External Service Bridge for Cloud Log Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Security Information and Event Management (SIEM) systems are limited in their ability to integrate with cloud-based services, as they are typically located within an enterprise's network behind a firewall, making it challenging to monitor and manage security threats from cloud-based sources effectively.

Innovation Solution

A method and system that integrate log data from cloud systems with internal management systems by using an external service bridge to securely receive, filter, and transmit log data through insecure protocols within the secure network, enabling proactive detection and prevention of security threats such as malware, spyware, and policy violations, and allowing integration with SIEM systems for data aggregation, correlation, and compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SIEM systems are located within an enterprise network behind a firewall, then network security is improved, but the ability to integrate with cloud-based services deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidintegration with cloud-based services
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an external service bridge as an intermediary component that sits between the cloud-based services and the internal SIEM system. This bridge receives log data from cloud services over the internet, translates and formats the data, and then transmits it to the SIEM system through the firewall using standard protocols. This intermediary enables cloud integration without requiring the SIEM system to be exposed to external networks, thus maintaining network security while achieving cloud service integration.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If log data is transmitted through secure connections from cloud systems, then data security is improved, but protocol complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidprotocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The external service bridge acts as a protocol translation intermediary that handles the complexity of secure connections from cloud services. It receives encrypted log data from cloud systems using secure protocols, decrypts and processes the data, then re-encodes it in formats compatible with internal SIEM systems. This intermediary absorbs the protocol complexity, allowing the SIEM system to use simple, standard protocols for receiving data while still maintaining security through the bridge's secure connection layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If multiple filtering lines are implemented for log data, then data quality is improved, but processing time increases

Engineering Contradiction:
Improvedata qualityVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The external service bridge performs preliminary filtering and formatting actions on log data before it enters the internal SIEM system. By implementing filtering at the bridge level, the system can pre-process and clean data externally, reducing the filtering burden on internal systems. This preliminary action ensures data quality is improved through multiple filtering lines while minimizing the impact on overall processing time by performing filtering work outside the core SIEM processing pipeline.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9912638B2Systems and methods for integrating cloud services with information management systems
Publication Date: 2018.03.06 ZSCALER INC
  • US9912638B2 patent drawing
  • US9912638B2 patent drawing
  • US9912638B2 patent drawing

AI summary

Systems and methods of integrating log data from a cloud system with an internal management system are described, wherein the cloud system is located externally from a secure network which contains the internal management system. The systems and methods include receiving log data from a cloud system through a secure connection between the secure network and the cloud system; buffering the received log data; filtering the buffered, received log data; and transmitting the filtered, buffered, received log data to the internal management system in a format associated with the internal management system.