SOC Event Correlation for Faster Cyber Threat Triage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in managing cybersecurity risks and maintaining an up-to-date security posture due to the complexity of monitoring multiple threat intelligence feeds and network configurations, with a need for effective cyber security analysis, risk assessment, and remediation systems.
Innovation Solution
A cybersecurity information and event management system that integrates threat intelligence feeds with a Security Operations Center (SOC) server to analyze logs, categorize events, determine associated devices, and generate reports, providing real-time monitoring and proactive threat detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If organizations manually monitor multiple threat intelligence feeds and network configurations, then they can maintain security awareness, but the complexity and time required for analysis increases significantly
Solution Approach 1:
The patent combines multiple threat intelligence feeds, log sources, and network configuration data into a single centralized analysis platform. The system merges disparate data sources including threat feeds, device logs, and network configurations to provide unified security analysis, eliminating the need to manually monitor each source separately and reducing overall system complexity.
Solution Approach 2:
The analysis platform performs multiple functions within a single system: it ingests and processes threat intelligence feeds, analyzes device logs, compares configurations against security baselines, generates vulnerability assessments, and provides remediation recommendations. This multi-functional approach consolidates what would otherwise require multiple separate tools and processes.
2Measurement precision
If organizations implement comprehensive security monitoring across all computer devices, then they can identify vulnerabilities and threats, but the time and resources required for analysis increase
Solution Approach 1:
The system performs preliminary actions by continuously collecting and preprocessing security data from multiple sources in the background, maintaining updated threat intelligence feeds and security baselines before actual analysis is needed. Configuration comparisons and vulnerability assessments are prepared in advance, so when security events occur, the analysis can be performed rapidly using pre-computed data and established baselines.
Solution Approach 2:
The patent replaces manual mechanical analysis processes with automated computational systems. The analysis platform automatically ingests, parses, and correlates security data from multiple sources, performs configuration comparisons, and generates vulnerability assessments without human intervention, substituting automated information processing for manual analysis and dramatically reducing time requirements.
3Adaptability or versatility
If organizations use multiple separate security tools for different functions, then they can address specific security needs, but the overall system complexity and coordination difficulty increases
Solution Approach 1:
The analysis platform is organized into distinct functional modules that handle different security tasks: threat intelligence ingestion, log analysis, configuration comparison, vulnerability assessment, and remediation tracking. Each module performs a specific function but all modules communicate through a unified architecture, allowing the system to maintain specialized capabilities while providing coordinated operation through a single interface.
Data Source
AI summary
A cybersecurity information and event management system is provided. The system includes a security operations server in communication with a plurality of computer devices in a computer network. The at least one processor is programmed to: a) receive a plurality of logs from the plurality of computer devices in the computer network; b) analyze the plurality of logs to identify a plurality of events that occurred on the computer network; c) categorize the plurality of identified events; d) for each event in a first event category, determine one or more computer devices of the plurality of computer devices associated with the corresponding event; e) determine a plurality of attributes for each computer device associated with at least one event of the first event category; and f) generate a list of computer devices associated with the first event category including the corresponding plurality of attributes.


