Automated EDR Data Integration into Open XDR Framework
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing open extended detection and response (XDR) frameworks face challenges in automatically integrating endpoint detection and response (EDR) data due to heterogeneity among EDR tools, noisy and low-fidelity alerts, and the difficulty in correlating alerts across multiple tools, leading to inefficiencies in incident identification and investigation.
Innovation Solution
A system and method for automated EDR data integration into an Open XDR framework, involving data ingestion, normalization using a unified EDR data model, enrichment with contextual information, and alert correlation, leveraging machine learning to improve alert fidelity and reduce noise, thereby enhancing incident investigation efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Area of stationary object
If EDR data from multiple heterogeneous tools is integrated into Open XDR framework, then comprehensive security monitoring coverage is improved, but data integration complexity increases due to different monitoring mechanisms and data fields
Solution Approach 1:
The patent employs an intermediary normalization layer that sits between heterogeneous EDR tools and the Open XDR framework. This normalization layer translates and standardizes data from different EDR tools into a common schema, enabling comprehensive multi-tool integration without directly coupling the heterogeneous data sources to the framework core, thus reducing integration complexity while maintaining broad coverage
Solution Approach 2:
The patent creates a universal data model and normalization schema that can accommodate multiple EDR tool types and formats. This universal interface allows the system to integrate diverse security tools through a single standardized mechanism, improving coverage while avoiding the need for separate integration paths for each tool type
2Quantity of substance
If alert deduplication mechanism is applied in EDR tools, then alert volume is reduced, but alert fidelity deteriorates due to loss of contextual information and timeliness
Solution Approach 1:
Instead of reducing alerts in the traditional dimension (merging identical alerts), the patent adds a new dimension by enriching each alert with contextual information from multiple EDR tools and time-series data. This dimensional expansion allows the system to maintain high alert volumes with full fidelity while providing analysts with additional context that helps prioritize and understand alerts without losing important information
Solution Approach 2:
The patent implements feedback loops where alert correlation results and contextual information are continuously fed back into the alert generation process. This feedback mechanism allows the system to refine alert fidelity over time by learning from patterns in the data, ensuring that deduplication does not permanently degrade alert quality but rather improves it through iterative analysis
3Productivity
If alerts from different EDR tools are correlated automatically, then incident identification efficiency is improved, but correlation difficulty increases due to independent alert generation and lack of contextual information
Solution Approach 1:
The patent performs preliminary actions by enriching each alert with contextual information and normalizing data structures before correlation takes place. This pre-processing step includes adding metadata, standardizing formats, and pre-computing relevant features, which significantly reduces the difficulty of subsequent correlation operations while maintaining high incident identification efficiency
Solution Approach 2:
The patent transforms alerts by changing their parameters through normalization and enrichment. By converting diverse alert formats into a unified schema and adding contextual parameters, the system makes correlated alerts more homogeneous and easier to analyze automatically, reducing correlation difficulty while improving incident detection productivity
Data Source
AI summary
A new approach is proposed to support integration of EDR data from a plurality of EDR tools/sources into an Open XDR framework in an automated manner. First, EDR data generated by each of the plurality of EDR tools covering a plurality of assets is ingested into the Open XDR framework. The ingested EDR data is then normalized through a unified EDR data model. The normalized EDR data is further enriched with one or more new data fields to better correlate the EDR normalized data from the plurality of EDR tools. A plurality of alerts are then generated from the normalized and enriched data along one or more alert pathways to improve fidelity of the plurality of alerts. The plurality of alerts are correlated with the contextual information of the plurality of assets as well as information from other data sources to identify a set of incidents of suspicious activities.


