Security Business Objects Automate Threat Detection Workflows
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing SIEM systems rely heavily on specialized user expertise for manual, multi-step data retrieval and analysis, limiting their ability to efficiently detect and respond to security threats in data processing systems.
Innovation Solution
The SIEM system incorporates a data storage sub-system with security business objects and workflows that abstract security data, enabling automated analysis and threat detection, and provides recommendations for remedial actions such as software patches.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual multi-step data retrieval and analysis processes are used by security analysts, then security analysis can be performed with existing tools, but the process requires heavy user expertise and is time-consuming
Solution Approach 1:
The patent segments the complex security analysis process into distinct workflow components and security business objects. Each security business object represents a specific security concept (vulnerability, attack, host, etc.) with predefined data retrieval and analysis logic, allowing analysts to compose complex analyses from modular, reusable segments rather than building everything from scratch manually
Solution Approach 2:
The patent implements preliminary action by pre-defining security business objects with embedded queries, data retrieval logic, and analysis routines. These objects are prepared in advance with standardized methods for accessing security data, so when an analyst executes a workflow, the heavy lifting of data retrieval and initial analysis has already been configured, significantly reducing execution time and required expertise
2Extent of automation
If specialized security analysts perform manual analysis, then comprehensive security assessment can be achieved, but the system relies heavily on user expertise rather than automation
Solution Approach 1:
The patent enables self-service automation through security business objects that contain embedded logic for data retrieval, correlation, and analysis. These objects autonomously execute predefined security analyses without requiring manual intervention for each step, while still allowing analysts to configure and control the overall workflow. The system serves itself by automatically managing data access and analysis execution based on the workflow definitions
Solution Approach 2:
The patent introduces security business objects as intermediaries between the analyst's high-level workflow specifications and the underlying complex data retrieval and analysis operations. These objects act as mediators that translate abstract security analysis requirements into concrete database queries and data processing operations, maintaining reliability by encapsulating expert knowledge within the intermediary layer while enabling automation at the execution layer
3Device complexity
If multiple queries and manual filtering are performed for security analysis, then detailed security information can be retrieved, but the process becomes complex and difficult to maintain
Solution Approach 1:
The patent implements universality by designing security business objects with standardized interfaces and methods that can be reused across multiple workflows. Each object represents a universal security concept (such as vulnerability assessment or attack detection) that can be instantiated and combined in different workflows to address various security analysis needs, reducing complexity through reuse while maintaining versatility through composition
Solution Approach 2:
The patent adds an abstraction dimension to the security analysis process by introducing security business objects as an intermediate layer between raw data queries and final analysis results. This additional dimension organizes complex data retrieval operations into structured, named objects with defined purposes, making the overall system easier to understand and maintain while preserving the ability to perform detailed analyses through the hierarchical object structure
Data Source
AI summary
A security information and event management (SIEM) system includes a data storage sub-system that stores (1) security data pertaining to security-related events and states of a production computer system, (2) security business objects (SBOs) as an abstraction layer over the security data, and (3) workflows which each include a set of the SBOs organized in a workflow-specific manner. Each SBO represents a security-related aspect of the production system and includes data queries to generate output data pertaining to the security-related aspect. Each workflow embodies a complex multi-step security analysis operation. In operation, security users of the SIEM system execute the workflows including the respective security business objects, resulting in a set of result data which identifies security threats and vulnerabilities of the production computer system. A workflow can provide additional contextualization for detected events, including asset data regarding the configuration of hosts in the data processing system which can be used to generate recommendations for remedial action, such as applying certain software patches to address a threat.


