Systems, apparatus and methods for monitoring and updating detection systems within a digital environment

A management hub system optimizes detection systems in IT networks by updating event rules and adjusting sensitivity based on logged events, addressing the challenge of managing diverse detection technologies and maintaining comprehensive coverage.

GB2637444APending Publication Date: 2025-07-23SOCURA LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
GB2025005594
Authority / Receiving Office
GB · GB
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-10-10
Filing Date
2024-08-20
Publication Date
2025-07-23

AI Technical Summary

Technical Problem

Managing multiple detection technologies in IT networks with overlapping functionalities and diverse languages is challenging, making it difficult to maintain comprehensive and efficient detection coverage.

Method used

A management hub system that communicates with detection systems to update event rules, disables reporting during validation periods, and compares logged events to thresholds to determine remedial actions, ensuring optimal detection sensitivity and coverage.

Benefits of technology

The system maintains efficient detection coverage by adjusting event rules to prevent over-reporting or under-detection, enabling centralized management of diverse technologies and improving overall network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A system for managing a digital environment comprises: a management hub 110; and a detection system 120 to detect events as determined by event rules (210, fig. 2), and to communicate reports associated with detected events to the management hub (220, fig. 2); wherein the management hub is configured to: determine a set of active event rules associated with the detection system (610), compare the determined set of active event rules to a predetermined set of event rules (620) to establish a discrepancy (630), determine a change to the set of active event rules to address the discrepancy, and communicate an update to the detection system (640), wherein the change comprises: additional event rules to be included in the set of active event rules; and / or a change to at least one event rule of the set of active event rules. The detection system detects events based on the updated event rules (650). Generating of reports may be disabled during a validation period and event logs are generated instead and communicated to management hub 110. Logged events are compared to a threshold to determine whether a remedial action is required (670). Remedial actions comprise increasing or decreasing event detection sensitivity.
Need to check novelty before this filing date? Find Prior Art

Description

FIELD OF THE INVENTION The present invention relates to systems, apparatus and methods for managing a digital environment (such as one or more related networks) and updating detection systems operating within the digital environment. BACKGROUND IT networks host systems running detection protocols. For example, different software applications may run processes providing access control, antivirus and anti-malware software, cloud security, email security, application security and intrusion prevention systems. Managed Security Service Providers (MSSP) operate software that provides oversight, so that a centralised system can be used to keep track of the statuses of the various different platforms providing detection functionality. For example, as systems are updated with patches to address vulnerabilities, or updated to newer versions of the software, a MSSP may keep track of those updates and notify users of the current operational status of each system. A challenge facing MSSP is to manage multiple technologies at once, often implementing different protocols and having overlapping functionality. The systems may operate using different languages. It can be hard to keep track of the exact detection coverage since different technologies have overlapping scopes. The aim of the present systems, apparatuses and methods is to address or reduce one or more of the problems associated with the current state of the art. SUMMARY OF THE INVENTION According to an aspect of the invention, a system for managing a digital environment comprises: a management hub; and one or more detection systems configured to provide event detection functionality within the digital environment, each operable to detect events as determined by a set of one or more event rules, and in response to communicate reports associated with detected events to the management hub; wherein the management hub is operable to: communicate an update to a detection system, in which the update defines a change to the set of one or more event rules associated with that detection system; disable generating of reports by the updated detection system during a validation period, during which events that would otherwise have resulted in a report being generated are logged without generating a report; compare the logged events to a threshold to determine whether a remedial action is required, and if not, enable the updated detection system to generate reports. The update may define at least one of: one or more additional event rules to be included in the set of one or more event rules; and a change to at least one event rule of the set of one or more event rules. The set of one or more event rules may define one or more event types to be detected, and an additional event rule may define an additional event type to be detected. The set of one or more event rules may comprise a plurality of event rules comprising at least a first event rule and a second event rule, and wherein during the validation period the management hub may be configured to: compare logged events detected based on the first event rule to a first threshold to determine whether a remedial action is required for the first event rule; and compare logged events detected based on the second event rule to a second threshold to determine whether a remedial action is required for the second event rule, wherein the first threshold and second threshold are the same or different. The