Federated Security Endpoint Search for Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional threat hunting techniques are inefficient and lack standardization, leading to prolonged detection times for harmful actors within networks, and they do not facilitate reusability or sharing of threat hunting knowledge across applications.

Innovation Solution

A computer-implemented method and system for structured threat hunting using a federated search on security endpoints, which organizes search information into steps and variables, runs security analytics on the dataset, and invokes responses to protect the system, leveraging a standardized and reusable threat hunting template.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If conventional threat hunting techniques are used, then threat hunting can be performed, but detection time is prolonged and efficiency is low

Engineering Contradiction:
Improvethreat detection efficiencyVSAvoiddetection time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The threat hunting process is segmented into distinct phases: data collection from multiple sources, data processing and enrichment, analytics execution, and response actions. Each phase is handled by specialized components working in parallel, reducing overall detection time while improving efficiency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Security data is pre-collected and pre-processed from multiple endpoints before threat analysis begins. Data enrichment and contextual information are prepared in advance, so when threat detection is needed, the analysis can proceed immediately with ready-to-use data, significantly reducing detection time.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If manual threat hunting is performed, then custom investigations can be conducted, but the process lacks standardization and reusability

Engineering Contradiction:
Improvethreat hunting flexibilityVSAvoidprocess standardization
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system provides universal threat hunting templates that can be applied across multiple endpoints and data sources. These templates encapsulate standardized investigation procedures that can be reused for different threat scenarios while maintaining adaptability through configurable parameters and custom analytics.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system allows dynamic adjustment of search parameters, data sources, and analytics configurations within standardized templates. This enables the same template structure to adapt to different threat scenarios by changing parameters rather than creating entirely new procedures, balancing standardization with flexibility.

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If comprehensive security data collection is performed across multiple endpoints, then more threat information is available, but data processing complexity increases

Engineering Contradiction:
Improvethreat information completenessVSAvoiddata processing complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system extracts only the relevant security data and events from multiple endpoints based on predefined criteria and threat indicators. Rather than processing all collected data, extraction filters focus on high-value information, reducing processing complexity while maintaining information completeness for threat detection.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

A centralized data processing intermediary component receives data from multiple endpoints, standardizes formats, enriches with contextual information, and prepares data for analytics. This intermediary layer simplifies the complexity by providing a unified processing pipeline that handles diverse data sources consistently.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12316652B2Invoking response(s) based on analysis of a dataset obtained from searching a security endpoint
Publication Date: 2025.05.27 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12316652B2 patent drawing
  • US12316652B2 patent drawing
  • US12316652B2 patent drawing

AI summary

A computer-implemented method according to one embodiment includes causing a search to be performed for data on at least one security endpoint and organizing information about the performed search into steps and variables. Security analytics are run on a dataset provided from the performed search, and based on results of the analytics, a response is invoked to protect a system that interacts with the analyzed dataset. A computer program product according to another embodiment includes a computer readable storage medium having program instructions embodied therewith. The program instructions are readable and/or executable by a computer to cause the computer to perform the foregoing method. A system according to another embodiment includes a processor, and logic integrated with the processor, executable by the processor, or integrated with and executable by the processor. The logic is configured to perform the foregoing method.