Multi-Tenant Threat Hunting Platform With Persistent Query Pipelines
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current SIEM tools lack the ability to conduct real-time threat hunting across multiple tenant networks, are not scalable, and do not provide a unified threat-hunting environment for managed security service providers (MSSPs) to efficiently manage and respond to threats across diverse client databases, leading to inefficiencies and high operational costs.
Innovation Solution
A networked, computer-assisted threat hunting platform that enables continuous data communication and automated threat detection and response across multiple tenant networks, allowing for simultaneous querying, threat analysis, and automated or manual response through a unified development environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If current SIEM tools are used for threat detection, then basic security monitoring is achieved, but real-time threat hunting across multiple tenant networks is not possible and scalability is limited
Solution Approach 1:
The threat hunting platform is designed to perform multiple functions across diverse tenant networks simultaneously. It can query different database types (SQL, NoSQL, graph databases), execute multiple query languages, and adapt to various network architectures through a unified interface, enabling one system to serve multiple security needs across multiple clients.
Solution Approach 2:
The platform segments the multi-tenant environment into isolated query execution contexts while maintaining centralized management. Each tenant's network is accessed through separate data transfer pipelines with maintained connections, allowing independent threat hunting operations in each segment while leveraging shared analytical capabilities.
2Measurement precision
If manual threat hunting methods are used, then detailed threat analysis is possible, but operational costs are high and response time is slow
Solution Approach 1:
The platform pre-establishes data transfer pipelines to tenant networks before threat hunting operations begin. These pipelines maintain persistent connections, so when threats need to be hunted, the communication channels are already in place, eliminating connection setup time and enabling immediate query execution.
Solution Approach 2:
The system enables automated threat hunting where the platform independently executes queries, analyzes results, and generates reports without requiring constant manual intervention. The automated code editor and integrated development environment allow the system to self-manage query optimization and result interpretation, reducing both time and operational costs.
3Adaptability or versatility
If multiple separate systems are used to manage different tenant networks, then comprehensive coverage is achieved, but device complexity and operational costs increase
Solution Approach 1:
The platform merges multiple threat hunting capabilities into a single unified system. It combines support for various database types, query languages, and network protocols into one integrated platform that manages multiple tenant networks simultaneously, reducing the need for separate specialized tools for each tenant or database type.
Solution Approach 2:
The platform acts as an intermediary layer between security analysts and diverse tenant networks. It provides a standardized interface that abstracts the complexity of different database systems and network architectures, allowing analysts to hunt threats across multiple tenants without needing to understand the underlying complexity of each individual system.
4Speed
If continuous connection to tenant networks is established, then real-time data communication is enabled, but network overhead and resource consumption increase
Solution Approach 1:
Data transfer pipelines are established in advance before threat hunting operations are needed. These pre-established connections remain in a low-power standby state, allowing the system to immediately begin data communication when threats require investigation without the overhead of establishing connections in real-time, thus balancing speed with resource efficiency.
Data Source
AI summary
Systems and methods for a threat-hunting development environment are disclosed herein. The systems and methods can include: executing a networked, assisted, threat-hunting environment that, via a dedicated user interface, is configured to establish data transfer pipelines between the threat-hunting environment and the at least one tenant network, the data transfer pipelines maintaining a connection between the threat-hunting environment and the at least one tenant network during an active session, via the at least one SIEM server, to allow continuous data communication; query the at least one tenant network with a query developed via an integrated code editor; receive the query result data from the at least one tenant network: analyze, the result data for a detected threat in the at least one tenant network; and based on the analyzed result data, push a subsequent query to the at least one tenant network to respond to detected threat.


