sources, analysts interact with simplified card representations that mediate the complexity by standardizing data from various sources into a unified, manageable format.
3Loss of information
If security investigation data and history are not automatically documented, then system simplicity is maintained, but information loss and inability to share findings occur
Solution Approach 1:
The card system enables automatic self-documentation of security investigations. As analysts assemble cards representing different data elements and relationships, the system automatically captures the investigation structure, associations, and history without requiring separate documentation actions. The card assembly process itself generates the documentation.
Solution Approach 2:
The system provides automatic feedback by tracking and recording card associations and investigation structures. As analysts manipulate cards to build investigations, the system continuously updates and stores the investigation history and relationships, providing real-time documentation feedback without increasing operational complexity for the analyst.
4Productivity
If data retrieval and analysis are performed without reusable formats, then flexibility is maintained, but productivity and resource efficiency decrease
Solution Approach 1:
The patent implements reusable card templates that can be copied and reused across multiple investigations. Once a card representing a specific alert, indicator, or entity relationship is created, it can be copied to new investigations, eliminating redundant data retrieval and analysis while maintaining adaptability through template customization options.
Solution Approach 2:
The card system provides dynamic flexibility where card templates can be adapted and customized for different investigation contexts. While maintaining a standardized reusable structure, the system allows analysts to modify card contents and relationships dynamically to suit specific investigation needs, balancing reusability with adaptability.
Data Source
AI summary
Examples disclosed herein relate to security investigations using a card system framework. Some of the examples enable presenting a first card on a user interface, the first card comprising a first content tile that describes a first security alert object that is associated with a first plurality of content items, the first plurality of content items comprising at least one of: a source host identifier, an Internet Protocol (IP) address, a severity level, a confidence level, an alert status, a user identifier, an alert type, an attack stage, a port, a protocol, and a geographical location; and in response to an indication that a first content item among the first plurality of content item is requested about the first security alert object, presenting a second card on the user interface, the second card comprising a second content tile that describes a second entity object that is associated with a second plurality of content items.


