Meta-Notable Event Framework for Security Threat Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security systems face challenges in efficiently detecting and remediating sophisticated network security threats across complex networked systems, as existing security applications struggle to effectively monitor and analyze vast amounts of machine-generated data from diverse sources.
Innovation Solution
The implementation of a data intake and query system, such as the SPLUNK® ENTERPRISE system, which uses a late-binding schema to collect, index, and search machine-generated data, enabling flexible data analysis and visualization through a meta-notable event framework that detects and correlates notable events across disparate data sources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If existing security applications are used to monitor network activity, then basic security monitoring is achieved, but sophisticated network security threats cannot be efficiently detected
Solution Approach 1:
The patent segments the security monitoring system into multiple specialized components: data collectors that gather raw security events, a normalization engine that standardizes event formats, a correlation engine that analyzes relationships between events, and a reporting module that presents findings. This segmentation allows each component to specialize in specific tasks, improving threat detection precision without overwhelming system complexity.
Solution Approach 2:
The patent introduces a normalization engine as an intermediary layer between raw security event data and the correlation analysis. This intermediary component transforms diverse security events from multiple sources into a standardized format, enabling the correlation engine to efficiently detect sophisticated threats without being overwhelmed by data heterogeneity.
2Adaptability or versatility
If multiple security applications are deployed to cover different security layers, then comprehensive security coverage is achieved, but efficient threat detection and remediation becomes difficult
Solution Approach 1:
The patent merges data collection, normalization, correlation, and reporting functions into a unified security monitoring platform. By combining multiple security applications into one integrated system, the patent maintains comprehensive security coverage across different layers while simplifying threat detection and remediation through centralized management and automated correlation of security events.
Solution Approach 2:
The patent creates a universal security monitoring platform that can handle multiple types of security events from diverse sources through a single system. The normalization engine provides multi-functionality by adapting to different event formats, while the correlation engine universally analyzes relationships across all security layers, improving ease of operation without sacrificing comprehensive coverage.
3Productivity
If vast amounts of machine-generated data are collected for analysis, then real-time operational intelligence is achieved, but data processing and analysis becomes computationally intensive
Solution Approach 1:
The patent applies preliminary action by implementing a normalization engine that standardizes security events as they are collected, before they enter the correlation analysis phase. This pre-processing step organizes data into consistent formats and extracts relevant fields upfront, reducing the computational burden during real-time correlation analysis and enabling faster operational intelligence without excessive resource consumption.
Solution Approach 2:
The patent extracts only the most relevant features and fields from vast amounts of machine-generated security data during the normalization phase. By taking out and retaining only critical information needed for threat detection, the system achieves real-time operational intelligence while minimizing computational resource consumption during correlation analysis.
Data Source
AI summary
Techniques and mechanisms are disclosed for a data intake and query system to generate “meta-notable” events by applying a meta-notable event rule to a collection of notable event data. A meta-notable event rule specifies one or more patterns of notable event instances defined by a set of notable event states and a set of transition rules (also referred to as association rules) indicating conditions for transitioning from one notable event state to another. The set of notable event states includes at least one start state and at least one end state. A meta-notable event is generated when a set of analyzed notable events satisfies a set of transition rules linking a start state to an end state (including transitions through any intermediary states between the start state and the end state).


