Event Detection System for Cybersecurity Threat Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in detecting and analyzing suspicious cybersecurity events due to inaccessible or unstructured data, which hinders the detection and mitigation of cybersecurity incidents.

Innovation Solution

A method involving processors that receive and process system event records to identify suspicious events, generate new event detectors based on selected properties, and send relevant information to client devices for analysis and mitigation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If raw and unstructured log files are used for cybersecurity monitoring, then data volume is increased, but data accessibility and understandability for security analysts deteriorates

Engineering Contradiction:
Improvedata volumeVSAvoiddata accessibility
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

The patent extracts relevant information from raw log files by processing them through event detectors that identify and extract only the suspicious events and associated data. This separates the valuable actionable information from the overwhelming volume of raw data, making it accessible and analyzable for security analysts while maintaining comprehensive monitoring coverage.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary processing layer consisting of event detectors and data processors that sit between the raw log sources and security analysts. This intermediary layer transforms unstructured log data into structured, actionable intelligence reports, bridging the gap between data availability and data usability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive data collection is implemented, then detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the detection system into multiple independent event detectors, each specialized for detecting specific types of security events. This modular approach allows comprehensive detection coverage across multiple security domains while keeping each individual detector simple and manageable, reducing overall system complexity through functional decomposition.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal processing framework that handles multiple types of security events through a common architecture. The event detectors and data processors can be configured to monitor various security domains (authentication, authorization, resource access, etc.) using the same underlying processing mechanisms, achieving comprehensive detection without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If existing event detectors are used, then detection coverage is maintained, but adaptability to new threat types deteriorates

Engineering Contradiction:
Improvedetection coverageVSAvoidadaptability to new threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic event detectors that can be configured and updated based on emerging threat patterns. The system allows security analysts to modify detector parameters, add new detection rules, and update threat signatures without replacing the entire detection infrastructure. This dynamic configuration capability maintains comprehensive detection coverage while enabling rapid adaptation to new threat types.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent incorporates feedback mechanisms where detected suspicious events and their associated data feed back into the system for analysis. This feedback loop enables the system to learn from detected patterns and refine its detection capabilities, allowing existing detectors to adapt to new threat types by analyzing emerging patterns and updating their detection criteria accordingly.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11698961B2System event detection system and method
Publication Date: 2023.07.11 PALANTIR TECHNOLOGIES INC
  • US11698961B2 patent drawing
  • US11698961B2 patent drawing
  • US11698961B2 patent drawing

AI summary

A method, performed by one or more processors, including receiving a plurality of system event records; processing the plurality of system event records using a set of event detectors to determine that a suspicious system event has occurred; sending, to a client device, a plurality of properties associated with the suspicious system event; receiving, from the client device, a selection indicator indicating a selected one or more properties of the plurality of properties; generating one or more new event detectors based on the selected one or more properties; and adding the one or more new event detectors to the set of event detectors.