Automated EDR Data Integration into Open XDR Framework

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing open extended detection and response (XDR) frameworks face challenges in automatically integrating endpoint detection and response (EDR) data due to heterogeneity among EDR tools, noisy and low-fidelity alerts, and the difficulty in correlating alerts across multiple tools, leading to inefficiencies in incident identification and investigation.

Innovation Solution

A system and method for automated EDR data integration into an Open XDR framework, involving data ingestion, normalization using a unified EDR data model, enrichment with contextual information, and alert correlation, leveraging machine learning to improve alert fidelity and reduce noise, thereby enhancing incident investigation efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Area of stationary object

If EDR data from multiple heterogeneous tools is integrated into Open XDR framework, then comprehensive security monitoring coverage is improved, but data integration complexity increases due to different monitoring mechanisms and data fields

Engineering Contradiction:
Improvesecurity monitoring coverageVSAvoiddata integration complexity
Core Design Contradiction:
Area of stationary objectVSDevice complexity

Solution Approach 1:

The patent employs an intermediary normalization layer that sits between heterogeneous EDR tools and the Open XDR framework. This normalization layer translates and standardizes data from different EDR tools into a common schema, enabling comprehensive multi-tool integration without directly coupling the heterogeneous data sources to the framework core, thus reducing integration complexity while maintaining broad coverage

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal data model and normalization schema that can accommodate multiple EDR tool types and formats. This universal interface allows the system to integrate diverse security tools through a single standardized mechanism, improving coverage while avoiding the need for separate integration paths for each tool type

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Quantity of substance

If alert deduplication mechanism is applied in EDR tools, then alert volume is reduced, but alert fidelity deteriorates due to loss of contextual information and timeliness

Engineering Contradiction:
Improvealert volumeVSAvoidalert fidelity
Core Design Contradiction:
Quantity of substanceVSMeasurement precision

Solution Approach 1:

Instead of reducing alerts in the traditional dimension (merging identical alerts), the patent adds a new dimension by enriching each alert with contextual information from multiple EDR tools and time-series data. This dimensional expansion allows the system to maintain high alert volumes with full fidelity while providing analysts with additional context that helps prioritize and understand alerts without losing important information

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent implements feedback loops where alert correlation results and contextual information are continuously fed back into the alert generation process. This feedback mechanism allows the system to refine alert fidelity over time by learning from patterns in the data, ensuring that deduplication does not permanently degrade alert quality but rather improves it through iterative analysis

Inventive Principle:
Principle #23Feedback

3Productivity

If alerts from different EDR tools are correlated automatically, then incident identification efficiency is improved, but correlation difficulty increases due to independent alert generation and lack of contextual information

Engineering Contradiction:
Improveincident identification efficiencyVSAvoidcorrelation difficulty
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent performs preliminary actions by enriching each alert with contextual information and normalizing data structures before correlation takes place. This pre-processing step includes adding metadata, standardizing formats, and pre-computing relevant features, which significantly reduces the difficulty of subsequent correlation operations while maintaining high incident identification efficiency

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent transforms alerts by changing their parameters through normalization and enrichment. By converting diverse alert formats into a unified schema and adding contextual parameters, the system makes correlated alerts more homogeneous and easier to analyze automatically, reducing correlation difficulty while improving incident detection productivity

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20230252134A1System and method for automated integration of endpoint detection and response (EDR) data to open extended detection and response (XDR) framework
Publication Date: 2023.08.10 STELLAR CYBER INC
  • US20230252134A1 patent drawing
  • US20230252134A1 patent drawing
  • US20230252134A1 patent drawing

AI summary

A new approach is proposed to support integration of EDR data from a plurality of EDR tools/sources into an Open XDR framework in an automated manner. First, EDR data generated by each of the plurality of EDR tools covering a plurality of assets is ingested into the Open XDR framework. The ingested EDR data is then normalized through a unified EDR data model. The normalized EDR data is further enriched with one or more new data fields to better correlate the EDR normalized data from the plurality of EDR tools. A plurality of alerts are then generated from the normalized and enriched data along one or more alert pathways to improve fidelity of the plurality of alerts. The plurality of alerts are correlated with the contextual information of the plurality of assets as well as information from other data sources to identify a set of incidents of suspicious activities.