management hub may be configured to communicate a second update to the detection system in response to determining that remedial action is required, wherein the second update may define a remedial change to the set of one or more event rules associated with that detection system. The set of one or more event rules may comprise a plurality of event rules, and wherein the remedial change may cause at least a subset of the plurality of event rules to return to a previous configuration. The remedial change may cause removal from the set of one or more event rules of one or more additional event rules added to the set of one or more event rules in response to the update. The remedial change to the set of one or more event rules may cause the set of one or more event rules to return to a previous configuration for the set of one or more event rules. The remedial change to the set of one or more event rules may cause at least one event rule of the set of one or more event rules to be replaced with an updated event rule. The updated event rule may correspond to a same event type as the at least one event rule to be replaced, and the updated event rule may have an increased or decreased event detection sensitivity for the event type. The management hub may be configured to compare the logged events to a threshold defining at least one of a threshold number of detected events and a threshold rate of detected events. The management hub may be configured to compare the logged events to a threshold upper value and a threshold lower value defining a range. In response to the logged events corresponding to a value within the range, the management hub may be configured to determine the remedial action is not required, and wherein in response to the logged events corresponding to a value not within the range, the management hub may be configured to determine the remedial action is required. In response to the logged events corresponding to a value exceeding the threshold upper value, the management hub may be configured to determine the remedial action is required for decreasing event detection sensitivity. In response to the logged events corresponding to a value less the threshold lower value, the management hub may be configured to determine the remedial action is required for increasing event detection sensitivity. The set of one or more event rules may define one or more event detection conditions for triggering detection of events for one or more event types. The system may comprise a plurality of detection systems each configured to provide event detection functionality within the digital environment, wherein the management hub may be operable to manage each of the plurality of the detection systems. The plurality of the detection systems may comprise a first detection system configured to provide a first type of event detection functionality and a second detection system configured to provide a second type of event detection functionality, the first type of event detection functionality may be different from the second type of event detection functionality. The management hub may be configured to: determine the set of active event rules associated with the detection system; compare the determined set of active event rules to a predetermined set of event rules to establish a discrepancy; determine a change to the set of active event rules, to be implemented to address the discrepancy; and communicate the update to the detection system defining the change to the set of active event rules associated with the detection system, wherein the change defines at least one of: one or more additional event rules to be included in the set of active event rules; and a change to at least one event rule of the set of one or more event rules. According to another aspect of the invention, a system for managing a digital environment comprises: a management hub; and one or more detection systems configured to provide event detection functionality within the digital environment, each operable to detect events as determined by one or more event rules, and in response to communicate reports associated with detected events to the management hub; wherein the management hub is configured to: determine a set of active event rules associated with at least one detection system of the one or more detection systems, compare the determined set of active event rules to a predetermined set of event rules to establish a discrepancy, determine a change to the set of active event rules, to be implemented to address the discrepancy, and communicate an update to the at least one detection system defining the change to the set of active event rules associated with that detection system, wherein the change defines at least one of: one or more additional event rules to be included in the set of active event rules; and a change to at least one event rule of the set of active event rules. According to another aspect of the invention, a computer-implemented method comprises: detecting, by one or more detection systems, events within a digital environment, each of the one or more detection systems detecting events as determined by a set of one or more event rules associate with that detection system; in response to detecting events by a detection system, the detection system communicating reports associated with detected events to a management hub; in which the management hub performs the steps of: communicating an update to a detection system, in which the update defines a change to the set of one or more event rules associated with that detection system; disabling generating of reports by the updated detection system during a validation period, during which events that would otherwise have resulted in a report being generated are logged without generating a report; and comparing the logged events to a threshold to determine whether a remedial action is required, and if not, enabling the updated detection system to generate reports. According to another aspect of the invention, for a system comprising a management hub and one or more detection systems configured to provide event detection functionality within