Re-Run Dropped Detection Tool for SIEM Outages
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions fail to efficiently address and mitigate the risks and inefficiencies associated with missed detections and feed/platform outages in Cyber Operations, particularly in Security Information Event Management (SIEM) systems, leading to visibility and detection risks.
Innovation Solution
A Re-Run Dropped Detections Tool system comprising an interactive Re-Run Dashboard and a Dispatch Engine that processes and generates re-run data, provides real-time monitoring, and visualization of metrics, and communicates via an API to manage and mitigate the impact of outages, reducing resource consumption and alert duplication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual re-run processes are used to address feed/platform outages, then detection completeness can be improved, but time consumption and resource usage increase significantly
Solution Approach 1:
The system performs preliminary actions by automatically generating re-run jobs before manual intervention is needed. The dashboard pre-calculates affected searches, identifies missing events, and prepares re-run job definitions, so that when outages occur, the re-run process can be executed immediately without manual analysis and preparation time.
Solution Approach 2:
The system enables self-service by allowing the SIEM platform to automatically monitor its own health, detect outages, and execute re-run operations without human intervention. The dashboard automatically identifies affected feeds/platforms, generates re-run job definitions, and coordinates execution, eliminating the need for manual operational responses.
2Measurement precision
If comprehensive re-run searches are executed to cover all missed events, then detection accuracy improves, but system resource consumption increases
Solution Approach 1:
The system applies local quality by targeting re-run operations only to specific affected feeds, platforms, or searches rather than executing comprehensive re-runs across the entire system. The dashboard identifies the precise scope of outages and generates localized re-run jobs only for impacted areas, reducing unnecessary resource consumption while maintaining detection accuracy for critical events.
Solution Approach 2:
The system segments the re-run process into discrete, manageable jobs based on affected feeds and platforms. Instead of executing a single comprehensive re-run, the dashboard divides the impact scope into multiple targeted search jobs that can be executed independently, optimizing resource utilization and enabling selective re-run of only the most critical detections.
3Reliability
If manual monitoring and tracking of re-run status is performed, then operational control is maintained, but productivity decreases
Solution Approach 1:
The system implements feedback mechanisms where the dashboard continuously monitors re-run job status, tracks completion progress, and provides real-time updates on detection re-run operations. This automated feedback loop maintains operational control by providing visibility into re-run status while eliminating the need for manual monitoring, thereby improving productivity.
Solution Approach 2:
The system replaces manual mechanical monitoring processes with automated electronic systems. The dashboard uses API integrations, job status tracking, and automated notifications to monitor re-run progress, substituting human operational control with automated mechanical systems that maintain reliability while significantly improving productivity.
Data Source
AI summary
An embodiment of the present invention is directed to a Re-Run Dropped Detection Tool that provides various features and tools to prepare, execute and monitor status of a Re-Run process. An embodiment of the present invention is directed to an automated dispatch/monitoring of alert jobs as well as monitoring of Re-Run as a Service (RRAAS) solution.

