Event Context Management System for Security Alert Prioritization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Security information and event management systems face challenges in processing the high volume of alerts generated by security systems, leading to a gap between alert generation and analyst processing capacity, resulting in unaddressed security risks due to operator overload.
Innovation Solution
An event context management system that receives and processes log data from various sources, converts it into events, and stores them in a non-homogeneous database for contextual searching, enabling aggregation of event context information to prioritize alerts and improve threat detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security systems generate comprehensive alerts to detect all potential threats, then security detection capability is improved, but operator workload increases to the point of overload
Solution Approach 1:
The patent introduces an event context management system as an intermediary between security alert generation and operator analysis. This system automatically aggregates event context information, performs preliminary analysis, and prioritizes alerts based on contextual relevance, thereby reducing the burden on operators while maintaining comprehensive security detection
Solution Approach 2:
The patent replaces manual operator analysis with automated computational processes. The system uses algorithms to aggregate event context, correlate security events, and prioritize alerts automatically, substituting human analytical work with machine-based processing that can handle high volumes of security data efficiently
2Measurement precision
If operators process alerts manually to ensure thorough analysis, then analysis quality is maintained, but processing speed decreases significantly
Solution Approach 1:
The patent segments the alert processing workflow into distinct automated stages: event context aggregation, event correlation, alert prioritization, and operator presentation. Each stage is handled by specialized automated processes that maintain analytical rigor while accelerating throughput, allowing operators to focus on high-value decision-making rather than manual data gathering
3Reliability
If the system stores detailed event context information for all security events, then threat detection accuracy is improved, but data storage complexity increases
Solution Approach 1:
The patent creates a universal event context data structure that serves multiple functions: storing detailed event information, enabling correlation across different security systems, supporting aggregation operations, and facilitating prioritization algorithms. This multi-functional data structure reduces overall system complexity by consolidating what would otherwise require multiple separate storage mechanisms
Data Source
AI summary
A method includes defining a set of context types; defining a set of source types, each comprising context types; defining, for each source type, and for each context type included in the events from data sources having the source type, a context definition comprising a set of fields, in events from the data sources, that are associated with the context type; receiving a query comprising a first field value and a time period; retrieving a plurality of events that include the first field value and the time period; for each retrieved event, and for each context definition defined for a source type and a context type of a data source from which the retrieved event originated, determining field values of fields in the set of fields of the context definition; aggregating, for each context type, determined field values from the events; and generating an output.


