SIEM Workflow Template for Cross-Manufacturer Security Task Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing SIEM devices lack the ability to automatically schedule and manage complex tasks across multiple security devices from different manufacturers, as tasks require different parameters and results cannot be transferred between them, leading to manual scheduling and inefficient network management.

Innovation Solution

Implementing a workflow template system within the SIEM device that defines abstract security tasks, allowing for automatic scheduling and execution across various security devices, with logical conditions to determine subsequent task execution based on previous results, enabling comprehensive management of network security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security devices from different manufacturers are deployed to conduct independent security tasks, then network security coverage is improved, but task management complexity increases and results cannot be transferred between tasks

Engineering Contradiction:
Improvenetwork security coverageVSAvoidtask management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal task template system that can define and manage security tasks across multiple security devices from different manufacturers. The SIEM device uses standardized task templates that can be applied universally to various security devices, enabling a single task definition to work across different device types and manufacturers, thus reducing management complexity while maintaining broad security coverage

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The SIEM device acts as an intermediary between multiple security devices and the task management system. It receives task templates, schedules them to appropriate security devices, collects results, and performs correlation analysis. This intermediary role standardizes the interaction between diverse security devices and the management system, enabling result transfer and correlation across tasks that would otherwise be independent

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security devices conduct tasks independently with device-specific parameters, then device optimization is improved, but automation capability deteriorates due to inability to transfer results between tasks

Engineering Contradiction:
Improvedevice optimizationVSAvoidautomation capability
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The patent segments task management into distinct components: task template definition, task scheduling, result collection, and correlation analysis. By separating these functions, the system maintains device-specific task execution while enabling automated workflow orchestration at the SIEM level. Each security device executes tasks according to its capabilities, but the overall process is automated through the structured task template approach

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses parameterized task templates that can adapt to different security devices by substituting device-specific parameters while maintaining the overall task structure. This allows automated task execution across different devices with varying parameters, enabling result transfer and correlation without sacrificing device optimization

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If manual scheduling is used for security tasks across different devices, then task execution flexibility is improved, but productivity decreases due to lack of automated workflow management

Engineering Contradiction:
Improvetask execution flexibilityVSAvoidworkflow management efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-defining task templates with all necessary parameters, dependencies, and correlation rules before execution. These templates are stored and can be automatically scheduled and instantiated without manual intervention. This preliminary preparation enables both flexibility (through customizable templates) and productivity (through automated instantiation and execution)

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10356044B2Security information and event management
Publication Date: 2019.07.16 ATHENA SECURITY LLP
  • US10356044B2 patent drawing
  • US10356044B2 patent drawing
  • US10356044B2 patent drawing

AI summary

Systems and methods are described for conducting work flows by an SIEM device to carry out a complex task automatically. According to one embodiment, an SIEM device may receive a work flow template defining at an abstract level multiple security tasks that are performed by one or more security devices. The SIEM device starts a work flow instance by deriving the work flow instance from the work flow template and scheduling the security tasks to be performed by the one or more security devices or replacements thereof. The SIEM device then collects results of security tasks.