Unified Security Query Layer for Cross-Subsystem Threat Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing threat mitigation systems require unique queries for each security-relevant subsystem, complicating the process of gathering information about computer attacks.
Innovation Solution
A threat mitigation system utilizing a universal query language that enables communication across multiple security-relevant subsystems, facilitated by a probabilistic process for analyzing unstructured data to detect security events and automate query formulation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a unique query is formulated for each security-relevant subsystem, then information can be obtained from each subsystem, but the complexity of the threat mitigation system increases
Solution Approach 1:
The patent introduces a universal query language that can be used to query multiple different security-relevant subsystems (SIEM, IDS/IPS, firewall, etc.) with a single standardized interface. This eliminates the need to create unique queries for each subsystem, reducing system complexity while maintaining the ability to gather information from all subsystems. The universal query language acts as a multi-functional tool that works across diverse security subsystems.
Solution Approach 2:
The patent introduces an intermediary layer (the universal query language and associated translation mechanisms) between the user and the various security subsystems. This intermediary translates standardized universal queries into subsystem-specific queries and translates subsystem-specific responses into a unified format. This mediator approach reduces complexity by abstracting away the differences between subsystems while preserving their individual capabilities.
2Loss of information
If multiple security-relevant subsystems are utilized, then comprehensive security information is gathered, but the difficulty of querying these subsystems increases
Solution Approach 1:
The universal query language provides a unified interface for querying diverse security subsystems, making the querying process as easy as it is for a single subsystem while maintaining the ability to gather comprehensive information from multiple subsystems. Users can issue the same type of query across different subsystems without needing to learn multiple query syntaxes.
Solution Approach 2:
The intermediary layer automatically handles the complexity of querying multiple subsystems by translating universal queries into appropriate subsystem-specific queries. This eliminates the need for users to manually formulate complex queries for each subsystem, reducing query formulation difficulty while maintaining information completeness.
3Loss of information
If manual query formulation is used for each subsystem, then specific security data is retrieved, but the time required for information gathering increases
Solution Approach 1:
The universal query language enables users to retrieve security data from multiple subsystems using a single standardized query approach, dramatically reducing the time required compared to manually formulating and executing separate queries for each subsystem. The unified interface allows parallel or sequential querying of multiple subsystems efficiently.
Solution Approach 2:
The intermediary layer automates the query translation and execution process across multiple subsystems, eliminating manual intervention and reducing the time required for information gathering. The system automatically manages the complexity of coordinating queries across multiple subsystems and aggregates results efficiently.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A computer-implemented method, computer program product and computing system for: establishing connectivity with a plurality of security-relevant subsystems within a computing platform; defining a unified query on a unified platform concerning the plurality of security-relevant subsystems; denormalizing the unified query to define a subsystem-specific query for each of the plurality of security-relevant subsystems, thus defining a plurality of subsystem-specific queries; and providing the plurality of subsystem-specific queries to the plurality of security-relevant subsystems.