Minimally Processed Data Intake for Cyber-Attack Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing volume of machine-generated data from diverse sources poses challenges in analysis and storage, as traditional systems often discard minimally processed data, limiting flexibility and efficiency in data retrieval and security threat detection.

Innovation Solution

The SPLUNK ENTERPRISE system employs a data intake and query system that stores minimally processed machine data for later analysis, using a late-binding schema to extract relevant information at search time, facilitating flexible data exploration and security threat detection through pre-specified schemas and correlation searches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional systems discard minimally processed data, then storage costs are reduced, but data retrieval flexibility and security threat detection capability are limited

Engineering Contradiction:
Improvedata retrieval flexibilityVSAvoiddata storage volume
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The system performs preliminary actions by storing minimally processed data in an optimized format with metadata tags before detailed analysis is needed. This allows the data to be readily available for future security threat detection and analysis without requiring reprocessing, thus improving adaptability while managing storage efficiently

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes the parameter of data storage by maintaining data in a minimally processed state with associated metadata rather than fully processing or discarding it. This parameter change enables flexible retrieval and analysis while optimizing storage space, resolving the contradiction between storage volume and data retrieval flexibility

Inventive Principle:
Principle #35Parameter changes

2Reliability

If all machine data is stored for later analysis, then security threat detection capability is improved, but storage requirements and system complexity increase

Engineering Contradiction:
Improvesecurity threat detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts only the essential metadata and key characteristics from machine data during initial ingestion, storing these extracted features alongside the minimally processed data. This extraction approach enables effective security threat detection without requiring storage of all raw data details, thus improving reliability while managing system complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary classification and tagging of data with security-relevant metadata during ingestion. This preliminary action enables efficient security threat detection later without requiring complex real-time processing of all stored data, resolving the contradiction between detection capability and system complexity

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If minimally processed data is maintained for later retrieval, then analysis flexibility is improved, but data processing time at ingestion is reduced

Engineering Contradiction:
Improveanalysis flexibilityVSAvoiddata ingestion efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system extracts only the necessary metadata and key identifiers from incoming machine data during ingestion, rather than performing full processing. This extraction approach maintains analysis flexibility for later retrieval while preserving data ingestion efficiency by minimizing processing overhead at ingestion time

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs partial processing of data at ingestion, maintaining it in a minimally processed state with essential metadata. This partial action approach provides sufficient analysis flexibility for most use cases while maintaining high ingestion efficiency, resolving the contradiction between flexibility and productivity

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11876809B2Identifying a cyber-attack impacting a particular asset
Publication Date: 2024.01.16 CISCO TECHNOLOGY INC
  • US11876809B2 patent drawing
  • US11876809B2 patent drawing
  • US11876809B2 patent drawing

AI summary

In a method, a plurality of events is accessed, wherein an event of the plurality of events includes a portion of raw-machine data from a data source of a plurality of data sources. For at least one event of the plurality of events, a transaction phase of a computer security transaction is correlated with the at least one event based at least in part on a data source associated with the at least one event. The transaction phase of the at least one event is correlated with a particular asset of a plurality of assets.