Distributed Audit Tools for Internal Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information security systems are inadequate in monitoring and controlling internal user activities and data access within enterprise computing networks, leaving them vulnerable to malicious internal threats and struggling to comply with regulatory requirements due to complex and unmanageable hierarchical structures.

Innovation Solution

An automated information auditing system that uses an advanced data extraction model and expert correlation system to gather and present relevant data through a distributed audit and response tool network, providing a graphical visualization interface for easy interpretation of security-related queries and incident investigation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If perimeter-based protection technologies are implemented, then external threats are blocked, but internal security monitoring capability deteriorates

Engineering Contradiction:
Improveexternal threat protectionVSAvoidinternal user activity monitoring
Core Design Contradiction:
Object-affected harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The system segments security monitoring into external perimeter protection and internal activity monitoring as separate functional components. Distributed audit tools are deployed across multiple systems to independently collect internal user activity data, while perimeter protection technologies continue to operate at the network boundary. This segmentation allows both external threat blocking and internal monitoring to function simultaneously without interference.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer of distributed audit and response tools that operate between the perimeter protection system and internal user systems. These tools act as mediators that collect and report internal user activities without interfering with external threat blocking, thereby enabling internal monitoring capability while maintaining perimeter security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hierarchical directory structures are used to manage access permissions, then security control is established, but data extraction complexity increases

Engineering Contradiction:
Improveaccess permission controlVSAvoidsecurity information extraction
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the complex hierarchical directory structure into manageable units by deploying distributed audit tools at different levels of the hierarchy. Each tool independently extracts security information from its local context, avoiding the need to traverse the entire hierarchical structure centrally. This reduces extraction complexity while maintaining reliable access permission control through coordinated reporting of segmented data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action by having distributed audit tools extract only the specific security information relevant to their local context rather than attempting to extract and process the entire hierarchical structure. This selective extraction approach reduces complexity while maintaining sufficient security control for each segment of the system.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If manual security auditing is performed, then detailed security analysis is achieved, but time consumption increases

Engineering Contradiction:
Improvesecurity compliance analysisVSAvoidauditing duration
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system implements self-service automation where distributed audit tools automatically collect, extract, and analyze security information from audit targets without requiring manual intervention. The tools autonomously traverse the hierarchical structure, correlate data using programmed templates, and generate compliance reports, thereby achieving detailed security analysis while dramatically reducing auditing time.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-programming correlation templates and data extraction logic into the distributed audit tools before deployment. These pre-configured instructions enable the tools to automatically perform detailed security analysis upon deployment, eliminating the need for time-consuming manual auditing processes while maintaining measurement precision.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If distributed audit tools are deployed across multiple systems, then comprehensive coverage is achieved, but system complexity increases

Engineering Contradiction:
Improveaudit coverage scopeVSAvoiddistributed tool management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements universality by designing distributed audit tools with multi-functional capabilities that can operate across diverse audit targets and environments. Each tool is equipped with universal data extraction logic and correlation templates that adapt to different system contexts, allowing comprehensive coverage while simplifying management through standardized, interchangeable components rather than specialized tools for each system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8572744B2Information security auditing and incident investigation system
Publication Date: 2013.10.29 CROWDSTRIKE
  • US8572744B2 patent drawing
  • US8572744B2 patent drawing
  • US8572744B2 patent drawing

AI summary

An information security auditing and incident investigation method can include applying a correlation template to query different audit targets in an enterprise system to provide a complete result set for the query across different audit targets, receiving audit data provided in response to the query and rendering the audit data to produce an audit report. The applying step can include distributing one or more distributed audit and response tools to each of the targets in the enterprise and communicating with the targets in the enterprise to acquire audit data from each of the targets. The receiving step can include organizing the audit data in a hierarchy, and recursively walking the hierarchy as a directed, cyclic graph noting memberships and paths. Finally, the rendering step can include generating a graphical visualization interface, disposing a real-time object browser within the interface, and further disposing a differential report in the interface.