Unified Vulnerability Detection via Log and Threat Data Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current IT infrastructure lacks effective methods to detect and respond to exploited vulnerabilities in a timely and comprehensive manner, often relying on disparate security tools that fail to integrate threat data and historical logs efficiently, leading to inadequate security measures.
Innovation Solution
The integration of vulnerability data with event log data, change audit data, and third-party threat intelligence, using tools like security configuration management, vulnerability management, and event logging tools to generate interactive reports and modify assets to address exploited vulnerabilities, with features such as automated conversion of vulnerability scan data into forensic search strings and elastic time search capabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple disparate security tools are used to monitor vulnerabilities, then coverage of security monitoring is improved, but integration efficiency and response timeliness deteriorate due to lack of coordination between tools
Solution Approach 1:
The patent merges multiple disparate security tools (vulnerability scanners, log analysis tools, threat intelligence platforms) into a unified security monitoring system. This integration allows the system to maintain comprehensive security coverage while eliminating the coordination problems of separate tools, directly resolving the contradiction between monitoring coverage and integration efficiency.
Solution Approach 2:
The security system is designed with multi-functional capabilities that can perform vulnerability scanning, log analysis, threat intelligence correlation, and automated response coordination through a single unified platform. This universal approach improves both coverage and integration efficiency simultaneously, rather than requiring separate specialized tools.
2Measurement precision
If comprehensive vulnerability scanning is performed across all IT assets, then vulnerability detection capability is improved, but processing time and resource consumption worsen
Solution Approach 1:
The patent segments the vulnerability scanning process by prioritizing assets based on their criticality and exposure risk. High-value assets are scanned more frequently and thoroughly, while lower-priority assets receive less intensive scanning. This segmentation maintains high detection capability for critical assets while reducing overall processing time and resource consumption.
Solution Approach 2:
The system applies partial scanning actions to less critical assets and excessive (more thorough) scanning actions to critical assets. This differentiated approach ensures that vulnerability detection capability is maximized where it matters most, while processing time is optimized by not applying the same level of scrutiny to all assets uniformly.
3Measurement precision
If detailed forensic analysis is performed on all security events, then accuracy of exploit detection is improved, but productivity and response speed deteriorate
Solution Approach 1:
The patent applies local quality by performing detailed forensic analysis only on specific security events that exhibit characteristics of potential exploits, rather than analyzing all events uniformly. The system uses initial filtering rules to identify suspicious events, then applies comprehensive forensic analysis only to those cases, thereby maintaining high detection accuracy while preserving response speed.
Solution Approach 2:
The system performs partial forensic analysis on most events and excessive (detailed) analysis only on high-suspicion events. This approach ensures that when exploits are detected, the accuracy is very high, while the overall productivity is maintained by not spending excessive time analyzing every single security event in detail.
4Measurement precision
If manual analysis of security data is used, then depth of investigation is improved, but response timeliness and automation level worsen
Solution Approach 1:
The patent implements preliminary automated actions that prepare and pre-process security data before human analysts need to review it. The system automatically correlates data from multiple sources, performs initial filtering and prioritization, and presents pre-processed information to analysts. This preliminary automation maintains deep investigation capability while significantly improving response timeliness.
Solution Approach 2:
The system acts as an intermediary between raw security data and human analysts, automatically performing data correlation, filtering, and enrichment tasks. This intermediary layer provides automated preprocessing that maintains investigation depth while freeing analysts to focus on high-level decision-making, thereby improving both automation level and response timeliness.
Data Source
AI summary
Disclosed herein are representative embodiments of methods, apparatus, and systems for improving the functioning of IT assets in an IT infrastructure. The embodiments help secure and protect against outside cybersecurity attacks on IT assets and infrastructures, such as internet-centric attacks. Particular embodiments comprise detecting exploitable vulnerabilities of IT assets of an IT infrastructure, using the observed vulnerability data together with collected event log data to determine whether a respective vulnerability has actually been exploited for an asset, integrating change audit data and third-party threat data with the vulnerability data for exploited vulnerabilities, generating user interfaces/reports that display selected aspects of the integrated data, and/or modifying the asset to address the exploited vulnerability in response.


