Security Business Objects Automate Threat Detection Workflows

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing SIEM systems rely heavily on specialized user expertise for manual, multi-step data retrieval and analysis, limiting their ability to efficiently detect and respond to security threats in data processing systems.

Innovation Solution

The SIEM system incorporates a data storage sub-system with security business objects and workflows that abstract security data, enabling automated analysis and threat detection, and provides recommendations for remedial actions such as software patches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual multi-step data retrieval and analysis processes are used by security analysts, then security analysis can be performed with existing tools, but the process requires heavy user expertise and is time-consuming

Engineering Contradiction:
Improveease of security analysisVSAvoidtime for security analysis
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent segments the complex security analysis process into distinct workflow components and security business objects. Each security business object represents a specific security concept (vulnerability, attack, host, etc.) with predefined data retrieval and analysis logic, allowing analysts to compose complex analyses from modular, reusable segments rather than building everything from scratch manually

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-defining security business objects with embedded queries, data retrieval logic, and analysis routines. These objects are prepared in advance with standardized methods for accessing security data, so when an analyst executes a workflow, the heavy lifting of data retrieval and initial analysis has already been configured, significantly reducing execution time and required expertise

Inventive Principle:
Principle #10Preliminary action

2Extent of automation

If specialized security analysts perform manual analysis, then comprehensive security assessment can be achieved, but the system relies heavily on user expertise rather than automation

Engineering Contradiction:
Improveautomation of security analysisVSAvoidquality of security analysis
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent enables self-service automation through security business objects that contain embedded logic for data retrieval, correlation, and analysis. These objects autonomously execute predefined security analyses without requiring manual intervention for each step, while still allowing analysts to configure and control the overall workflow. The system serves itself by automatically managing data access and analysis execution based on the workflow definitions

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces security business objects as intermediaries between the analyst's high-level workflow specifications and the underlying complex data retrieval and analysis operations. These objects act as mediators that translate abstract security analysis requirements into concrete database queries and data processing operations, maintaining reliability by encapsulating expert knowledge within the intermediary layer while enabling automation at the execution layer

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If multiple queries and manual filtering are performed for security analysis, then detailed security information can be retrieved, but the process becomes complex and difficult to maintain

Engineering Contradiction:
Improvecomplexity of analysis processVSAvoidflexibility of security analysis
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements universality by designing security business objects with standardized interfaces and methods that can be reused across multiple workflows. Each object represents a universal security concept (such as vulnerability assessment or attack detection) that can be instantiated and combined in different workflows to address various security analysis needs, reducing complexity through reuse while maintaining versatility through composition

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent adds an abstraction dimension to the security analysis process by introducing security business objects as an intermediate layer between raw data queries and final analysis results. This additional dimension organizes complex data retrieval operations into structured, named objects with defined purposes, making the overall system easier to understand and maintain while preserving the ability to perform detailed analyses through the hierarchical object structure

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9069930B1Security information and event management system employing security business objects and workflows
Publication Date: 2015.06.30 EMC IP HLDG CO LLC
  • US9069930B1 patent drawing
  • US9069930B1 patent drawing
  • US9069930B1 patent drawing

AI summary

A security information and event management (SIEM) system includes a data storage sub-system that stores (1) security data pertaining to security-related events and states of a production computer system, (2) security business objects (SBOs) as an abstraction layer over the security data, and (3) workflows which each include a set of the SBOs organized in a workflow-specific manner. Each SBO represents a security-related aspect of the production system and includes data queries to generate output data pertaining to the security-related aspect. Each workflow embodies a complex multi-step security analysis operation. In operation, security users of the SIEM system execute the workflows including the respective security business objects, resulting in a set of result data which identifies security threats and vulnerabilities of the production computer system. A workflow can provide additional contextualization for detected events, including asset data regarding the configuration of hosts in the data processing system which can be used to generate recommendations for remedial action, such as applying certain software patches to address a threat.