External Service Bridge for Cloud Log Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Security Information and Event Management (SIEM) systems are limited in their ability to integrate with cloud-based services, as they are typically located within an enterprise's network behind a firewall, making it challenging to monitor and manage security threats from cloud-based sources effectively.
Innovation Solution
A method and system that integrate log data from cloud systems with internal management systems by using an external service bridge to securely receive, filter, and transmit log data through insecure protocols within the secure network, enabling proactive detection and prevention of security threats such as malware, spyware, and policy violations, and allowing integration with SIEM systems for data aggregation, correlation, and compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SIEM systems are located within an enterprise network behind a firewall, then network security is improved, but the ability to integrate with cloud-based services deteriorates
Solution Approach 1:
The patent introduces an external service bridge as an intermediary component that sits between the cloud-based services and the internal SIEM system. This bridge receives log data from cloud services over the internet, translates and formats the data, and then transmits it to the SIEM system through the firewall using standard protocols. This intermediary enables cloud integration without requiring the SIEM system to be exposed to external networks, thus maintaining network security while achieving cloud service integration.
2Reliability
If log data is transmitted through secure connections from cloud systems, then data security is improved, but protocol complexity increases
Solution Approach 1:
The external service bridge acts as a protocol translation intermediary that handles the complexity of secure connections from cloud services. It receives encrypted log data from cloud systems using secure protocols, decrypts and processes the data, then re-encodes it in formats compatible with internal SIEM systems. This intermediary absorbs the protocol complexity, allowing the SIEM system to use simple, standard protocols for receiving data while still maintaining security through the bridge's secure connection layer.
3Measurement precision
If multiple filtering lines are implemented for log data, then data quality is improved, but processing time increases
Solution Approach 1:
The external service bridge performs preliminary filtering and formatting actions on log data before it enters the internal SIEM system. By implementing filtering at the bridge level, the system can pre-process and clean data externally, reducing the filtering burden on internal systems. This preliminary action ensures data quality is improved through multiple filtering lines while minimizing the impact on overall processing time by performing filtering work outside the core SIEM processing pipeline.
Data Source
AI summary
Systems and methods of integrating log data from a cloud system with an internal management system are described, wherein the cloud system is located externally from a secure network which contains the internal management system. The systems and methods include receiving log data from a cloud system through a secure connection between the secure network and the cloud system; buffering the received log data; filtering the buffered, received log data; and transmitting the filtered, buffered, received log data to the internal management system in a format associated with the internal management system.


