EDR Tenant IOA Rule Synchronization With Difference Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Manually transferring indicators-of-attack (IOA) rules across multiple tenants of an Endpoint Detection and Response (EDR) tools can result in errors, leading to false or misleading security alerts.
Innovation Solution
A computing system is configured to synchronize and manage IOA rules across multiple tenants by performing a difference operation between source and destination tenants, generating a user interface to indicate common, updated, and missing rules, and allowing automatic or manual updates based on these differences.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If IOA rules are manually transferred across multiple tenants of an EDR tool, then the rules can be moved between tenants, but errors occur in the transferred rules leading to false or misleading security alerts
Solution Approach 1:
The patent implements automated copying of IOA rules from source tenant to destination tenant using a computing system that retrieves, compares, and transfers rules electronically. This eliminates manual copying errors while maintaining rule integrity through systematic data retrieval and transfer processes.
Solution Approach 2:
The system performs a difference operation between source and destination rules to generate feedback information about common rules, updated rules, and missing rules. This feedback mechanism allows verification of rule transfer accuracy and enables corrective actions before false alerts occur.
2Reliability
If automated synchronization of IOA rules is implemented across tenants, then transfer accuracy improves, but system complexity increases
Solution Approach 1:
The computing system performs multiple functions within a single platform: retrieving rules from source tenants, performing difference operations for comparison, generating user interface data, and facilitating rule updates. This multi-functionality reduces the need for separate specialized systems while maintaining synchronization accuracy.
Solution Approach 2:
The computing system acts as an intermediary between source and destination tenants, managing the complexity of rule synchronization internally. It handles data retrieval, comparison operations, and update coordination, shielding users from underlying system complexity while ensuring accurate rule transfer.
3Device complexity
If manual rule transfer is used, then system complexity remains low, but time consumption increases due to error correction
Solution Approach 1:
The system performs preliminary actions by retrieving and comparing rules before actual transfer occurs. The difference operation identifies common, updated, and missing rules in advance, allowing verification and correction before final synchronization, thus preventing time loss from later error correction.
Solution Approach 2:
The patent replaces manual mechanical rule transfer with automated computing operations. The computing system electronically retrieves, compares, and transfers rules, substituting manual copying and error-prone mechanical processes with efficient automated digital operations that reduce time consumption.
Data Source
AI summary
A computing system is configured to manage and synchronize indicators-of-attack (IOA) rules across multiple tenants of an Endpoint Detection and Response (EDR) tool. The computing system is configured to compare rules between an indicated source tenant and a destination tenant. The computing system may then generate output indicating common rules, updated rules, and missing rules between the source and destination tenants. A user, or the system itself, may update the rules at the destination tenant based on the rules at the source tenant. Such an endpoint security synchronization system avoids problems that may occur with manually transferring IOA rules across multiple tenants of an EDR tool which may result in errors that result in false or misleading security alerts.