a digital environment, each of the one or more detection systems being operable to detect events as determined by one or more event rules, a computer-implemented method comprises the management hub performing the steps of: determining a set of active event rules associated with at least one detection system of the one or more detection systems, comparing the determined set of active event rules to a predetermined set of event rules to establish a discrepancy, determining a change to the set of active event rules, to be implemented to address the discrepancy, and communicating an update to the at least one detection system defining the change to the set of active event rules associated with that detection system, wherein the change defines at least one of: one or more additional event rules to be included in the set of active event rules; and a change to at least one event rule of the set of active event rules. Various aspect and features of the present invention are defined in the appended claims and within the text of the accompanying description. Example embodiments include at least a system, a method, a computer program and a machine-readable, non-transitory storage medium which stores such a computer program. BRIEF DESCRIPTION OF THE FIGURES In orderthatthe present disclosure may be more readily understood, preferable embodiments thereof will now be described, by way of example only, with reference to the accompanying drawings, in which: Figure 1 is a schematic diagram illustrating a system comprising a management hub and detection systems, in accordance with embodiments of the disclosure; Figures 2 and 3 are schematic diagrams illustrating examples of flow of data for controlling reporting functionality for a detection system; Figure 4 is a schematic flowchart illustrating a method performed by a management hub; Figure 5 is a schematic flowchart illustrating a method performed by a detection system; Figures 6 and 7 are schematic diagrams illustrating examples of flow of data for updating detection coverage for a detection system; Figure 8 is a schematic flowchart illustrating a method performed by a management hub; Figure 9 is a schematic flowchart illustrating a method performed by a detection system; and Figure 10 is a high-level diagram illustrating flow of data and interactions within a system. DETAILED DESCRIPTION OF THE DISCLOSURE We describe systems for managing a digital environment. By the term digital environment, we mean a network - or multiple related networks - each comprising network equipment enabling communication between devices, and connecting multiple endpoint devices. For simplicity, we will refer to the digital environment as a ‘network’, but it should be understood that the term encompasses systems in which multiple networks are being managed, via a central management hub that is able to communicate with one or more devices on each of the networks. In some embodiments of the disclosure a system is provided for managing detection systems running on a network, those systems providing services such as SIEM (security information and event management), EDR (endpoint detection and response) and NDR (network detection and response). Such systems may also include functions including access control, antivirus and anti-malware software, cloud security, email security, application security and intrusion prevention systems, for example. We do not intend the term “detection system” to cover firewall functionality - which relates instead to securing access rather than detecting events, perse. The system generally provides a management hub at a device on the network. The management hub operates to allow users to view and update details of the detection systems deployed on the network(s) via an interface. The hub provides an interface for receiving user input so as to define system behaviour, view system behaviour, view details of events occurring on the system (either in real-time or via reports or logs of events), and to update and control the various systems running on the network. The network detection systems running on the network are each configured to provide detection functionality of some type, in line with at least the examples given above. Of course, it will be apparent to the skilled person in this field that there are many types of detection systems suitable for operating on networks, and the present invention is envisaged to operate with any combination of those known systems. It is envisaged that the detection systems are each provided by software running on a server on the network, or on another device on the network. Multiple detection systems may operate from the same server or other device. One or more detection systems, or the management hub, may be provided in a cloud server, for example. The only requirement is that the systems can detect events on the network and communicate with devices on the network. Each detection system is operable to detect events on the network as determined by one or more event rules, and in response to detection of an event, to communicate a report associated with the event to the management hub. Events on the network may define any type of network-related activity, involving attempts to access ports, review of data content being communicated on the network, patterns of data communications or access, actions of software on devices on the network, or details of hardware operations on networked devices. Monitoring of such events and the types of events and actions being monitored are well understood in the technical field. Event rules define trigger points for generating reports of events that have been detected. For example, the rule may define thresholds for a number of access attempts to a particular device or port, before the pattern of behaviour is seen as a possible threat to the network or device malfunction. Event rules may define any type of trigger threshold for generating ‘error’ or ‘warning’ reports in relation to any type of network behaviour that is being monitored. These reports may include details of the devices involved in the event, details of communications sent or received, or