Scoped Application Mapping Third-Party Alerts to Security Records

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current remote network management platforms face inefficiencies in managing and integrating security incidents across complex enterprise networks, particularly in consolidating and transforming data from third-party security services into unified security incident records.

Innovation Solution

A software application within the remote network management platform is configured to pull past alerts from a third-party database, map fields using mapping data, and create security incident records, enabling efficient management and visualization of security incidents through a graphical user interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If security services from multiple third-party providers are integrated into a unified platform, then security incident management capability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity incident management capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a mapping table as an intermediary component that bridges third-party security alert data and internal security incident records. This mapping table contains field correspondence relationships that enable automatic translation between different data formats without requiring complex integration logic throughout the system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the integration process into distinct modular components: alert reception module, mapping table lookup module, and record creation module. This segmentation allows each component to handle specific tasks independently, reducing overall system complexity while maintaining comprehensive security incident management capability.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If manual creation of security incident records from third-party alerts is performed, then data accuracy is improved, but time consumption increases

Engineering Contradiction:
Improvedata accuracyVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent pre-establishes mapping tables that define correspondence relationships between third-party alert fields and internal security incident record fields before actual data processing occurs. This preliminary action enables automatic accurate mapping during runtime without requiring manual intervention for each record creation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system performs self-service by automatically matching alert fields to record fields using the pre-configured mapping table. The mapping module autonomously translates third-party alert data into internal security incident records without human intervention, maintaining data accuracy while eliminating manual time consumption.

Inventive Principle:
Principle #25Self-service

3Loss of information

If comprehensive field mapping between third-party alerts and security incident records is implemented, then data integration completeness is improved, but processing complexity increases

Engineering Contradiction:
Improvedata integration completenessVSAvoidprocessing complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The mapping table serves as an intermediary that comprehensively defines all field correspondences between third-party alerts and security incident records in a centralized location. This approach ensures complete data integration while keeping processing logic simple, as the mapping table handles all translation complexity in one place rather than scattering it throughout the processing system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11533339B2Creating security incident records using a remote network management platform
Publication Date: 2022.12.20 SERVICENOW INC
  • US11533339B2 patent drawing
  • US11533339B2 patent drawing
  • US11533339B2 patent drawing

AI summary

An example embodiment performed by a scoped software application executable on a computing device of a computational instance of a remote network management platform may involve: requesting and receiving, from an application database associated with a third-party software application, alert rules that trigger alerts when associated events occur in a managed network; receiving data representing selection of a set of the alert rules and, based on the data, requesting and receiving, from the application database, a set of past alerts that have been triggered by the set of the alert rules; using mapping data to map fields of the set of the past alerts to fields of a sample security incident record; displaying a preview region including the sample security incident record; using the mapping data to create security incident records that map to the set of the past alerts; and writing, to a security incident database, the security incident records.