Card System Framework for Security Investigation Data Organization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security analysts face challenges in organizing, documenting, and sharing large amounts of data related to security alerts across multiple sources, leading to inefficiencies in investigation and data reuse.

Innovation Solution

A card system framework that organizes data in a reusable card format, allowing users to interactively request details, document investigation history, and share findings, with content tiles that can be reused across different contexts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If security analysts manually organize and document security alert data from multiple sources, then investigation completeness can be achieved, but time consumption and operational complexity increase significantly

Engineering Contradiction:
Improveinvestigation completenessVSAvoidtime consumption
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent segments security investigation data into discrete, standardized cards representing different data types (alerts, indicators, entities, etc.). Each card is an independent unit that can be individually managed, retrieved, and reused, eliminating the need to manually organize entire investigation datasets while maintaining completeness through systematic categorization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary organization and structuring of security data into standardized card formats before investigations begin. By pre-defining card templates and data relationships, the system prepares the investigative framework in advance, allowing analysts to quickly assemble complete investigations without manual organization during the actual investigation process.

Inventive Principle:
Principle #10Preliminary action

2Loss of information

If security analysts access multiple different data sources to find relevant data, then data comprehensiveness is improved, but device complexity and operational difficulty increase

Engineering Contradiction:
Improvedata comprehensivenessVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent creates a universal card-based framework that can represent multiple types of security data (alerts, indicators, entities, investigations) using a single standardized structure. This multi-functional card system eliminates the need for separate data source interfaces while maintaining comprehensive data representation through type-specific card templates.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The card system acts as an intermediary layer between multiple data sources and the analyst. Instead of directly accessing complex multiple data sources, analysts interact with simplified card representations that mediate the complexity by standardizing data from various sources into a unified, manageable format.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of information

If security investigation data and history are not automatically documented, then system simplicity is maintained, but information loss and inability to share findings occur

Engineering Contradiction:
Improvedocumentation completenessVSAvoidautomation complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The card system enables automatic self-documentation of security investigations. As analysts assemble cards representing different data elements and relationships, the system automatically captures the investigation structure, associations, and history without requiring separate documentation actions. The card assembly process itself generates the documentation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system provides automatic feedback by tracking and recording card associations and investigation structures. As analysts manipulate cards to build investigations, the system continuously updates and stores the investigation history and relationships, providing real-time documentation feedback without increasing operational complexity for the analyst.

Inventive Principle:
Principle #23Feedback

4Productivity

If data retrieval and analysis are performed without reusable formats, then flexibility is maintained, but productivity and resource efficiency decrease

Engineering Contradiction:
Improveinvestigation efficiencyVSAvoiddata format flexibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent implements reusable card templates that can be copied and reused across multiple investigations. Once a card representing a specific alert, indicator, or entity relationship is created, it can be copied to new investigations, eliminating redundant data retrieval and analysis while maintaining adaptability through template customization options.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The card system provides dynamic flexibility where card templates can be adapted and customized for different investigation contexts. While maintaining a standardized reusable structure, the system allows analysts to modify card contents and relationships dynamically to suit specific investigation needs, balancing reusability with adaptability.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10599839B2Security investigations using a card system framework
Publication Date: 2020.03.24 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10599839B2 patent drawing
  • US10599839B2 patent drawing
  • US10599839B2 patent drawing

AI summary

Examples disclosed herein relate to security investigations using a card system framework. Some of the examples enable presenting a first card on a user interface, the first card comprising a first content tile that describes a first security alert object that is associated with a first plurality of content items, the first plurality of content items comprising at least one of: a source host identifier, an Internet Protocol (IP) address, a severity level, a confidence level, an alert status, a user identifier, an alert type, an attack stage, a port, a protocol, and a geographical location; and in response to an indication that a first content item among the first plurality of content item is requested about the first security alert object, presenting a second card on the user interface, the second card comprising a second content tile that describes a second entity object that is associated with a second plurality of content items.