Multi-Tenant SIEM Job Orchestration for Adaptive Security Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platforms are technologically incapable of scaling to manage multiple tenant networks efficiently, requiring manual integration and management, leading to high costs and security vulnerabilities due to the lack of automation and adaptability.

Innovation Solution

A cloud-based MSSP provider server with a job manager and workflow engine autonomously monitors tenant networks for configuration changes, generates fetch jobs, retrieves and enriches security information, and generates outputs to enhance network security, using a unified platform to manage multiple tenant networks with automated updates and customizable playbooks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual integration and management is used for multiple tenant networks, then device complexity is reduced, but productivity and scalability are worsened

Engineering Contradiction:
Improvesecurity management efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments security management into tenant-specific instances that can be independently managed while sharing common infrastructure. Each tenant network has dedicated security monitoring and management components that operate autonomously, enabling efficient multi-tenant management without overwhelming complexity at the system level.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The platform implements self-service capabilities where security functions are automatically performed without manual intervention. The system autonomously monitors tenant networks, detects security events, executes responses, and manages configurations through automation, significantly improving productivity while containing complexity through standardized automated processes.

Inventive Principle:
Principle #25Self-service

2Extent of automation

If automation is implemented for security management, then productivity is improved, but device complexity increases

Engineering Contradiction:
Improveautomation levelVSAvoidsystem complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The system employs universal automation frameworks and standardized protocols that can be applied across multiple tenant networks with different configurations. This multi-functionality allows high automation levels to be achieved without proportionally increasing complexity, as the same automated infrastructure serves diverse security management needs through configuration rather than structural complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If manual management is used, then device complexity is reduced, but adaptability to different tenant architectures is worsened

Engineering Contradiction:
Improvearchitectural adaptabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The platform implements dynamic configuration capabilities that automatically adapt to different tenant network architectures. The system dynamically adjusts security policies, monitoring parameters, and response strategies based on detected tenant configurations, enabling high adaptability without requiring complex manual reconfiguration for each tenant architecture.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250278483A1Devices, systems, and methods for ingesting & enriching security information to autonomously secure a plurality of tenant networks
Publication Date: 2025.09.04 BLUEVOYANT LLC
  • US20250278483A1 patent drawing
  • US20250278483A1 patent drawing
  • US20250278483A1 patent drawing

AI summary

A Security Information and Event Management (“SIEM”) provider server configured to enhance network security on behalf of a tenant network by autonomously ingesting and enriching security information associated with the tenant network is disclosed herein. The SIEM provider server can be configured to periodically monitor the tenant network for configuration changes, detect a configuration change in the tenant network, update a fetch job parameter stored in a job database based on the detected configuration change in the tenant network, generate a fetch job for the tenant network based on the updated job parameter stored in the job database and store the generated fetch job in a queue, execute the generated fetch job such that the job manager retrieves security information from a data source associated with the tenant network, enrich the retrieved security information, and generate an output configured to enhance the security of the tenant network.