any other relevant details defining the event which may be used as a reference by those monitoring the network. These are received by the management hub, and may be processed and displayed to a user - either live, or via logs that record such reports. The user may take action via a user interface of the management hub to react to the report, or to use further tools to investigate a possible error or threat on the network. The user may also use the interface to update settings to the devices on the network, which may include issuing updates to detection systems - to the event rules defining the types of reports being generated, and the frequency of the report. This may be achieved by altering a threshold level of activity, or a type of activity, which leads to a report being generated. If too many reports are received, or too many reports within particular categories, then the user or the system as a whole may struggle to interpret them. The optimised security system will issue the minimal number of reports required to detect errors and threats of note, requiring action by the management hub. There is a balance between overcaution - of generating too many reports - and a lack of caution in which problematic events go undetected. In general terms, the management hub operates to communicate updates to the detection system(s), in which an update defines at least one change to a set of one or more event rules associated with a detection system. An update may define at least one of a change to one or more of the event rules associated with a detection system, and / or one or more additional event rules to be employed by that detection system. In order to minimise disruption management of the network, resulting from a sudden increase or decrease in the number of reports being generated, the management hub acts to validate the behaviour of the detection system under the application of the updates. This is achieved by disabling generation of reports by the updated detection system during an initial validation period, during which the performance of the updated detection system is reviewed. During this validation period, events that would otherwise have resulted in a report being generated by the detection system are instead logged without generating a report. In this way, the potential for a sudden increase in reporting is avoided, and the potential for the management hub and its operators to be inundated with ‘false positive’ reports is thus also avoided. The management hub is able to access the event logs during this period, and to compare them (or metadata associated with event logs) to expected or desired levels of activity reporting. In other words, for each detection system or each type of event (or both), upper and / or lower thresholds may be set to govern an acceptable number of event logs to receive during a given period. In this way, the management hub compares the logged events produced by the updated detection system to a threshold, to determine whether a remedial action is required - to change the updated event rule in some way to bring the number of events being reported back within the accepted bounds. If the threshold is not exceeded, then the management hub reenables the updated detection system to generate reports. In other words, the updated activity level observed during the validation period is compared against thresholds that are set to define an acceptable level of activity. These may be defined by a user, or may be defined by the system, or may be set according to recommended levels defined by the software providers. The thresholds may be upper bounds or lower bounds, or define a range between upper and lower bounds. The thresholds associated with each network security system may differ, and the thresholds associated with logs of different types may also differ. The bounds may be variable over time, and may be set by the system in response to current or historic levels of reports being received at the management hub. Where it is established that the thresholds are broken (with either too many or too few events being logged), then the network management hub determines whether a remedial action is required. The remedial action may include determining to reverse the deployment of that update, and communicating that to the detection system so that the event rules may be reverted to their previous form. The remedial action may involve determining a change to the updated event rule and communicating that new updated rule to the detection system (for example, changing a detection threshold for triggering the event). The remedial action may involve generating different event rules and communicating those to the network security system either to replace the originally issued update, or to be applied in addition to it. In addition the management hub may operate to audit the detection systems running on the network by compiling event rules associated with each detection system. In this way, the hub may generate a “map” of the detection coverage present within the digital environment being monitored -associating the event rules with the many different areas of detection / security that are applicable to the network(s). By compiling a comprehensive list of the event rules being applied, the system (or a user of the system) may determine gaps in the security coverage, or weaknesses in the coverage. This can trigger development and roll-out of new event rules, or even new security systems, to provide the required additional coverage. In other words, the management hub is configured to determine a set of active event rules associated with the detection system(s) in their current state. The system may store one or more predetermined sets of event rules defining preferred levels of detection coverage within the digital environment. For example, a preferred set of event rules may provide comprehensive coverage over various differing types of detection available on the network(s). The system compares the active set of rules to a predetermined set, to establish whether a discrepancy exists between the two - indicating a deficiency in the detection coverage. In that