Distributed SIEM Agent Routing for Segmented Network Exfiltration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional SIEM solutions face challenges in scaling to manage storage and analysis needs of thousands of endpoints and navigating segmented networks, with hybrid SIEM solutions requiring tight release version coupling and struggling with data exfiltration from segmented networks.

Innovation Solution

The implementation of agent devices that can pre-process event data within a network, determine their capabilities, and dynamically select a target device to exfiltrate data to a remote SIEM server through a distributed ledger system, allowing for efficient data management and analysis across segmented networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If conventional SIEM solutions aggregate event data from thousands of endpoints, then comprehensive security monitoring is achieved, but storage and analysis scalability deteriorates

Engineering Contradiction:
Improveevent data volumeVSAvoidstorage and analysis scalability
Core Design Contradiction:
Quantity of substanceVSProductivity

Solution Approach 1:

The patent divides the network into multiple segments with designated exfiltration points. Agent devices in segmented networks can exfiltrate data to intermediate devices within the same segment, which then relay to external SIEM servers. This segmentation allows distributed data collection without requiring all devices to communicate directly with external servers, improving scalability while maintaining comprehensive monitoring.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary devices that act as relay points between agent devices and external SIEM servers. These intermediaries receive, buffer, and forward event data, enabling agent devices to exfiltrate data even when direct external communication is blocked by network segmentation. This intermediary layer resolves the contradiction by providing indirect access paths that maintain data flow scalability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If hybrid SIEM solutions are implemented to manage segmented networks, then data exfiltration capability improves, but system complexity and version coupling requirements worsen

Engineering Contradiction:
Improvedata exfiltration capabilityVSAvoidsystem configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements automatic capability determination where agent devices autonomously assess their own exfiltration capabilities and select appropriate target devices without manual configuration. The system self-organizes by having devices automatically learn their network neighborhood and dynamically route data through capable intermediaries, eliminating the need for complex manual setup and version coupling while maintaining adaptability to segmented networks.

Inventive Principle:
Principle #25Self-service

3Productivity

If agent devices pre-process event data before exfiltration, then data analysis efficiency improves, but processing time and computational resources worsen

Engineering Contradiction:
Improvedata analysis efficiencyVSAvoiddata processing time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent implements selective pre-processing where agent devices perform only essential filtering and compression of event data before exfiltration, rather than complete analysis. High-value suspicious events are prioritized for immediate exfiltration and detailed analysis at the SIEM server, while routine events receive minimal processing. This partial action approach improves analysis efficiency by ensuring critical data is available faster, while accepting that not all data undergoes full pre-processing.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11196759B2SIEM system and methods for exfiltrating event data
Publication Date: 2021.12.07 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11196759B2 patent drawing
  • US11196759B2 patent drawing
  • US11196759B2 patent drawing

AI summary

Embodiments provide for a security information and event management (SIEM) system utilizing distributed agents that can intelligently traverse a network to exfiltrate data in an efficient and secure manner. A plurality of agent devices can dynamically learn behavioral patterns and/or service capabilities of other agent devices in the networking environment, and select optimal routes for exfiltrating event data from within the network. The agent devices can independently, selectively, or collectively pre-process event data for purposes of detecting a suspect event from within the network. When a suspect event is detected, agent devices can select a target device based on the learned service capabilities and networking environment, and communicate the pre-processed event data to the target device. The pre-processed event data is thus traversed through the network along an optimal route until it is exfiltrated from the network and stored on a remote server device for storage and further analysis.