Unified Security Investigation Platform for Incident Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security analysts face inefficiencies in identifying, investigating, and reporting security incidents due to the cumbersome use of disparate data sources and lack of consistent reporting tools, leading to inconsistent and difficult-to-share investigation reports.

Innovation Solution

A data intake and query system, such as the SPLUNK ENTERPRISE system, is employed to collect, index, and search machine-generated data from various sources, enabling efficient data analysis and report generation through a flexible schema and late-binding schema approach, which allows for real-time operational intelligence and improved incident investigation capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If analysts use disparate third-party applications and manual methods to collect and cross-reference security data, then data collection flexibility is maintained, but investigation efficiency and report consistency deteriorate

Engineering Contradiction:
Improveinvestigation efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges multiple disparate data sources and third-party applications into a single unified security investigation platform. The system consolidates log data, network traffic data, endpoint data, and threat intelligence into one centralized interface, eliminating the need for analysts to switch between multiple applications and manually cross-reference data, thereby improving investigation efficiency while maintaining manageable system complexity through integrated architecture

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified security investigation platform provides multi-functional capabilities that replace multiple specialized third-party applications. The system can collect data from diverse sources, perform real-time analysis, generate consistent reports, and share findings across the organization through a single universal interface, maintaining flexibility while improving productivity through consolidated functionality

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If analysts manually collect and cross-reference information from multiple data sources using various applications, then data collection adaptability is maintained, but report consistency and ease of sharing deteriorate

Engineering Contradiction:
Improvedata collection adaptabilityVSAvoidreport consistency
Core Design Contradiction:
Adaptability or versatilityVSManufacturing precision

Solution Approach 1:

The system implements homogeneous data handling procedures across all data sources through standardized collection methods and unified analysis protocols. By processing log data, network traffic data, endpoint data, and threat intelligence through consistent pipelines, the system ensures that all investigations follow the same methodology, producing uniform and consistent reports regardless of the underlying data source diversity

Inventive Principle:
Principle #33Homogeneity

Solution Approach 2:

The system performs preliminary data standardization and normalization during the data collection phase, converting diverse data formats from multiple sources into a unified structure before analysis. This preliminary action ensures that all subsequent processing and reporting operations work with consistent data, maintaining report consistency while preserving the ability to adapt to different data sources

Inventive Principle:
Principle #10Preliminary action

3Ease of manufacture

If conventional security applications are used without unified data processing, then implementation simplicity is maintained, but operational intelligence quality and incident understanding deteriorate

Engineering Contradiction:
Improvesystem implementation easeVSAvoidsecurity insight quality
Core Design Contradiction:
Ease of manufactureVSLoss of information

Solution Approach 1:

The system introduces intermediary data processing layers that bridge raw data from multiple sources and the final analysis results. These intermediary components include standardized data collection interfaces, unified data models, and consistent analysis protocols that enhance the quality of operational intelligence by ensuring thorough and systematic processing of all security-relevant information before presentation to analysts

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11132111B2Assigning workflow network security investigation actions to investigation timelines
Publication Date: 2021.09.28 CISCO TECHNOLOGY INC
  • US11132111B2 patent drawing
  • US11132111B2 patent drawing
  • US11132111B2 patent drawing

AI summary

Techniques and mechanisms are disclosed that enable network security analysts and other users to efficiently conduct network security investigations and to produce useful representations of investigation results. As used herein, a network security investigation generally refers to an analysis by an analyst (or team of analysts) of one or more detected network events that may pose internal and/or external threats to a computer network under management. A network security application provides various interfaces that enable users to create investigation timelines, where the investigation timelines display a collection of events related to a particular network security investigation. A network security application further provides functionality to monitor and log user interactions with the network security application, where particular logged user interactions may also be added to one or more investigation timelines.