Host Agent Event Contextualization for Intrusion Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Security Information and Event Management (SIEM) solutions fail to effectively contextualize event information and monitor events at the host or end-user level, missing potential threats present only on individual devices within a network.
Innovation Solution
The method involves enhancing event data by determining lookup keys in host devices, checking for existing key-value pairs, appending and storing them in memory, and using an agent to log and analyze activity for host intrusion detection, thereby enriching log output and detecting threats at the host level.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If SIEM software and processes are used to track security information and events, then network-level security monitoring is improved, but host-level event contextualization and monitoring capability deteriorates
Solution Approach 1:
The patent segments security monitoring into two distinct layers: network-level monitoring (handled by traditional SIEM) and host-level monitoring (handled by the new agent-based system). The host agent independently collects, contextualizes, and enriches event data at the host level, then transmits relevant information to the network SIEM. This segmentation allows each layer to specialize in its specific monitoring needs without compromising the other.
Solution Approach 2:
The host agent acts as an intermediary between the host operating system and the network SIEM system. It collects raw events from the host, enriches them with contextual information from local data sources (process lists, network connections, file systems), and forwards the enhanced events to the network SIEM. This intermediary layer enables host-level contextualization while maintaining network-level monitoring capabilities.
2Productivity
If traditional SIEM solutions are used, then centralized security event aggregation is improved, but host-level threat detection capability deteriorates
Solution Approach 1:
The host agent performs preliminary actions by collecting, contextualizing, and enriching event data at the host level before transmission to the network SIEM. It pre-processes events by adding contextual information (process details, network connection data, file system information) and filtering relevant events, so that the centralized SIEM receives already-enriched data rather than raw logs. This preliminary host-level processing improves threat detection accuracy while maintaining centralized aggregation efficiency.
3Loss of information
If network-level monitoring is implemented, then overall network security visibility is improved, but individual host threat detection capability deteriorates
Solution Approach 1:
The patent implements local quality by enabling each host to have its own dedicated agent that collects and contextualizes events with host-specific information. Each agent maintains local data sources (process lists, network connections, file systems) that provide host-specific context. This ensures that each host's events are analyzed with appropriate local context while still contributing to overall network visibility through centralized SIEM integration.
Data Source
AI summary
Disclosed are apparatus and methods that facilitate analysis of events associated with network and computer systems. The methodology includes determining at least one lookup key in a host device for an event occurring in the host device and determining whether the at least one lookup key is used in a memory to determine if at least one key-value pair exists for the event. The methodology also includes appending the at least one key-value pair to the event, and storing the at least one key-value pair in the memory based on the at least one lookup key including replacing existing keys found for the at least one lookup key.


