Distributed SIEM Agents for Segmented Event Data Exfiltration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional SIEM solutions face challenges in scaling to manage storage and analysis needs of thousands of endpoints and maintaining data exfiltration from segmented networks, with hybrid solutions requiring tight version coupling and exposing cloud-based SIEM providers to liability risks.

Innovation Solution

The implementation of agent devices that can pre-process and exfiltrate event data from segmented or unsegmented networks to a remote SIEM server, using distributed ledgers for data storage and dynamic connectivity configurations to determine the best path for data transmission, allowing for efficient and secure data collection and analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If conventional SIEM solutions aggregate event data from thousands of endpoints, then comprehensive security monitoring is achieved, but storage and analysis scalability deteriorates

Engineering Contradiction:
Improveevent data volumeVSAvoidstorage and analysis scalability
Core Design Contradiction:
Quantity of substanceVSProductivity

Solution Approach 1:

The system segments the centralized SIEM architecture into distributed agent devices deployed at different network locations. Each agent independently pre-processes event data locally, dividing the massive data aggregation task into smaller manageable units that can be handled independently, thereby improving scalability while maintaining comprehensive monitoring coverage

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Agent devices perform preliminary processing of event data before transmission to the SIEM server. This includes filtering, aggregation, and initial analysis of events at the source, reducing the volume and complexity of data that needs to be stored and analyzed centrally, thus improving storage and analysis scalability

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If hybrid SIEM solutions are implemented to enable data exfiltration from segmented networks, then data collection capability is improved, but liability risk for cloud providers increases

Engineering Contradiction:
Improvedata exfiltration capabilityVSAvoidliability risk
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

Agent devices autonomously determine their own capabilities and automatically learn their network neighborhood without requiring manual configuration or exposing cloud providers to direct liability. The agents self-manage the complex tasks of capability assessment, neighborhood mapping, and target device selection, making the system adaptable to segmented networks while isolating cloud providers from operational risks

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If agent devices communicate with multiple neighbors in segmented networks, then data transmission flexibility is improved, but network complexity increases

Engineering Contradiction:
Improvedata transmission flexibilityVSAvoidnetwork configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Agent devices automatically learn their network neighborhood by discovering neighboring agents and their capabilities without manual configuration. This self-learning mechanism enables flexible multi-path data transmission through segmented networks while keeping the system simple to deploy and maintain, as the complexity of network topology management is handled autonomously by the agents

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3970038B1SIEM system and methods for exfiltrating event data
Publication Date: 2023.03.29 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3970038B1 patent drawingFigure 1
  • EP3970038B1 patent drawingFigure 2
  • EP3970038B1 patent drawingFigure 3~4

AI summary

Embodiments provide for a security information and event management (SIEM) system utilizing distributed agents that can intelligently traverse a network to exfiltrate data in an efficient and secure manner. A plurality of agent devices can dynamically learn behavioral patterns and/or service capabilities of other agent devices in the networking environment, and select optimal routes for exfiltrating event data from within the network. The agent devices can independently, selectively, or collectively pre-process event data for purposes of detecting a suspect event from within the network. When a suspect event is detected, agent devices can select a target device based on the learned service capabilities and networking environment, and communicate the pre-processed event data to the target device. The pre-processed event data is thus traversed through the network along an optimal route until it is exfiltrated from the network and stored on a remote server device for storage and further analysis.