Security Management System Normalizing Heterogeneous Event Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Heterogeneous security products from different vendors use differing classification and reporting schemes, leading to redundant information and reduced effectiveness of managed security services due to confusion, expense, uncertainty, and human error in administration and configuration.

Innovation Solution

A computer-implemented method for integrated security management that identifies equivalent event signatures across security systems with different naming schemes by analyzing co-occurrence profiles, similarity metrics, and signature associations, enabling consistent and accurate security actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If heterogeneous security products from different vendors are deployed to provide comprehensive security coverage, then security coverage and protection capability are improved, but system complexity and administration difficulty increase due to differing classification and reporting schemes

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a security management system as an intermediary layer between heterogeneous security products and the user. This mediator translates and normalizes different vendor-specific event signature formats into a unified classification scheme, allowing comprehensive security coverage from multiple vendors while hiding the underlying complexity of differing reporting schemes from administrators

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security management system implements a universal event signature classification framework that can handle and normalize events from multiple different security vendors. This universal system performs multiple functions: receiving diverse input formats, translating them into a common schema, and providing unified security management capabilities across heterogeneous products

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If heterogeneous security products with different naming schemes are integrated, then comprehensive security monitoring is achieved, but information redundancy and confusion increase reducing effectiveness

Engineering Contradiction:
Improvesecurity monitoring effectivenessVSAvoidinformation redundancy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent merges event signatures from multiple heterogeneous security products into a unified classification framework. By combining and normalizing the different naming schemes into a common event signature schema, the system eliminates information redundancy and confusion while maintaining comprehensive security monitoring capabilities from all deployed products

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If manual configuration and administration of heterogeneous security systems is performed, then customization and control are improved, but human error and operational expense increase

Engineering Contradiction:
Improveconfiguration controlVSAvoidadministration time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The security management system provides self-service capabilities by automatically translating and normalizing event signatures from different vendors without requiring manual configuration. The system autonomously handles the complexity of integrating heterogeneous security products, reducing administrative time and human error while maintaining ease of operation through automated classification and reporting

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10242187B1Systems and methods for providing integrated security management
Publication Date: 2019.03.26 GEN DIGITAL INC
  • US10242187B1 patent drawing
  • US10242187B1 patent drawing
  • US10242187B1 patent drawing

AI summary

The disclosed computer-implemented method for providing integrated security management may include (1) identifying a computing environment protected by security systems and monitored by a security management system that receives event signatures from the security systems, where a first security system uses a first event signature naming scheme that differs from a second event signature naming scheme used by a second security system, (2) observing a first event signature that originates from the first security system and uses the first event signature naming scheme, (3) determine that the first event signature is equivalent to a second event signature that uses the second event signature naming scheme, and (4) performing, in connection with observing the first event signature, a security action associated with the second event signature and directed to the computing environment. Various other methods, systems, and computer-readable media are also disclosed.