Web-Based Log Analysis for Vulnerability Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current log management systems are inefficient in detecting vulnerabilities and tracking their exploitation, as they typically analyze log data only after an intrusion is detected and discard original log data, leading to large storage needs and limited proactive vulnerability management.

Innovation Solution

A web-based log analysis system that combines log monitoring and vulnerability management, using a log management appliance to collect and archive log data, transmit it to cloud storage, and utilize a vulnerability database with signatures and traces to detect past exploits, enabling proactive vulnerability detection and remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If log data is archived and retained for vulnerability analysis, then vulnerability detection capability is improved, but storage space requirements increase

Engineering Contradiction:
Improvevulnerability detection capabilityVSAvoidstorage space
Core Design Contradiction:
ReliabilityVSVolume of stationary object

Solution Approach 1:

The patent extracts only the essential vulnerability-related information from log data by using vulnerability signatures and traces. Instead of storing and analyzing entire log files, the system extracts specific patterns and characteristics that indicate vulnerability exploitation, significantly reducing storage requirements while maintaining detection capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system creates simplified representations of vulnerability indicators through signatures and traces. These are essentially copied patterns that represent the essence of vulnerability exploitation without requiring storage of the original, potentially large log data. The signatures and traces serve as compact copies that enable efficient detection.

Inventive Principle:
Principle #26Copying

2Use of energy by moving object

If log analysis is performed only after intrusion detection, then resource usage is reduced, but response time to security threats increases

Engineering Contradiction:
Improveresource usageVSAvoidresponse time
Core Design Contradiction:
Use of energy by moving objectVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-defining vulnerability signatures and traces before actual vulnerability exploitation occurs. These signatures and traces are prepared in advance and stored in the vulnerability database, enabling immediate matching and detection when vulnerabilities are attempted, thus reducing response time without requiring continuous heavy resource usage for analysis.

Inventive Principle:
Principle #10Preliminary action

3Speed

If traditional log management systems are installed at customer premises, then local analysis speed is improved, but device complexity and storage requirements increase

Engineering Contradiction:
Improveanalysis speedVSAvoidsystem complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The system achieves multi-functionality by combining vulnerability detection, log analysis, and trace matching capabilities into a unified cloud-based platform. The same infrastructure serves multiple customers and multiple vulnerability types, reducing individual device complexity while maintaining fast analysis speeds through centralized processing and pre-computed signatures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9876813B2System and method for web-based log analysis
Publication Date: 2018.01.23 QUALYS
  • US9876813B2 patent drawing
  • US9876813B2 patent drawing
  • US9876813B2 patent drawing

AI summary

The technology described herein provides a novel system and method for web-based log analysis. The analysis combines the benefits of typical log monitoring systems with those of typical vulnerability managements systems. The synergy of the combined log monitoring and vulnerability management results in a single provider detecting vulnerability and subsequently accessing archived log data to detect if the vulnerability has been exploited in the past, identifying compromised machines for customers.