Workflow Model Generation from Unstructured Security Logs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current automated event investigation solutions in cybersecurity are limited and ineffective due to their inability to adapt to the dynamic nature of cyber threats, lack of domain expertise, and failure to address company-specific vulnerabilities, making it difficult to detect and remediate advanced attacks.

Innovation Solution

A system that monitors user interfaces to generate activity logs, extracts features and common variables from unstructured data, and generates structured log events to create workflow models, which are then used to automate or assist workflows, leveraging natural language understanding and process mining to construct and optimize security processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If automated event investigation solutions are built in advance with fixed recipes, then implementation is straightforward, but the system cannot adapt to dynamic cyber threats and advanced attacks

Engineering Contradiction:
Improveadaptability to dynamic cyber threatsVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system transitions from static pre-defined investigation recipes to dynamic workflow models that are continuously constructed and updated based on real-time analysis of security event logs. The workflow models adapt to new threat patterns by learning from historical data and evolving attack methodologies, enabling the system to respond to dynamic cyber threats while maintaining manageable complexity through automated model generation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system automatically constructs workflow models from security event logs without requiring manual reconfiguration for each new threat scenario. The automated model construction process enables the system to self-adapt to emerging threats by deriving investigation workflows directly from log data patterns, reducing the need for expert intervention while improving adaptability.

Inventive Principle:
Principle #25Self-service

2Productivity

If unstructured data from activity logs is analyzed manually, then domain expertise can be applied, but the process is time-consuming and inefficient

Engineering Contradiction:
Improveworkflow efficiencyVSAvoidloss of domain expertise
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The system replaces manual analysis of unstructured activity logs with automated natural language processing and machine learning techniques. The automated model construction process extracts meaningful patterns from unstructured log data while preserving domain expertise by training models on expert-defined workflows, thereby improving productivity without losing the nuanced understanding that human experts provide.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system introduces workflow models as an intermediary layer between raw unstructured log data and investigative actions. These models serve as mediators that encode domain expertise and translate unstructured data into structured investigation workflows, enabling efficient automated processing while preserving the knowledge embedded in expert analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If comprehensive monitoring of user interfaces is performed to capture all activity logs, then complete workflow data is obtained, but system resource consumption increases

Engineering Contradiction:
Improvecompleteness of workflow dataVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system extracts only the essential features and common variables from comprehensive activity logs required for workflow model construction. By selectively extracting relevant information rather than processing all captured data, the system maintains complete and reliable workflow data while reducing the computational resources needed for analysis and model generation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system segments the log analysis process into distinct phases: comprehensive monitoring captures all activity, then feature extraction identifies relevant patterns, and finally common variable identification focuses on key elements for model construction. This segmentation enables complete data collection while optimizing resource usage by processing only essential information in subsequent stages.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11403577B2Assisting and automating workflows using structured log events
Publication Date: 2022.08.02 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11403577B2 patent drawing
  • US11403577B2 patent drawing
  • US11403577B2 patent drawing

AI summary

An example system includes a processor to monitor a user interface to generate activity logs including step-flows. The processor is to extract features and common variables from unstructured data in the activity logs and generate structured log events based on the extracted features and the common variables. The processor is to generate a workflow model based on the structured log events. The processor is to automate or assist workflow based on the generated workflow model.