Event Clustering for Managed Infrastructure Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for managing and securing managed infrastructure face challenges in efficiently clustering and securing events, particularly in identifying breaches, intrusions, and propagations, due to the complexity of network traffic and the need for continuous updates in rule-based approaches, which are not scalable.
Innovation Solution
A system that includes an extraction engine to cluster events based on common characteristics, using graph topology and entropy analysis, and a collaborative interface for security management, allowing for physical changes in the infrastructure to maintain security, including access control, intrusion detection, and threat propagation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If rule-based approaches are used for security management, then security coverage can be comprehensive, but the system complexity and maintenance burden increase continuously
Solution Approach 1:
The system enables self-service through automated event clustering that groups security events based on common characteristics without requiring continuous manual rule updates. The clustering algorithm automatically identifies patterns and relationships in security events, allowing the system to maintain comprehensive security coverage while reducing the complexity and maintenance burden associated with manual rule-based approaches.
2Reliability
If rule-based approaches are used for security management, then security coverage can be comprehensive, but the scalability deteriorates due to continuous update requirements
Solution Approach 1:
The automated event clustering system performs self-service by continuously analyzing security events and automatically grouping them based on identified characteristics. This eliminates the need for continuous manual rule updates, allowing the system to maintain comprehensive security coverage while improving scalability and reducing the maintenance burden that limits productivity in rule-based approaches.
3Ease of manufacture
If manual directory creation is used for information organization, then information can be categorized, but the automation level and efficiency are insufficient for massive information volumes
Solution Approach 1:
The system applies self-service through automated event clustering that automatically organizes security events into groups based on common characteristics. This eliminates the need for manual directory creation and categorization, providing efficient information organization that can handle massive volumes of security events while maintaining high automation levels.
4Ease of operation
If traditional folder systems are used for message management, then message storage is simple, but the ability to serve multiple activities and visibility of tasks is limited
Solution Approach 1:
The event clustering system applies multi-functionality by creating clusters that can serve multiple security activities simultaneously. Each cluster groups events with common characteristics, allowing the same clustered information to be used for detection, analysis, response, and reporting activities. This enhances adaptability and versatility while maintaining ease of operation through automated grouping.
Data Source
AI summary
A system is in communication with a managed infrastructure comprising. At least a first engine one engine receives message data from managed infrastructure that includes managed infrastructure physical hardware that supports the flow and processing of information. The at least first engine one engine determines common characteristics of events, and produces clusters of events relating to the failure of errors in the managed infrastructure. A second engine uses a source address for each of an event and a graph topology of the managed infrastructure that represents a node to node connectivity and a graph coordinate for each of an event, with an optional subset of attributes extracted for each of an event. The second engine provides a list of connections between components or nodes in the managed infrastructure. A display computer system has a collaborative interface (UI) accessible by at least two parties for situations relative to clustered messages relating to the managed infrastructure. The collaborative interface allows the at least two parties to take an action relative to a clustered message. In response to production of the clusters, one or more physical changes in a managed infrastructure hardware is made. In response to the production of the clusters, security of the managed infrastructure is maintained.