case, one or more new event rules, or changes to active event rules, are determined in order to address the discrepancy. The rules, or updates to existing rules, may then be communicated as previously described, in order to update the behaviour of the detection system(s). In addition, the management hub may interact with the different detection systems using different communication protocols, languages, and settings. It is not unusual for systems on a network to be provided by different suppliers, be programmed in different languages, or receive configuration settings and provide report outputs in different formats. By using the management hub of the invention, users may interact with a single centralised system to adapt and monitor the behaviour of multiple different systems operating on the network. For example, the event rules may be specified at the hub using a standardised set of instructions and parameters, but may subsequently be communicated to the various different detection systems using different formats of message, different languages, and / or using different protocols. Referring now to Figure 1, a system 100 is shown comprising a management hub 110 and detection systems 120-1, 120-2 and 120-3. Figure 1 provides an example of a system in which the management hub 110 can act as a central management hub capable of communicating with each of the detections systems 120-1, 120-2 120-3 for management of a digital environment. Whilst Figure 1 shows an example system 100 comprising the management hub 110 and three respective detection systems, embodiments of the disclosure provide systems comprising any suitable number of respective detection systems. In some cases, a system may comprise a management hub and a single detection system. In other cases, a system may comprise a management hub and a potentially large number N of respective detection systems, where N may be any suitable value potentially of the order of tens or even hundreds. Therefore, more generally, in embodiments of the disclosure a system comprises a management hub and one or more detection systems each configured to provide detection functionality within a digital environment. Of course, in some embodiments of the disclosure a system can comprise a first management hub, a second management hub and a plurality of detection systems. The first management hub may be associated with a first subset of the plurality of detection systems and the second management hub may be associated with a second subset of the plurality of detection systems. Still referring to Figure 1, the management hub 110 is configured to communicate with the detection systems 120-1, 120-2, 120-3 either directly or indirectly (e.g. via one or more networked devices) using one or more of a wired and / or wireless communication. Any suitable wireless communication protocol may be used for communication between management hub 110 and a detection system. Suitable wireless communication protocols are generally known and are not discussed in detail. In some cases, a same wireless communication protocol may be used for communication between the management hub 110 and each of the detection systems. In other cases, two or more different wireless communication protocols may be used for communication between the management hub 110 and the detection systems. In some examples, the management hub 110 and the detection systems 120-1,120-2, 120-3 are part of a same Local Area Network (LAN). The detection systems (e.g. 120-1, 120-2, 120-3) provide event detection functionality and report generating functionality. A given detection system is operable to detect one or more events and generate one or more reports as determined by one or more event rules associated with that given detection system. A set of one or more event rules may specify one or more event detection conditions and one or more reporting conditions (e.g. trigger points). Event detection conditions may relate to conditions associated with any of one or more networks and / or one or more networked devices and may relate to any suitable network and / or device activity. For example, an event detection condition may relate to any suitable network activity which users may wish to monitor. Reporting conditions may specify conditions which when met trigger generating of one or more reports. The reporting conditions may specify one or more event-related conditions which when met trigger generating of one or more reports. For example, a reporting condition may specify a threshold associated with an event type (e.g. a threshold number and / or a threshold rate for the event type), such that in response to the detection system detecting events satisfying at least one of the threshold number and / or threshold rate, reporting can be triggered. More generally, event rules also define one or more reporting conditions (trigger points) for generating reports of events that have been detected. The threshold(s) used by the management hub for comparison with logged events during the validation period are set independently of threshold(s) associated with reporting conditions. In some examples, a reporting condition may specify that a report is to be generated for each detection of an event type. Alternatively, a reporting condition may specify that a report is be generated for each detection of an event type in response to the number of detections for that event type triggering a threshold (e.g. threshold number and / or threshold rate of detections). The above discussion refers to reporting condition(s) specified by one or more event rules, (e.g. a different reporting condition may be specified for different event types and / or a same reporting condition may be specified for one or more different event types). In some examples, a detection system may have an associated reporting condition which may be used for controlling reporting by the detection system. For example, a reporting condition associated with a detection system may specify that a report is to be generated for each detection of an event type. Alternatively, a reporting condition associated with a detection system may specify