Network Security Event Pooling and Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for sharing network security event information are inefficient, often resulting in irrelevant data being shared across networks, making it difficult for administrators to identify and address relevant threats in a timely manner, and there is a lack of automated and reliable mechanisms for prioritizing threats based on severity.

Innovation Solution

A system that pools and filters security threat data across multiple networks using profiling techniques to automatically direct queries and filter results, prioritizing relevant information based on group membership, threat indicators, and network characteristics, and provides a centralized query routing service that sanitizes and routes information to similarly situated networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network administrators manually monitor and analyze security events across multiple networks, then they can identify relevant threats, but the process becomes time-consuming and inefficient due to the vast quantities of information that must be sifted through

Engineering Contradiction:
Improvethreat identification accuracyVSAvoidtime to identify threats
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent introduces an intermediary system that acts as a mediator between multiple network security monitoring systems. This intermediary receives security events from various networks, applies centralized filtering and prioritization logic, and delivers relevant threats to appropriate administrators. The intermediary eliminates the need for administrators to manually sift through all raw data while maintaining accurate threat identification through sophisticated filtering algorithms that consider network profiles, event types, and severity indicators.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical manual analysis process with an automated electronic system. Instead of administrators manually reviewing security logs and events, the system employs automated filtering, prioritization, and routing mechanisms that process security data in real-time. This substitution of mechanical human analysis with electronic automation dramatically reduces the time required to identify threats while maintaining or improving identification accuracy through consistent application of filtering criteria.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If security threat information is shared across multiple networks, then networks can learn from each other's threats and take preemptive action, but irrelevant data from dissimilar networks reduces the quality and actionability of shared information

Engineering Contradiction:
Improvethreat information relevanceVSAvoidinformation sharing scope
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by tailoring the information sharing process to the specific characteristics of each network. Instead of uniform information distribution, the system profiles each network's security posture, industry sector, and risk tolerance to determine which threats are relevant. This allows the system to share information broadly across multiple networks (maintaining versatility) while ensuring each network receives only locally relevant threats (maintaining reliability). The filtering logic adapts to local network characteristics rather than applying a one-size-fits-all approach.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent dynamically changes the parameters of information sharing based on network profiles and threat characteristics. The system adjusts which parameters (such as threat severity thresholds, event types, or network categories) are applied when routing information to different networks. This parameter adaptation allows the system to maintain broad information sharing capabilities while ensuring that each network receives information matched to its specific context, thereby resolving the contradiction between sharing scope and information relevance.

Inventive Principle:
Principle #35Parameter changes

3Extent of automation

If a centralized system collects and processes security events from multiple networks, then threat prioritization and filtering can be automated, but the system complexity increases significantly

Engineering Contradiction:
Improvethreat filtering automationVSAvoidsystem architecture complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The patent segments the centralized security information processing system into distinct functional modules: event collection components that gather data from multiple networks, filtering components that apply prioritization logic, routing components that distribute information to appropriate networks, and profiling components that maintain network characteristics. This segmentation allows each module to perform a specific function with well-defined interfaces, reducing overall system complexity while maintaining high automation. The modular architecture enables independent development, testing, and maintenance of each component.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal processing framework that handles multiple types of security events, network profiles, and filtering criteria through a single standardized system architecture. Rather than creating separate specialized systems for different threat types or networks, the universal framework processes all security events through common filtering and prioritization logic that adapts to different contexts. This multi-functionality reduces system complexity by eliminating redundant components while maintaining comprehensive automation capabilities across diverse security scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11704405B2Techniques for sharing network security event information
Publication Date: 2023.07.18 SERVICENOW INC
  • US11704405B2 patent drawing
  • US11704405B2 patent drawing
  • US11704405B2 patent drawing

AI summary

This disclosure provides techniques for pooling and searching network security events reported by multiple sources. As information representing a security event is received from one source, it is searched against a central or distributed database representing events reported from multiple, diverse sources (e.g., different client networks). Either the search or correlated results can be filtered and/or routed according at least one characteristic associated with the networks, for example, to limit correlation to events reported by what are presumed to be similarly situated networks. The disclosed techniques facilitate faster identification of high-relevancy security event information, and thereby help facilitate faster threat identification and mitigation. Various techniques can be implemented as standalone software (e.g., for use by a private network) or for a central pooling and/or query service. This disclosure also provides different examples of actions that can be taken in response to search results.