EDR Tenant IOA Rule Synchronization to Prevent Alert Errors

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manually transferring indicators-of-attack (IOA) rules across multiple tenants of an Endpoint Detection and Response (EDR) tool can result in errors, leading to false or misleading security alerts.

Innovation Solution

A computing system that synchronizes IOA rules by performing a difference operation between source and destination tenants, generating a user interface to indicate common, updated, and missing rules, and allowing automatic or manual updates to minimize errors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If IOA rules are manually transferred across tenants, then the process is simple and direct, but errors occur leading to false or misleading security alerts

Engineering Contradiction:
Improveease of rule transferVSAvoidaccuracy of security alerts
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system creates a copy of the IOA rules from the source tenant and applies it to the destination tenant through automated synchronization. This copying mechanism ensures that the rules are transferred accurately without manual intervention errors, while maintaining the simplicity of the transfer process through automated operations.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system provides feedback by displaying a user interface that indicates common rules, updated rules, and missing rules between source and destination tenants. This feedback mechanism allows users to verify the synchronization status and ensures accuracy by highlighting any discrepancies before finalizing the rule transfer.

Inventive Principle:
Principle #23Feedback

2Reliability

If automated synchronization is implemented, then accuracy and reliability improve, but system complexity increases

Engineering Contradiction:
Improveaccuracy of rule synchronizationVSAvoidcomplexity of synchronization system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The computing system acts as an intermediary between source and destination tenants, managing the synchronization process automatically. This intermediary handles the complex operations of comparing, identifying, and transferring rules, thereby improving accuracy while shielding users from the underlying complexity through a simplified user interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs self-service by automatically comparing rules between tenants, identifying differences, and executing the synchronization without requiring manual intervention. This self-service capability enhances reliability by eliminating human errors while the complexity is managed internally by the automated processes.

Inventive Principle:
Principle #25Self-service

3Productivity

If manual rule transfer is performed, then the process is quick and direct, but errors lead to false security alerts

Engineering Contradiction:
Improvespeed of rule transferVSAvoidprecision of rule application
Core Design Contradiction:
ProductivityVSManufacturing precision

Solution Approach 1:

The system performs preliminary actions by automatically comparing the source and destination rules before transferring them. This preliminary comparison identifies common rules, updated rules, and missing rules, ensuring precision in rule application while maintaining quick transfer speed through automated processing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses automated copying mechanisms to transfer rules from source to destination tenant, ensuring precision by accurately replicating the rules without manual intervention errors. This copying process maintains productivity by executing quickly while guaranteeing precision through automated validation.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20250348605A1Endpoint security synchronization
Publication Date: 2025.11.13 WELLS FARGO BANK NA
  • US20250348605A1 patent drawing
  • US20250348605A1 patent drawing
  • US20250348605A1 patent drawing

AI summary

A computing system is configured to manage and synchronize indicators-of-attack (IOA) rules across multiple tenants of an Endpoint Detection and Response (EDR) tool. The computing system is configured to compare rules between an indicated source tenant and a destination tenant. The computing system may then generate output indicating common rules, updated rules, and missing rules between the source and destination tenants. A user, or the system itself, may update the rules at the destination tenant based on the rules at the source tenant. Such an endpoint security synchronization system avoids problems that may occur with manually transferring IOA rules across multiple tenants of an EDR tool which may result in errors that result in false or misleading security alerts.