Containerized SIEM Deployment Architecture for Scalable Data Ingestion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions struggle to effectively leverage exponential data growth in security analytics due to limitations in data ingestion, processing, and storage, leading to significant blind spots in IT security and operations.

Innovation Solution

A containerized application software deployment architecture is implemented, allowing multiple instances of SIEM application components to run on each host, optimized for resource utilization, with dedicated hosts for ingress gateways and flexible storage configurations, enhancing data ingestion rates and system performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional security solutions are used to process security data, then data processing capability is limited, but infrastructure cost and complexity increase to handle exponential data growth

Engineering Contradiction:
Improvedata processing capabilityVSAvoidinfrastructure complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the SIEM application into multiple independent containerized components (ingress gateways, indexers, search heads, storage units) that can be deployed and scaled independently across multiple hosts. This modular architecture enables parallel processing of security data, significantly increasing throughput and processing capability while distributing infrastructure complexity across manageable units rather than requiring a monolithic complex system

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The containerized architecture creates universal building blocks that can perform multiple functions. For example, indexer containers can both ingest and index data, search head containers can query and analyze data, and the same container types can be replicated across different hosts to handle various data streams. This multi-functionality increases processing capability through resource sharing and eliminates the need for specialized hardware for each function, reducing overall infrastructure complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If more infrastructure is deployed to handle increased data rates, then data ingestion capability improves, but resource utilization decreases

Engineering Contradiction:
Improvedata ingestion rateVSAvoidresource utilization
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The patent merges multiple SIEM application instances into a coordinated federated cluster where containers are distributed across multiple hosts. Instead of deploying separate monolithic SIEM systems on each host (which would waste resources), the system combines multiple lightweight container instances that share common infrastructure resources such as storage backends, network connections, and processing power. This merging approach increases total data ingestion rate across the cluster while maintaining high resource utilization through shared resources

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent transitions from a single-dimension scaling approach (adding more powerful individual servers) to a multi-dimensional distributed architecture where scalability is achieved by adding container instances across multiple hosts in a federated cluster. This dimensional shift allows the system to increase data ingestion rates by distributing workloads across the cluster while efficiently utilizing the aggregate resources of all hosts, rather than requiring each individual host to be over-provisioned

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Use of energy by moving object

If containerized architecture is implemented to improve resource utilization, then infrastructure efficiency increases, but system complexity increases

Engineering Contradiction:
Improveresource utilizationVSAvoiddeployment complexity
Core Design Contradiction:
Use of energy by moving objectVSDevice complexity

Solution Approach 1:

The containerized SIEM components are designed to be self-service in nature, with each container instance automatically managing its own configuration, resource allocation, and operational parameters. The federated cluster enables automatic service discovery and coordination between components, reducing the need for manual configuration and management. This self-service capability allows the system to achieve high resource utilization through automated resource management while offsetting the increased deployment complexity through reduced operational overhead

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11388234B2Infrastructure for deploying a security information and event management application on a container platform
Publication Date: 2022.07.12 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11388234B2 patent drawing
  • US11388234B2 patent drawing
  • US11388234B2 patent drawing

AI summary

Embodiments described herein are generally directed to a containerized application software deployment architecture. According to an example, a system includes multiple hosts that are part of aa stretch cluster spanning multiple data centers. Each of the hosts include a processing resource, a memory, and a storage device. Each host of a first subset of the multiple hosts runs multiple containerized instances of a component of a Security Information and Event Management (SIEM) application within respective containers. At least one host of the multiple hosts is separate from the first subset and is dedicated to running at least one containerized ingress gateway application operable to load balance requests directed to the SIEM application among the multiple containerized instances running on the first subset of hosts.