Meta-Notable Event Framework for Security Threat Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems face challenges in efficiently detecting and remediating sophisticated network security threats across complex networked systems, as existing security applications struggle to effectively monitor and analyze vast amounts of machine-generated data from diverse sources.

Innovation Solution

The implementation of a data intake and query system, such as the SPLUNK® ENTERPRISE system, which uses a late-binding schema to collect, index, and search machine-generated data, enabling flexible data analysis and visualization through a meta-notable event framework that detects and correlates notable events across disparate data sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing security applications are used to monitor network activity, then basic security monitoring is achieved, but sophisticated network security threats cannot be efficiently detected

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the security monitoring system into multiple specialized components: data collectors that gather raw security events, a normalization engine that standardizes event formats, a correlation engine that analyzes relationships between events, and a reporting module that presents findings. This segmentation allows each component to specialize in specific tasks, improving threat detection precision without overwhelming system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a normalization engine as an intermediary layer between raw security event data and the correlation analysis. This intermediary component transforms diverse security events from multiple sources into a standardized format, enabling the correlation engine to efficiently detect sophisticated threats without being overwhelmed by data heterogeneity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple security applications are deployed to cover different security layers, then comprehensive security coverage is achieved, but efficient threat detection and remediation becomes difficult

Engineering Contradiction:
Improvesecurity coverageVSAvoidthreat remediation efficiency
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent merges data collection, normalization, correlation, and reporting functions into a unified security monitoring platform. By combining multiple security applications into one integrated system, the patent maintains comprehensive security coverage across different layers while simplifying threat detection and remediation through centralized management and automated correlation of security events.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal security monitoring platform that can handle multiple types of security events from diverse sources through a single system. The normalization engine provides multi-functionality by adapting to different event formats, while the correlation engine universally analyzes relationships across all security layers, improving ease of operation without sacrificing comprehensive coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If vast amounts of machine-generated data are collected for analysis, then real-time operational intelligence is achieved, but data processing and analysis becomes computationally intensive

Engineering Contradiction:
Improveoperational intelligence speedVSAvoidcomputational resource consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The patent applies preliminary action by implementing a normalization engine that standardizes security events as they are collected, before they enter the correlation analysis phase. This pre-processing step organizes data into consistent formats and extracts relevant fields upfront, reducing the computational burden during real-time correlation analysis and enabling faster operational intelligence without excessive resource consumption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts only the most relevant features and fields from vast amounts of machine-generated security data during the normalization phase. By taking out and retaining only critical information needed for threat detection, the system achieves real-time operational intelligence while minimizing computational resource consumption during correlation analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11736502B2Generating meta-notable event summary information
Publication Date: 2023.08.22 CISCO TECHNOLOGY INC
  • US11736502B2 patent drawing
  • US11736502B2 patent drawing
  • US11736502B2 patent drawing

AI summary

Techniques and mechanisms are disclosed for a data intake and query system to generate “meta-notable” events by applying a meta-notable event rule to a collection of notable event data. A meta-notable event rule specifies one or more patterns of notable event instances defined by a set of notable event states and a set of transition rules (also referred to as association rules) indicating conditions for transitioning from one notable event state to another. The set of notable event states includes at least one start state and at least one end state. A meta-notable event is generated when a set of analyzed notable events satisfies a set of transition rules linking a start state to an end state (including transitions through any intermediary states between the start state and the end state).