IP Library Granted Patent US 9,069,930
Granted Patent B1
US 9,069,930 · App. 13/074,250 · Granted Jun 30, 2015

Security information and event management system employing security business objects and workflows

Inventor: Catherine V. Hart (Burlington, MA)
Assignee: EMC Corporation
G06F21/00G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,069,930
App. No.
13/074,250
Granted
Jun 30, 2015
Kind
B1
Abstract

A security information and event management (SIEM) system includes a data storage sub-system that stores (1) security data pertaining to security-related events and states of a production computer system, (2) security business objects (SBOs) as an abstraction layer over the security data, and (3) workflows which each include a set of the SBOs organized in a workflow-specific manner. Each SBO represents a security-related aspect of the production system and includes data queries to generate output data pertaining to the security-related aspect. Each workflow embodies a complex multi-step security analysis operation. In operation, security users of the SIEM system execute the workflows including the respective security business objects, resulting in a set of result data which identifies security threats and vulnerabilities of the production computer system. A workflow can provide additional contextualization for detected events, including asset data regarding the configuration of hosts in the data processing system which can be used to generate recommendations for remedial action, such as applying certain software patches to address a threat.

Claims (26)

1. A security information and event management system, comprising:

a data storage sub-system operative to store (1) security data from one or more sources, the security data pertaining to security-related events and states of a production computer system, (2) a collection of security business objects serving as an abstraction layer over the security data, each security business object representing a respective security-related aspect of the production system and including a respective set of queries of the sources of security data to generate respective output security data pertaining to the respective security-related aspect, the security business objects including (i) threat/attack objects including respective queries and logical operations on event data describing events in the production computer system, (ii) vulnerability objects including respective queries and logical operations on vulnerability data describing vulnerabilities of the production computer system, and (iii) asset objects including respective queries and logical operations on asset data describing configuration of assets in the production computer system, and (3) a collection of security workflows each including a respective set of the security business objects organized in a respective workflow-specific manner, each security workflow embodying a respective complex and multi-step security analysis operation with respect to the production computer system, at least one of the security workflows including a threat/attack object, a vulnerability object and an asset object arranged in user-specified sequence with output security data of one object serving as input security data to a next succeeding object; and

processing circuitry operative in response to user input to execute the security workflows including the respective security business objects, the execution of each security workflow resulting in a corresponding set of result data stored in the data storage sub-system, the result data identifying one or more security threats and system-specific vulnerability information regarding vulnerability of the production computer system to the security threats.

2. A security information and event management system according to claim 1 , employing a unified data ontology by which the security business objects reference the security data, the unified data ontology providing a single set of content, meaning and structure for the security data across all the sources.

3. A security information and event management system according to claim 1 , wherein the security business objects include respective processing routines providing respective functions selected from data filtering, data seeking, and data transformation.

4. A security information and event management system according to claim 1 , wherein each security workflow includes one or more context security business objects providing system-specific contextualization of a respective threat, the contextualization including vulnerability context data from which the vulnerability information in the result data is derived.

5. A security information and event management system according to claim 1 , wherein the security business objects of each workflow are functionally arranged such that output data from one or more of the security business objects serves as input data to a respective other one or ones of the security business objects, and each security business object performs a respective logical operation on its input data to generate its output data.

6. A security information and event management system according to claim 1 , wherein the security data is collected from the production computer system and includes data describing detected activities in the production computer system that may have security implications.

7. A security information and event management system according to claim 3 , wherein the security business objects are each arranged to obtain and process the security data pertaining to a respective distinct one of the security threats or a respective distinct one of a set of vulnerabilities of the production computer system to the security threats.

8. A security information and event management system according to claim 3 , wherein the security business objects include trigger-type security business objects and context-type security business objects, the processing routine of each trigger-type security business object employing gathered security data to direct continuing operation to a next step in a workflow, the processing routine of each context-type security business object operating to enrich security data gathered in one or more trigger-type security business objects in a workflow.

9. A security information and event management system according to claim 3 , wherein the security business objects are user-definable by user of the system.

10. A security information and event management system according to claim 4 , wherein the contextualization includes software asset data regarding a software configuration of a computer of the production computer system, the asset data identifying a patch level of the software configuration and used by a security business object of the workflow to generate a recommendation regarding installation of a software patch to address the respective security threat.

11. A security information and event management system according to claim 5 , wherein the workflows are user-definable by users of the system by selection and arrangement of existing security business objects.

12. A security information and event management system according to claim 6 , wherein the security data includes data collected from network event sources in the production computer system including application firewalls and intrusion detection sensors.

13. A method of operating a security information and event management system, comprising:

storing, in a data storage sub-system, (1) security data from one or more sources, the security data pertaining to security-related events and states of a production computer system, (2) a collection of security business objects serving as an abstraction layer over the security data, each security business object representing a respective security-related aspect of the production system and including a respective set of queries of the sources of security data to generate respective output security data pertaining to the respective security-related aspect, the security business objects including (i) threat/attack objects including respective queries and logical operations on event data describing events in the production computer system, (ii) vulnerability objects including respective queries and logical operations on vulnerability data describing vulnerabilities of the production computer system, and (iii) asset objects including respective queries and logical operations on asset data describing configuration of assets in the production computer system, and (3) a collection of security workflows each including a respective set of the security business objects organized in a respective workflow-specific manner, each security workflow embodying a respective complex and multi-step security analysis operation with respect to the production computer system, at least one of the security workflows including a threat/attack object, a vulnerability object and an asset object arranged in a user-specified sequence with output security data of one object serving as input security data to a next succeeding object; and

by processing circuitry in response to user input, executing the security workflows including the respective security business objects, the execution of each security workflow resulting in a corresponding set of result data stored in the data storage sub-system, the result data identifying one or more security threats and system-specific vulnerability information regarding vulnerability of the production computer system to the security threats.

14. A method according to claim 13 , employing a unified data ontology by which the security business objects reference the security data, the unified data ontology providing a single set of content, meaning and structure for the security data across all the sources.

15. A method according to claim 13 , wherein the security business objects include respective processing routines providing respective functions selected from data filtering, data seeking, and data transformation.

16. A method according to claim 13 , wherein each security workflow includes one or more context security business objects providing system-specific contextualization of a respective threat, the contextualization including vulnerability context data from which the vulnerability information in the result data is derived.

17. A method according to claim 13 , wherein the security business objects of each workflow are functionally arranged such that output data from one or more of the security business objects serves as input data to a respective other one or ones of the security business objects, and each security business object performs a respective logical operation on its input data to generate its output data.

18. A method according to claim 15 , wherein the security business objects are each arranged to obtain and process the security data pertaining to a respective distinct one of the security threats or a respective distinct one of a set of vulnerabilities of the production computer system to the security threats.

19. A method according to claim 15 , wherein the security business objects include trigger-type security business objects and context-type security business objects, the processing routine of each trigger-type security business object employing gathered security data to direct continuing operation to a next step in a workflow, the processing routine of each context-type security business object operating to enrich security data gathered in one or more trigger-type security business objects in a workflow.

20. A method according to claim 15 , wherein the security business objects are user-definable by user of the system.

21. A method according to claim 16 , wherein the contextualization includes software asset data regarding a software configuration of a computer of the production computer system, the asset data identifying a patch level of the software configuration and used by a security business object of the workflow to generate a recommendation regarding installation of a software patch to address the respective security threat.

22. A method according to claim 17 , wherein the workflows are user-definable by users of the system by selection and arrangement of existing security business objects.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2011
From: HART, CATHERINE V.
To: EMC CORPORATION
Reel/Frame 026113/0527 →