that a report is be generated for each detection of an event type in response to the number of detections for that event type triggering a threshold. Hence more generally, one or more reporting conditions for one or more event types may be specified by one or more event rules and / or associated with one or more detection systems for controlling reporting generating for detected events. Hence more generally, a given detection system is operable to detect one or more events and communicate one or more reports associated with one or more of the events. In embodiments of the disclosure, any of the detections systems 120-1, 120-2, 120-3 can provide event detection and communicate reports to the management hub 110. In this way, reports can be communicated to the management hub 110 for being assessed by users for purposes such as assessing errors or threats on a digital network. As explained previously, it can be desirable to allow updates to detection systems within a digital environment. The techniques to be discussed below provide systems for allowing updates to detection systems with improved control. In a first aspect, at least some of the systems and methods to be discussed allow deployment of one or more updates to one or more detection systems and control reporting functionality of one or more of the detection systems that apply one or more of the updates. In another aspect, at least some of the systems to be discussed allow detection of event rules currently used by one or more detection systems and deployment of one or more updates for improving detection coverage for one or more of the detection systems. In some aspects, at least some of the systems to be discussed below allow detection of event rules currently used by one or more detection systems and deployment of one or more updates for improving detection coverage for one or more of the detection systems, and also allow the deployment of one or more of the updates to one or more of the detection systems whilst controlling reporting functionality of one or more of the detection systems. Figure 2 schematically illustrates an example of flow of data and interaction between the management hub 110 and a detection system 120 (such as any of 120-1,120-2,120-3, for example). Figure 2 represents an example in which the management hub 110 is operable to communicate one or more updates to the detection system 120 and control reporting functionality of the detection system 120 that applies one or more of the updates. Figure 2 schematically illustrates an example for a single management hub and a single detection system, however it will be appreciated that the same operations may similarly be performed for interaction of the management hub with any suitable number of detection systems. The operations to be discussed with respect to Figure 2 may for example be performed in parallel for a number of respective detection systems so that a number of detection systems can be concurrently managed by the management hub. Figure 2 shows operations of the management hub 110 and the detection system 120 and it will be appreciated that the communications between the management hub 110 and the detection system 120 may be direct communications (i.e. without communicating via one or more intermediate devices) or may be indirect communications via one or more intermediate devices. At a step 210, the detection system detects one or more events. At a step 220, the detection system communicates one or more reports associated with one or more of the events to the management hub. The steps 210 and 220 provide event detection and reporting functionality and are performed by the detection system as determined by a set of one or more event rules associated with the detection system. Whilst the steps 210 and 220 are shown as separate steps, in some cases these operations may in fact be performed as a single step. At a step 230, the management hub communicates one or more updates to the detection system. One or more of the updates specify a change to the set of one or more event rules associated with the detection system (also referred to as the initial set of event rules associated with the detection system). A change to the set of one or more event rules may be in the form of a change (modification) to one or more of the event rules associated with the detection system and / or one or more additional event rules to be employed by the detection system. The updates may for example have been specified by a user and / or may be pre-defined updates stored by the management hub with a scheduled time for deployment. Hence, the step 230 may be performed in response to a request from a user to deploy one or more updates for the detection system and / or based on stored information indicative of a deployment time scheduled for one or more updates. At a step 240, the detection system detects one or more events. At a step 250, the detection system communicates one or more event log(s) (or metadata associated with one or more event logs) for one or more of the events detected by the detection system to the management hub. The steps 240 and 250 are performed by the detection system based on the updated set of one or more event rules as updated by one or more of the updates communicated at the step 230. Whilst the steps 240 and 250 are shown as separate steps, in some cases these operations may in fact be performed as a single step. Therefore, the steps 210 and 220 are performed as determined by the previous set of one or more event rules (also referred to as the initial set of event rules), and the steps 240 and 250 are performed as determined by the updated set of one or more event rules (for brevity of explanation the term updated detection system is used to refer to the detection system using the updated set of one or more event rules). In the techniques of the present disclosure, generating of reports by the updated detection system is disabled during a validation period. The updated detection system generates an event log for one or more detected events and communicates the event log to the management hub. In this way, operations for generating