Standard Metadata Model for Cross-System Log Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security management systems for detecting malicious activities across different products in enterprise computing networks cannot perform combined searches due to differing log structures and attributes, making it difficult to detect sophisticated attacks that exploit multiple vulnerabilities.

Innovation Solution

A standard metadata model is introduced to map log data from various computing systems to standardized attributes, creating connected metadata that allows for a central repository to associate and search across different systems, enabling correlated searches and event analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If different products use different log structures and attributes, then each product can be optimized for its specific security analysis needs, but combined search across multiple products becomes impossible

Engineering Contradiction:
Improveproduct-specific optimizationVSAvoidlog structure integration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a normalized log structure as an intermediary layer between different security products. This normalized structure contains common attributes (such as event time, source system, target system, event type) that enable combined searches across multiple products while preserving access to product-specific attributes. The normalization layer acts as a mediator that translates diverse log formats into a unified representation without losing important product-specific information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a normalized log structure is implemented within each product, then common search across logs within that product is enabled, but combined search across different products remains impossible due to different attributes

Engineering Contradiction:
Improvecommon search capabilityVSAvoidcross-product correlation
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent extends the normalized log structure to serve multiple products simultaneously by defining a universal set of common attributes that apply across all security products. This universal normalized structure enables a single search operation to query logs from multiple products while maintaining the ability to access product-specific attributes when needed. The design allows the same normalized structure to function for both intra-product and inter-product searches.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If sophisticated attacks exploit multiple vulnerabilities across different systems, then detection accuracy for individual vulnerabilities remains high, but detection of the combined attack chain becomes difficult

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidattack chain correlation
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the attack detection problem into two levels: individual vulnerability detection (maintaining high precision) and attack chain correlation (enabling combined analysis). The normalized log structure segments common attributes from product-specific attributes, allowing searches to operate at different granularities. This segmentation enables the system to detect individual vulnerabilities with high accuracy while also correlating events across multiple systems to identify coordinated attacks.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9876809B2Standard metadata model for analyzing events with fraud, attack, or any other malicious background
Publication Date: 2018.01.23 SAP SE
  • US9876809B2 patent drawing
  • US9876809B2 patent drawing
  • US9876809B2 patent drawing

AI summary

A standard metadata model for analyzing events with fraud, attack or other malicious background is disclosed. Log data for two or more computing systems is stored, and mapped to standardized attributes based on metadata entities defined for each computing system. A standard metadata model is defined for the computing systems, in which one or more standardized attributes of a first set of computing systems is associated with one or more standardized attributes of a second set of computing systems to define connected metadata that connects attributes of the associated metadata entities.