Federated Security Endpoint Search for Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional threat hunting techniques are inefficient and lack standardization, leading to prolonged detection times for harmful actors within networks, and they do not facilitate reusability or sharing of threat hunting knowledge across applications.
Innovation Solution
A computer-implemented method and system for structured threat hunting using a federated search on security endpoints, which organizes search information into steps and variables, runs security analytics on the dataset, and invokes responses to protect the system, leveraging a standardized and reusable threat hunting template.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If conventional threat hunting techniques are used, then threat hunting can be performed, but detection time is prolonged and efficiency is low
Solution Approach 1:
The threat hunting process is segmented into distinct phases: data collection from multiple sources, data processing and enrichment, analytics execution, and response actions. Each phase is handled by specialized components working in parallel, reducing overall detection time while improving efficiency.
Solution Approach 2:
Security data is pre-collected and pre-processed from multiple endpoints before threat analysis begins. Data enrichment and contextual information are prepared in advance, so when threat detection is needed, the analysis can proceed immediately with ready-to-use data, significantly reducing detection time.
2Adaptability or versatility
If manual threat hunting is performed, then custom investigations can be conducted, but the process lacks standardization and reusability
Solution Approach 1:
The system provides universal threat hunting templates that can be applied across multiple endpoints and data sources. These templates encapsulate standardized investigation procedures that can be reused for different threat scenarios while maintaining adaptability through configurable parameters and custom analytics.
Solution Approach 2:
The system allows dynamic adjustment of search parameters, data sources, and analytics configurations within standardized templates. This enables the same template structure to adapt to different threat scenarios by changing parameters rather than creating entirely new procedures, balancing standardization with flexibility.
3Loss of information
If comprehensive security data collection is performed across multiple endpoints, then more threat information is available, but data processing complexity increases
Solution Approach 1:
The system extracts only the relevant security data and events from multiple endpoints based on predefined criteria and threat indicators. Rather than processing all collected data, extraction filters focus on high-value information, reducing processing complexity while maintaining information completeness for threat detection.
Solution Approach 2:
A centralized data processing intermediary component receives data from multiple endpoints, standardizes formats, enriches with contextual information, and prepares data for analytics. This intermediary layer simplifies the complexity by providing a unified processing pipeline that handles diverse data sources consistently.
Data Source
AI summary
A computer-implemented method according to one embodiment includes causing a search to be performed for data on at least one security endpoint and organizing information about the performed search into steps and variables. Security analytics are run on a dataset provided from the performed search, and based on results of the analytics, a response is invoked to protect a system that interacts with the analyzed dataset. A computer program product according to another embodiment includes a computer readable storage medium having program instructions embodied therewith. The program instructions are readable and/or executable by a computer to cause the computer to perform the foregoing method. A system according to another embodiment includes a processor, and logic integrated with the processor, executable by the processor, or integrated with and executable by the processor. The logic is configured to perform the foregoing method.