reports and sending reports to the management hub are temporarily disabled following an update to the set of one or more event rules. At a step 260, the management hub evaluates the event log(s) (or the metadata associated with the event logs) against one or more thresholds. Preset information specifying one or more thresholds may be stored by the management hub to be used to evaluate one or more event logs received from the detection system. The metadata associated with an event log may be indicative of one or more properties for the event log. The one or more properties may comprise one or more of: a number of detections associated with an event rule (or an event type); a rate of detections associated with the event rule; and timings associated with the detections (e.g. a time window). The metadata may include details of event rule execution such as: rule query, execution time, searched time window and number of matched events. At a step 270, responsive to the evaluation at the step 260, the management hub can communicate, to the detection system, an action to be taken. At a step 280, responsive to receiving from the management hub data indicative of an action to be taken, the detection system performs the action. The action to be taken may correspond to an event rule update action to update the updated set of one or more event rules. Alternatively, the action to be taken may correspond to a report enabling action to enable the detection system to generate reports. For example, in response to the evaluation at the step 260 indicating that the event log triggers one or more of the thresholds, at the step 270 an event rule update action may be instructed by the management hub. In this way, the set of one or more event rules can be updated in a way that modifies the subsequent behaviour of the detection system in a way that subsequently has a reduced likelihood of triggering one or more of the thresholds. More generally, the event rule update action can be considered a corrective or remedial action that can mitigate for one or more changes caused by the update previously instructed by the management hub at the step 230. Conversely, in response to the evaluation at the step 260 indicating that the event log does not trigger one or more of the thresholds, at the step 280 a report enabling action to enable the detection system to generate reports can be instructed by the management hub. Therefore, following the update instructed by the management hub at the step 230, one or more event logs can be accessed at the management hub for determining whether a corrective update to the set of one or more event rules should be performed, and in response to determining that a corrective update is not needed, the management hub can instruct the detection system to enable generating of reports so that the update previously instructed by the management hub at the step 230 is deployed for generating reports. Figure 2 schematically illustrates an example in which the management hub instructs an update to the set of one or more event rules (at the step 230) and generating of reports by the detection system is disabled until the management hub instructs the detection system to enable generating of reports (at the step 280). Hence, in this case the detection system may receive a communication indicative of one or more updates to one or more event rules and disable generating of reports until another communication is received which is indicative of one of: i) a corrective update action to be applied to one or more event rules; and ii) a report enabling action to enable generating of reports. Therefore, in the example of Figure 2, the management hub disables generating of reports by the updated detection system during a validation period. During the validation period, events that would otherwise have resulted in a report being generated are logged without generating a report. In the example of Figure 2, the validation period (that is, the time period from applying the updated event rule(s) to performing the remedial action or the action of enabling reports) may be of any suitable duration (e.g. of the order of seconds, minutes, hours, or days). In some examples, the duration of the validation period may vary depending on decision making at the management hub. Alternatively or in addition, the duration of the validation period may be set in advance to a predetermined duration. For example, the management hub may receive event logs from the detection system and perform the evaluation (at the step 260) in response to receiving a sufficient number of event logs for allowing an evaluation. Hence, a time at which the evaluation is performed (and at which the validation period ends) may vary depending on a rate at which event logs are received. The validation period may thus have a duration that varies accordingly so as to allow gathering of sufficient statistics at the management hub. More generally, the management hub may use a validation period of dynamic time duration or predefined time duration. In some cases, the evaluation (at the step 260) may in fact comprise a number of evaluation steps. A first evaluation may be performed, and in response to determining that the event log(s) trigger one or more of the thresholds, it may be decided at that stage that corrective action is required. However, in response to the first evaluation determining that the event log(s) do not trigger one or more of the thresholds, it may be decided to continue the validation period and a second evaluation may be performed. In some cases, the validation period may be of a predefined duration. For example, a predefined duration such as N seconds (where N may be a value in the range 5 seconds to 7 days) may be specified in advance for the validation period. As explained above, in the example of Figure 2, generating of reports by the detection system is disabled until the management hub instructs the detection system to enable generating of reports. In other cases, the duration of the validation period may be set in advance to a predetermined duration and the detection system can be instructed to disable generating