Computing Resource Name Correlation for Cybersecurity Root Cause Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity solutions struggle to effectively identify and mitigate software vulnerabilities due to the rapid development and deployment of software, leading to increased business risk and operator burnout, as manual management of complex CI/CD pipelines is inadequate.
Innovation Solution
A method and system for cybersecurity root cause analysis that parses and correlates computing resource names using structured unit formats, normalizes and compares these units, and identifies the root cause of cybersecurity events to facilitate mitigation actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If automated tools are implemented to manage complex CI/CD pipelines, then productivity and accuracy of root cause identification improve, but device complexity increases
Solution Approach 1:
The patent segments computing resource names into structured units (e.g., organization unit, environment unit, resource type unit, identifier unit) that can be independently parsed, compared, and correlated. This segmentation enables automated tools to systematically break down complex resource identification into manageable components, improving root cause identification speed while maintaining manageable system complexity through modular processing.
Solution Approach 2:
The patent introduces structured unit formats as an intermediary layer between raw computing resource names and root cause analysis. By translating diverse naming conventions into a standardized structured unit representation, the system enables automated correlation without requiring direct complex comparisons of raw names, thus improving productivity while abstracting away the complexity of handling multiple naming formats.
2Measurement precision
If manual management of computing resources is used, then device complexity remains low, but measurement precision of root cause identification deteriorates
Solution Approach 1:
The patent transforms computing resource names from unstructured text into structured units with defined parameters (organization, environment, resource type, identifier). This parameterization enables precise automated comparison and correlation, significantly improving root cause identification accuracy. The structured format allows systematic analysis of resource relationships that would be infeasible through manual management.
3Adaptability or versatility
If diverse naming conventions are accommodated, then adaptability improves, but measurement precision deteriorates due to formatting differences
Solution Approach 1:
The patent creates a universal structured unit format that can represent multiple naming conventions and formats. By mapping diverse resource names (from different providers, environments, and organizations) into a common structured representation, the system achieves both adaptability to various naming styles and precision in correlation through standardized comparison of structured units.
Solution Approach 2:
The structured unit format serves as an intermediary that bridges diverse naming conventions. Instead of directly comparing heterogeneous resource names, the system translates them into a standardized intermediate representation, enabling accurate correlation while accommodating various original formats and conventions.
Data Source
AI summary
A system and method for cybersecurity root cause analysis. A method includes parsing a first string into at least one first structured unit based on predetermined structured unit formats. The first string is indicated in cybersecurity data related to a cybersecurity event. Each predetermined structured unit format is defined with respect to at least one substring each having a respective data type. Each first structured unit is compared to a corresponding second structured unit of at least one second structured unit of a second string. Each second structured unit is a portion of text of the second string identified by parsing the second string based on the predetermined structured unit formats. The first string is correlated to the second string based on the comparison. A resource corresponding to the second string is identified. A root cause of the cybersecurity event is determined based on the identified resource.


