Scoped Application Mapping Third-Party Alerts to Security Records
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current remote network management platforms face inefficiencies in managing and integrating security incidents across complex enterprise networks, particularly in consolidating and transforming data from third-party security services into unified security incident records.
Innovation Solution
A software application within the remote network management platform is configured to pull past alerts from a third-party database, map fields using mapping data, and create security incident records, enabling efficient management and visualization of security incidents through a graphical user interface.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If security services from multiple third-party providers are integrated into a unified platform, then security incident management capability is improved, but system complexity increases
Solution Approach 1:
The patent introduces a mapping table as an intermediary component that bridges third-party security alert data and internal security incident records. This mapping table contains field correspondence relationships that enable automatic translation between different data formats without requiring complex integration logic throughout the system.
Solution Approach 2:
The patent segments the integration process into distinct modular components: alert reception module, mapping table lookup module, and record creation module. This segmentation allows each component to handle specific tasks independently, reducing overall system complexity while maintaining comprehensive security incident management capability.
2Measurement precision
If manual creation of security incident records from third-party alerts is performed, then data accuracy is improved, but time consumption increases
Solution Approach 1:
The patent pre-establishes mapping tables that define correspondence relationships between third-party alert fields and internal security incident record fields before actual data processing occurs. This preliminary action enables automatic accurate mapping during runtime without requiring manual intervention for each record creation.
Solution Approach 2:
The system performs self-service by automatically matching alert fields to record fields using the pre-configured mapping table. The mapping module autonomously translates third-party alert data into internal security incident records without human intervention, maintaining data accuracy while eliminating manual time consumption.
3Loss of information
If comprehensive field mapping between third-party alerts and security incident records is implemented, then data integration completeness is improved, but processing complexity increases
Solution Approach 1:
The mapping table serves as an intermediary that comprehensively defines all field correspondences between third-party alerts and security incident records in a centralized location. This approach ensures complete data integration while keeping processing logic simple, as the mapping table handles all translation complexity in one place rather than scattering it throughout the processing system.
Data Source
AI summary
An example embodiment performed by a scoped software application executable on a computing device of a computational instance of a remote network management platform may involve: requesting and receiving, from an application database associated with a third-party software application, alert rules that trigger alerts when associated events occur in a managed network; receiving data representing selection of a set of the alert rules and, based on the data, requesting and receiving, from the application database, a set of past alerts that have been triggered by the set of the alert rules; using mapping data to map fields of the set of the past alerts to fields of a sample security incident record; displaying a preview region including the sample security incident record; using the mapping data to create security incident records that map to the set of the past alerts; and writing, to a security incident database, the security incident records.


