Re-Run Dropped Detection Tool for SIEM Outages

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions fail to efficiently address and mitigate the risks and inefficiencies associated with missed detections and feed/platform outages in Cyber Operations, particularly in Security Information Event Management (SIEM) systems, leading to visibility and detection risks.

Innovation Solution

A Re-Run Dropped Detections Tool system comprising an interactive Re-Run Dashboard and a Dispatch Engine that processes and generates re-run data, provides real-time monitoring, and visualization of metrics, and communicates via an API to manage and mitigate the impact of outages, reducing resource consumption and alert duplication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual re-run processes are used to address feed/platform outages, then detection completeness can be improved, but time consumption and resource usage increase significantly

Engineering Contradiction:
Improvedetection completenessVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically generating re-run jobs before manual intervention is needed. The dashboard pre-calculates affected searches, identifies missing events, and prepares re-run job definitions, so that when outages occur, the re-run process can be executed immediately without manual analysis and preparation time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by allowing the SIEM platform to automatically monitor its own health, detect outages, and execute re-run operations without human intervention. The dashboard automatically identifies affected feeds/platforms, generates re-run job definitions, and coordinates execution, eliminating the need for manual operational responses.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If comprehensive re-run searches are executed to cover all missed events, then detection accuracy improves, but system resource consumption increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system applies local quality by targeting re-run operations only to specific affected feeds, platforms, or searches rather than executing comprehensive re-runs across the entire system. The dashboard identifies the precise scope of outages and generates localized re-run jobs only for impacted areas, reducing unnecessary resource consumption while maintaining detection accuracy for critical events.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system segments the re-run process into discrete, manageable jobs based on affected feeds and platforms. Instead of executing a single comprehensive re-run, the dashboard divides the impact scope into multiple targeted search jobs that can be executed independently, optimizing resource utilization and enabling selective re-run of only the most critical detections.

Inventive Principle:
Principle #1Segmentation

3Reliability

If manual monitoring and tracking of re-run status is performed, then operational control is maintained, but productivity decreases

Engineering Contradiction:
Improveoperational controlVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements feedback mechanisms where the dashboard continuously monitors re-run job status, tracks completion progress, and provides real-time updates on detection re-run operations. This automated feedback loop maintains operational control by providing visibility into re-run status while eliminating the need for manual monitoring, thereby improving productivity.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system replaces manual mechanical monitoring processes with automated electronic systems. The dashboard uses API integrations, job status tracking, and automated notifications to monitor re-run progress, substituting human operational control with automated mechanical systems that maintain reliability while significantly improving productivity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11714900B2System and method for implementing re-run dropped detection tool
Publication Date: 2023.08.01 JPMORGAN CHASE BANK NA
  • US11714900B2 patent drawing
  • US11714900B2 patent drawing

AI summary

An embodiment of the present invention is directed to a Re-Run Dropped Detection Tool that provides various features and tools to prepare, execute and monitor status of a Re-Run process. An embodiment of the present invention is directed to an automated dispatch/monitoring of alert jobs as well as monitoring of Re-Run as a Service (RRAAS) solution.