EDR Tenant IOA Rule Synchronization With Difference Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manually transferring indicators-of-attack (IOA) rules across multiple tenants of an Endpoint Detection and Response (EDR) tools can result in errors, leading to false or misleading security alerts.

Innovation Solution

A computing system is configured to synchronize and manage IOA rules across multiple tenants by performing a difference operation between source and destination tenants, generating a user interface to indicate common, updated, and missing rules, and allowing automatic or manual updates based on these differences.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If IOA rules are manually transferred across multiple tenants of an EDR tool, then the rules can be moved between tenants, but errors occur in the transferred rules leading to false or misleading security alerts

Engineering Contradiction:
ImproveManual rule transfer capabilityVSAvoidAccuracy of transferred rules
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements automated copying of IOA rules from source tenant to destination tenant using a computing system that retrieves, compares, and transfers rules electronically. This eliminates manual copying errors while maintaining rule integrity through systematic data retrieval and transfer processes.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs a difference operation between source and destination rules to generate feedback information about common rules, updated rules, and missing rules. This feedback mechanism allows verification of rule transfer accuracy and enables corrective actions before false alerts occur.

Inventive Principle:
Principle #23Feedback

2Reliability

If automated synchronization of IOA rules is implemented across tenants, then transfer accuracy improves, but system complexity increases

Engineering Contradiction:
ImproveAccuracy of rule synchronizationVSAvoidComputing system architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The computing system performs multiple functions within a single platform: retrieving rules from source tenants, performing difference operations for comparison, generating user interface data, and facilitating rule updates. This multi-functionality reduces the need for separate specialized systems while maintaining synchronization accuracy.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The computing system acts as an intermediary between source and destination tenants, managing the complexity of rule synchronization internally. It handles data retrieval, comparison operations, and update coordination, shielding users from underlying system complexity while ensuring accurate rule transfer.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If manual rule transfer is used, then system complexity remains low, but time consumption increases due to error correction

Engineering Contradiction:
ImproveSynchronization system structureVSAvoidTime for rule transfer and error correction
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by retrieving and comparing rules before actual transfer occurs. The difference operation identifies common, updated, and missing rules in advance, allowing verification and correction before final synchronization, thus preventing time loss from later error correction.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual mechanical rule transfer with automated computing operations. The computing system electronically retrieves, compares, and transfers rules, substituting manual copying and error-prone mechanical processes with efficient automated digital operations that reduce time consumption.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12386986B1Endpoint security synchronization
Publication Date: 2025.08.12 WELLS FARGO BANK NA
  • US12386986B1 patent drawing
  • US12386986B1 patent drawing
  • US12386986B1 patent drawing

AI summary

A computing system is configured to manage and synchronize indicators-of-attack (IOA) rules across multiple tenants of an Endpoint Detection and Response (EDR) tool. The computing system is configured to compare rules between an indicated source tenant and a destination tenant. The computing system may then generate output indicating common rules, updated rules, and missing rules between the source and destination tenants. A user, or the system itself, may update the rules at the destination tenant based on the rules at the source tenant. Such an endpoint security synchronization system avoids problems that may occur with manually transferring IOA rules across multiple tenants of an EDR tool which may result in errors that result in false or misleading security alerts.