Security Context Map for Correlating Disparate Server Events

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current SIEM solutions are inadequate in detecting sophisticated security incidents in mission critical systems, as they operate on a per event basis, lack contextual information, and struggle with the large volumes of data generated, leading to delayed detection of security threats.

Innovation Solution

A method and system that aggregates and contextualizes disparate events from fault-tolerant servers, using platform-specific data to generate threat assessment rules, enabling real-time detection of security incidents by correlating unrelated events and identifying patterns indicative of security threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If current SIEM solutions operate on a per event basis, then the system complexity is reduced, but the detection precision of sophisticated security incidents deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoiddetection precision
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent combines multiple per-event analysis rules into a unified security incident detection framework that correlates events across different sources and time periods. The system merges platform-specific data, event logs, and threat intelligence into a comprehensive analysis model that detects sophisticated security incidents by evaluating relationships between multiple events rather than treating them in isolation.

Inventive Principle:
Principle #5Merging (Combining)

2Speed

If per event analysis is used, then the processing speed is maintained, but the loss of contextual information increases

Engineering Contradiction:
Improveprocessing speedVSAvoidcontextual information
Core Design Contradiction:
SpeedVSLoss of information

Solution Approach 1:

The system performs preliminary actions by pre-processing and indexing platform-specific data, event logs, and threat intelligence before security incidents occur. This includes building security context maps, pre-computing event relationships, and maintaining ready-to-use analysis models that enable rapid detection without losing contextual information during the actual security incident response.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If comprehensive security analysis is implemented, then the detection capability is improved, but the mean time to detection increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidmean time to detection
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements dynamic analysis that adapts the depth and scope of security analysis based on real-time conditions, event severity, and system state. The system dynamically adjusts correlation parameters, selects relevant data sources, and modifies analysis rules based on the specific security context, enabling comprehensive detection capability while maintaining rapid response times through intelligent resource allocation.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9948678B2Method and system for gathering and contextualizing multiple events to identify potential security incidents
Publication Date: 2018.04.17 XYPRO TECHNOLOGY CORP
  • US9948678B2 patent drawing
  • US9948678B2 patent drawing
  • US9948678B2 patent drawing

AI summary

A method and system for aggregating and correlating disparate and unrelated events to enable faster security event detection. A plurality of event logs generated by a number of disparate, unrelated, independent components of a fault-tolerant server and platform-specific data are contextualized through the use of a security context map, enabling unrelated events to be correlated to identify security incidents indicative of security threats. User- or system-generated rules may then be applied to the contextualized data to enable more sophisticated security breach identification.