Modular Action-Level Integration Framework for Cybersecurity Platforms
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cybersecurity incident management platforms face challenges in managing complex integrations due to large integration files that call multiple APIs, making it difficult to customize, extend, and share functionalities from different providers without breaking existing functionality.
Innovation Solution
An open integration framework that defines integrations at the action level, using integration and action definition files, allowing for modular and customizable integrations executed in Docker containers, with support for multiple languages and libraries, enabling users to create, extend, and share integrations easily.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If large integration files are used to call multiple APIs, then comprehensive functionality is achieved, but customization and extension become difficult
Solution Approach 1:
The patent segments large monolithic integration files into smaller modular components organized by functionality and API group. Each module can be independently configured, loaded, and customized, allowing users to select only the functionalities they need rather than managing comprehensive but unwieldy integration files.
Solution Approach 2:
The patent introduces a hierarchical dimension to integration file organization, structuring them across multiple levels (e.g., core functionality, optional modules, provider-specific extensions). This multi-dimensional structure enables users to navigate and customize integrations by selecting appropriate levels of detail and scope.
2Adaptability or versatility
If comprehensive integration files are used to cover all functionalities, then all services are available, but extending and sharing functionalities becomes difficult
Solution Approach 1:
The patent creates universal integration modules that can serve multiple purposes and be reused across different contexts. These modular components are designed with standardized interfaces and configurations, enabling them to be extended for specific use cases while maintaining their core functionality and compatibility with the broader system.
3Ease of operation
If large integration files are used, then complete functionality is provided, but transparency and manageability are reduced
Solution Approach 1:
The patent extracts and separates specific functionalities, configuration parameters, and API call details from large integration files into distinct modular components. This extraction enables users to view, edit, and manage individual functionalities independently, significantly improving transparency and ease of operation.
4Adaptability or versatility
If monolithic integration files are used, then all functionalities are included, but customization risks breaking existing functionality
Solution Approach 1:
By segmenting integration files into isolated modular components with well-defined interfaces, the patent ensures that customizations to one module do not affect other modules. This segmentation provides protection against breaking existing functionality while enabling safe customization.
Solution Approach 2:
The patent applies local quality by allowing different modules to have different levels of configurability and customization options appropriate to their specific functionality. Critical core modules maintain stricter interfaces for stability, while peripheral modules offer greater flexibility, optimizing the balance between customization safety and adaptability.
Data Source
AI summary
In an open integration framework of a computerized cybersecurity incident management software platform, integrations are defined at an action level for integrating cybersecurity products for performing desired actions into the cybersecurity incident management software platform. High-level parameters of an integration are defined through an integration definition file. The integration definition file identifies a cybersecurity product to be called through an application program interface. One or more actions of the integration are defined through one or more respective action definition files that define details of the one or more actions. The action definition files identify the integration defined by the integration definition file, and the actions requiring use of the cybersecurity product through the application program interface.


