Modular Security Alerts and Actions for Machine-Data Threat Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in effectively identifying and remediating complex security threats due to the vast amount of machine-generated data from diverse sources, lacking efficient data processing and analysis capabilities, particularly in networked computing environments.

Innovation Solution

A data intake and query system, such as the SPLUNK® ENTERPRISE system, employs a late-binding schema and flexible extraction rules to process and analyze minimally processed machine data at search time, enabling real-time insights and correlation across disparate data sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional SIEM systems process security data, then security monitoring is provided, but the systems cannot effectively identify and remediate complex security threats due to lack of advanced analysis capabilities

Engineering Contradiction:
Improvesecurity threat identification capabilityVSAvoiddata processing and analysis capability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the data processing pipeline into distinct phases: data collection, data preparation, machine learning model inference, and alert generation. Each phase is handled by specialized components (e.g., forwarders for collection, indexers for preparation, search heads for inference), allowing complex threat analysis to be broken down into manageable processing stages that improve overall reliability without overwhelming any single component.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Machine learning models serve as intermediary components between raw security data and final alert decisions. These models process prepared data through learned patterns and relationships, transforming complex data structures into actionable threat assessments. The models act as a bridge that translates raw log data into intelligent security insights, enabling effective threat identification without requiring direct complex analysis of all原始 data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If systems collect and process large volumes of machine-generated data from diverse sources, then comprehensive security monitoring is achieved, but data processing and analysis becomes inefficient

Engineering Contradiction:
Improvevolume of machine data processedVSAvoiddata processing and analysis efficiency
Core Design Contradiction:
Quantity of substanceVSProductivity

Solution Approach 1:

The system performs preliminary data preparation actions during the indexing phase, where data is normalized, enriched with metadata, and organized into a searchable format before actual security analysis occurs. This pre-processing step transforms raw machine data from diverse sources into a standardized structure, significantly improving the efficiency of subsequent analysis operations and enabling rapid processing of large data volumes during threat investigation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The data processing system dynamically adapts its behavior based on search queries and data characteristics. The search head can adjust processing depth, select relevant data fields, and modulate analysis intensity according to the specific security investigation requirements. This dynamic processing allows the system to maintain high efficiency when analyzing large datasets by focusing computational resources only on relevant portions of the data rather than uniformly processing everything at maximum intensity.

Inventive Principle:
Principle #15Dynamics

3Speed

If real-time data processing is implemented for security incidents, then rapid threat response is enabled, but system complexity increases

Engineering Contradiction:
Improvethreat detection and response speedVSAvoidreal-time processing system complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The system implements periodic data processing cycles where security data is continuously collected and indexed, then processed in scheduled search operations. Rather than requiring constant real-time analysis of all incoming data, the system performs periodic searches that query prepared data structures for security incidents. This periodic processing approach enables rapid threat response when needed while reducing overall system complexity by allowing batch processing during normal operation.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system replaces complex real-time mechanical data processing mechanisms with more efficient search-based approaches. Instead of continuously transforming and analyzing raw data streams in real-time, the system pre-processes data into a searchable format and uses optimized query mechanisms to retrieve and analyze only relevant information when security incidents are detected. This substitution of processing mechanics significantly reduces system complexity while maintaining rapid response capability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Adaptability or versatility

If flexible schema definitions are used to handle diverse data sources, then adaptability improves, but data processing complexity increases

Engineering Contradiction:
Improveability to handle diverse data sourcesVSAvoidschema definition and processing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system employs a universal data preparation framework that handles multiple data source formats through a single normalized processing pipeline. The indexer can ingest data from various sources (network logs, host logs, application logs) and automatically transform them into a common internal representation using standardized field types and data structures. This universal approach provides high adaptability to diverse data sources while avoiding the complexity of maintaining separate processing schemas for each source type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system manages schema flexibility by dynamically adjusting processing parameters rather than maintaining complex schema definitions. When encountering new or varied data sources, the system can modify extraction and transformation parameters to accommodate different formats while using the same underlying processing framework. This parameter-based adaptability allows the system to handle diverse data sources without increasing fundamental processing complexity, as the same core algorithms simply operate with different parameter settings.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250227117A1Executing modular alerts and associated security actions
Publication Date: 2025.07.10 CISCO TECHNOLOGY INC
  • US20250227117A1 patent drawing
  • US20250227117A1 patent drawing
  • US20250227117A1 patent drawing

AI summary

Techniques and mechanisms are disclosed for configuring actions to be performed by a network security application in response to the detection of potential security incidents, and for causing a network security application to report on the performance of those actions. For example, users may use such a network security application to configure one or more “modular alerts.” As used herein, a modular alert generally represents a component of a network security application which enables users to specify security modular alert actions to be performed in response to the detection of defined triggering conditions, and which further enables tracking information related to the performance of modular alert actions and reporting on the performance of those actions.