Event Context Management System for Security Alert Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security information and event management systems face challenges in processing the high volume of alerts generated by security systems, leading to a gap between alert generation and analyst processing capacity, resulting in unaddressed security risks due to operator overload.

Innovation Solution

An event context management system that receives and processes log data from various sources, converts it into events, and stores them in a non-homogeneous database for contextual searching, enabling aggregation of event context information to prioritize alerts and improve threat detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security systems generate comprehensive alerts to detect all potential threats, then security detection capability is improved, but operator workload increases to the point of overload

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidoperator processing capacity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an event context management system as an intermediary between security alert generation and operator analysis. This system automatically aggregates event context information, performs preliminary analysis, and prioritizes alerts based on contextual relevance, thereby reducing the burden on operators while maintaining comprehensive security detection

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual operator analysis with automated computational processes. The system uses algorithms to aggregate event context, correlate security events, and prioritize alerts automatically, substituting human analytical work with machine-based processing that can handle high volumes of security data efficiently

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If operators process alerts manually to ensure thorough analysis, then analysis quality is maintained, but processing speed decreases significantly

Engineering Contradiction:
Improvealert analysis qualityVSAvoidalert processing speed
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The patent segments the alert processing workflow into distinct automated stages: event context aggregation, event correlation, alert prioritization, and operator presentation. Each stage is handled by specialized automated processes that maintain analytical rigor while accelerating throughput, allowing operators to focus on high-value decision-making rather than manual data gathering

Inventive Principle:
Principle #1Segmentation

3Reliability

If the system stores detailed event context information for all security events, then threat detection accuracy is improved, but data storage complexity increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoiddata store complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal event context data structure that serves multiple functions: storing detailed event information, enabling correlation across different security systems, supporting aggregation operations, and facilitating prioritization algorithms. This multi-functional data structure reduces overall system complexity by consolidating what would otherwise require multiple separate storage mechanisms

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11960485B2User interface for event data store
Publication Date: 2024.04.16 SUMO LOGIC INC
  • US11960485B2 patent drawing
  • US11960485B2 patent drawing
  • US11960485B2 patent drawing

AI summary

A method includes defining a set of context types; defining a set of source types, each comprising context types; defining, for each source type, and for each context type included in the events from data sources having the source type, a context definition comprising a set of fields, in events from the data sources, that are associated with the context type; receiving a query comprising a first field value and a time period; retrieving a plurality of events that include the first field value and the time period; for each retrieved event, and for each context definition defined for a source type and a context type of a data source from which the retrieved event originated, determining field values of fields in the set of fields of the context definition; aggregating, for each context type, determined field values from the events; and generating an output.