SIEM Workflow Template for Cross-Manufacturer Security Task Automation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing SIEM devices lack the ability to automatically schedule and manage complex tasks across multiple security devices from different manufacturers, as tasks require different parameters and results cannot be transferred between them, leading to manual scheduling and inefficient network management.
Innovation Solution
Implementing a workflow template system within the SIEM device that defines abstract security tasks, allowing for automatic scheduling and execution across various security devices, with logical conditions to determine subsequent task execution based on previous results, enabling comprehensive management of network security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple security devices from different manufacturers are deployed to conduct independent security tasks, then network security coverage is improved, but task management complexity increases and results cannot be transferred between tasks
Solution Approach 1:
The patent implements a universal task template system that can define and manage security tasks across multiple security devices from different manufacturers. The SIEM device uses standardized task templates that can be applied universally to various security devices, enabling a single task definition to work across different device types and manufacturers, thus reducing management complexity while maintaining broad security coverage
Solution Approach 2:
The SIEM device acts as an intermediary between multiple security devices and the task management system. It receives task templates, schedules them to appropriate security devices, collects results, and performs correlation analysis. This intermediary role standardizes the interaction between diverse security devices and the management system, enabling result transfer and correlation across tasks that would otherwise be independent
2Reliability
If security devices conduct tasks independently with device-specific parameters, then device optimization is improved, but automation capability deteriorates due to inability to transfer results between tasks
Solution Approach 1:
The patent segments task management into distinct components: task template definition, task scheduling, result collection, and correlation analysis. By separating these functions, the system maintains device-specific task execution while enabling automated workflow orchestration at the SIEM level. Each security device executes tasks according to its capabilities, but the overall process is automated through the structured task template approach
Solution Approach 2:
The system uses parameterized task templates that can adapt to different security devices by substituting device-specific parameters while maintaining the overall task structure. This allows automated task execution across different devices with varying parameters, enabling result transfer and correlation without sacrificing device optimization
3Ease of operation
If manual scheduling is used for security tasks across different devices, then task execution flexibility is improved, but productivity decreases due to lack of automated workflow management
Solution Approach 1:
The patent implements preliminary action by pre-defining task templates with all necessary parameters, dependencies, and correlation rules before execution. These templates are stored and can be automatically scheduled and instantiated without manual intervention. This preliminary preparation enables both flexibility (through customizable templates) and productivity (through automated instantiation and execution)
Data Source
AI summary
Systems and methods are described for conducting work flows by an SIEM device to carry out a complex task automatically. According to one embodiment, an SIEM device may receive a work flow template defining at an abstract level multiple security tasks that are performed by one or more security devices. The SIEM device starts a work flow instance by deriving the work flow instance from the work flow template and scheduling the security tasks to be performed by the one or more security devices or replacements thereof. The SIEM device then collects results of security tasks.


