Visual Security Workflow Using Standardized Content Bundles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security investigations in organizations require high skill levels and are inefficient due to the need for advanced automation scripts to analyze large numbers of events, leading to misallocation of security resources, as senior analysts perform tasks more suitable for junior-level analysts.

Innovation Solution

A tool that connects standardized content bundles to facilitate arbitrarily complex investigations, allowing an investigation server to provide and select content bundles based on input and output parameters, forming a single workflow to produce desired results, thus enabling less-skilled analysts to conduct complex investigations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional manual examination or script-based analysis is used to investigate security events, then investigation accuracy can be maintained, but the skill level required becomes very high and security resources are misallocated

Engineering Contradiction:
Improveinvestigation accuracyVSAvoidskill level required
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The investigation process is segmented into discrete, standardized content bundles that perform specific investigative actions. Each bundle handles a particular aspect of security event analysis (e.g., user behavior analysis, threat intelligence checking, device fingerprinting), allowing junior analysts to assemble complex investigations from pre-built components without needing to master advanced scripting or analysis techniques.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary layer of standardized content bundles that mediate between raw security events and final investigative conclusions. These bundles encapsulate complex analysis logic, transforming raw events into structured findings that junior analysts can interpret and combine, thereby maintaining investigation accuracy while reducing the skill barrier.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If senior-level analysts perform complex investigations using advanced automation scripts, then investigation quality is maintained, but security resources are misallocated as junior-level tasks are handled by senior personnel

Engineering Contradiction:
Improveinvestigation qualityVSAvoidresource allocation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The content bundles are designed to be universal and multi-functional, capable of handling various investigative scenarios through standardized interfaces and parameters. A single bundle can serve multiple investigation types (e.g., the same user behavior analysis bundle can be applied to both insider threat investigations and credential compromise investigations), allowing consistent quality across different investigation types while enabling junior analysts to perform diverse investigative tasks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system allows investigation complexity to be adjusted through parameter changes rather than requiring different skill levels. By modifying input parameters, time ranges, event types, and combination logic within the standardized content bundles, junior analysts can tackle investigations of varying complexity without needing advanced scripting skills, thereby improving resource allocation efficiency while maintaining investigation quality.

Inventive Principle:
Principle #35Parameter changes

3Quantity of substance

If a large number of events are analyzed in security reports, then comprehensive security monitoring is achieved, but the complexity of automation scripts required increases significantly

Engineering Contradiction:
Improvenumber of events analyzedVSAvoidautomation script complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The analysis of large volumes of security events is segmented into discrete content bundles, each handling a specific analytical function. Instead of requiring a single complex script to process all events, the system divides the workload into manageable bundles (e.g., one bundle for filtering events by type, another for enriching with threat intelligence, another for correlating with user behavior baselines), dramatically reducing the complexity required for each individual component while maintaining comprehensive event analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses standardized content bundles that can be copied and reused across multiple investigations. Once a bundle is created and validated for analyzing a particular type of security event, it can be replicated and applied to numerous other investigations involving similar events, eliminating the need to write complex automation scripts from scratch for each new investigation and reducing overall script complexity while maintaining comprehensive event coverage.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9306961B1Visual security workflow
Publication Date: 2016.04.05 EMC IP HLDG CO LLC
  • US9306961B1 patent drawing
  • US9306961B1 patent drawing
  • US9306961B1 patent drawing

AI summary

An improved technique involves providing a tool that connects standardized content bundles in order to carry out an arbitrarily complex investigation. An investigation server makes content bundles, which perform a standardized set of investigative actions based on a set of inputs, available to an investigation analyst. The investigation analyst selects particular content bundles based on a specified set of input parameters and a desired set of output parameters defining the investigation. The investigation analyst then connects the particular content bundles to form a single, complex workflow configured to produce the desired set of output parameters from the specified set of input parameters as a result of the investigation.