Unified Security Investigation Platform for Incident Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network security analysts face inefficiencies in identifying, investigating, and reporting security incidents due to the cumbersome use of disparate data sources and lack of consistent reporting tools, leading to inconsistent and difficult-to-share investigation reports.
Innovation Solution
A data intake and query system, such as the SPLUNK ENTERPRISE system, is employed to collect, index, and search machine-generated data from various sources, enabling efficient data analysis and report generation through a flexible schema and late-binding schema approach, which allows for real-time operational intelligence and improved incident investigation capabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If analysts use disparate third-party applications and manual methods to collect and cross-reference security data, then data collection flexibility is maintained, but investigation efficiency and report consistency deteriorate
Solution Approach 1:
The patent merges multiple disparate data sources and third-party applications into a single unified security investigation platform. The system consolidates log data, network traffic data, endpoint data, and threat intelligence into one centralized interface, eliminating the need for analysts to switch between multiple applications and manually cross-reference data, thereby improving investigation efficiency while maintaining manageable system complexity through integrated architecture
Solution Approach 2:
The unified security investigation platform provides multi-functional capabilities that replace multiple specialized third-party applications. The system can collect data from diverse sources, perform real-time analysis, generate consistent reports, and share findings across the organization through a single universal interface, maintaining flexibility while improving productivity through consolidated functionality
2Adaptability or versatility
If analysts manually collect and cross-reference information from multiple data sources using various applications, then data collection adaptability is maintained, but report consistency and ease of sharing deteriorate
Solution Approach 1:
The system implements homogeneous data handling procedures across all data sources through standardized collection methods and unified analysis protocols. By processing log data, network traffic data, endpoint data, and threat intelligence through consistent pipelines, the system ensures that all investigations follow the same methodology, producing uniform and consistent reports regardless of the underlying data source diversity
Solution Approach 2:
The system performs preliminary data standardization and normalization during the data collection phase, converting diverse data formats from multiple sources into a unified structure before analysis. This preliminary action ensures that all subsequent processing and reporting operations work with consistent data, maintaining report consistency while preserving the ability to adapt to different data sources
3Ease of manufacture
If conventional security applications are used without unified data processing, then implementation simplicity is maintained, but operational intelligence quality and incident understanding deteriorate
Solution Approach 1:
The system introduces intermediary data processing layers that bridge raw data from multiple sources and the final analysis results. These intermediary components include standardized data collection interfaces, unified data models, and consistent analysis protocols that enhance the quality of operational intelligence by ensuring thorough and systematic processing of all security-relevant information before presentation to analysts
Data Source
AI summary
Techniques and mechanisms are disclosed that enable network security analysts and other users to efficiently conduct network security investigations and to produce useful representations of investigation results. As used herein, a network security investigation generally refers to an analysis by an analyst (or team of analysts) of one or more detected network events that may pose internal and/or external threats to a computer network under management. A network security application provides various interfaces that enable users to create investigation timelines, where the investigation timelines display a collection of events related to a particular network security investigation. A network security application further provides functionality to monitor and log user interactions with the network security application, where particular logged user interactions may also be added to one or more investigation timelines.


