Deduplicated Network Location Aggregation for Security Event Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise organizations face challenges in identifying and analyzing large amounts of network data distributed across multiple sources, making it difficult to find valuable insights or detect security threats in a timely and efficient manner, especially with the expansion of distributed computing systems.
Innovation Solution
A computer-implemented method and system that aggregates and deduplicates lists of network locations from multiple sources, allowing for the identification of unique network locations and the detection of notable events by searching network data or machine data for these locations, using a deduplicated list to flag significant security events.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data analysts attempt to identify and analyze large amounts of network data from multiple sources, then valuable insights and security threats can be detected, but the complexity and difficulty of handling and analyzing the data increases significantly
Solution Approach 1:
The patent segments the large network data into discrete events with specific fields, organizing them into a structured format that can be efficiently processed. Events are divided into manageable units with defined schemas, allowing the system to handle large volumes of data without being overwhelmed by complexity.
Solution Approach 2:
The patent introduces an intermediary processing layer between raw network data and analysis tools. This layer standardizes data from multiple sources into a common event format, acting as a mediator that simplifies subsequent analysis operations while maintaining the integrity and security value of the original data.
2Reliability
If network data from multiple sources is collected and analyzed, then comprehensive security monitoring is achieved, but the time required to process and identify notable events increases
Solution Approach 1:
The patent performs preliminary actions by pre-defining event schemas, field structures, and search criteria before actual security analysis begins. Data is pre-processed and organized into standardized event formats with predefined fields, so that when security threats need to be detected, the system can quickly search predefined structures rather than processing raw unstructured data from multiple sources.
3Reliability
If distributed computing systems are expanded to handle more network data, then security monitoring capability is improved, but the difficulty of detecting and measuring security events increases
Solution Approach 1:
The patent changes parameters by transforming diverse network data from distributed systems into a standardized event format with consistent fields and schemas. This parameter standardization allows the system to maintain improved security monitoring capability across expanded distributed computing systems while reducing detection difficulty through uniform data structures and predictable event formats.
Data Source
AI summary
Systems and methods are provided for identifying network addresses and/or IDs of a deduplicated list among network data, machine data, and/or events derived from network data and/or machine data, and for identifying notable events by searching for the presence of network addresses and/or network IDs that are deduplicated across lists received from multiple external sources. One method includes receiving a plurality of lists of network locations, wherein each list is received from over a network, wherein each of the network locations includes a domain name or an IP address, and wherein at least two of the plurality of lists each include a same network location; aggregating the plurality of lists of network locations into a deduplicated list of unique network locations; and searching network data or machine data for a network location included in the deduplicated list of unique network locations.