of reports for the predetermined duration. Accordingly, generating of reports by the detection system can be disabled for at least the predetermined duration and the detection system can re-enable generating reports upon expiry of the predetermined duration. In this way, in response to the management hub determining that corrective action is not required and that generating of reports by the updated detection system can be enabled, the management hub need not communicate an instructing signal back to the detection system, since the detection system will automatically commence report generating itself upon expiry of the predetermined duration. Figure 3 schematically illustrates an example of this situation. In the example of Figure 3, the steps 210, 220, 230, 240, 250 and 260 are the same as discussed previously with respect to Figure 2. At a step 271, the management hub determines whether action is to be taken in response to the evaluation at the step 260. In response to determining that no action is to be taken by the management hub (e.g. the evaluation indicates that current behaviour of the updated detection system is within an acceptable range), the management hub proceeds to a step 290 to end the processing in respect of the update instructed at the step 230. In this case, the detection system can proceed to a step 281 to automatically enable generating of reports after expiry of the predetermined duration for the validation period. At the step 271, in response to determining that action is to be taken by the management hub, the management hub proceeds to communicate a corrective action to the detection system. At a step 282, the detection system performs the corrective action to apply an update to one or more event rules. Hence, in the example of Figure 3, a predetermined duration (e.g. T seconds) can be specified for the validation period. The validation period may correspond to the period of time starting at the step 240 and ending at the step 281, as schematically shown in Figure 3. The management hub can be operable to complete the step 271 prior to expiry of the predetermined duration so that if it is determined that action is to be taken, the management hub can communicate the instructing signal to apply corrective action. This is schematically represented in Figure 3. In particular, a second predefined duration (e.g. P seconds, where P is a value less than T) shorter than the predefined duration can be specified for completing the step 271. Therefore, prior to, or upon, expiry of the second predefined duration, the management hub can make a decision as to whether action is to be taken in response to the evaluation at the step 260. Figures 2 and 3 schematically illustrate examples of flow of data for a system comprising a management hub and one or more detection systems. Figures 4 and 5 are schematic flowcharts illustrating a method 400 that may be performed by the management hub and a method 500 that may be performed by a detection system. In the following discussion, for brevity of explanation the methods 400 and 500 will be discussed with respect to a respective one of the one or more detection systems, however it will be appreciated that the methods may in fact be performed for any suitable number of detection systems. Referring to method 400 in Figure 4, at a step 410 a management hub (e.g. management hub 110) communicates one or more updates to one or more detection systems for updating a set of one or more event rules associated with one or more of the detection systems. At a step 420, the management hub receives one or more event logs (e.g. metadata for one or more event logs) that have been generated by an updated detection system (i.e. a detection system performing event detection on the basis of an updated set of one or more event rules). At a step 430, the management hub evaluates one or more of the event logs with respect to one or more thresholds. At a step 440, in response to the evaluation, the management hub communicates an action to the detection system, in which the action specifies one of: a remedial action (corrective action) that can mitigate for one or more changes caused by the update previously instructed by the management hub at the step 410; and a report enabling action to enable the detection system to generate reports. Of course, in some cases enabling of report generating by the updated detection system may occur upon expiry of the validation period without needing communication of a report enabling action at the step 440, as already explained above. Referring to method 500 in Figure 5, at a step 510 a detection system (e.g. any of detection systems 120-1,120-2 and 120-3) receives, from a management hub (e.g. management hub 110), one or more updates. At a step 520, the detection system, using a set of one or more event rules having been updated based on one or more of the updates received from the management hub, detects one or more events. At a step 530, the detection system communicates, to the management hub, an event log for one or more of the detected events. At a step 540, the detection system receives, from the management hub, a communication indicative of an action to be taken by the detection system. At a step 550, the detection system performs the action, in which the action specifies one of: a remedial action (corrective action) that can mitigate for one or more changes caused by the update(s) previously instructed by the management hub; and a report enabling action to enable the detection system to generate reports. Of course, in some cases enabling of report generating by the updated detection system may occur upon expiry of the validation period without needing to receive a report enabling action at the step 540, as already explained above. In particular, a predefined duration for the validation period may for example be included in a same message providing the one or more updates. For example, the one or more updates may have associated time information specifying a duration for the validation period after which report generating is to be automatically enabled, and the management hub can be operable to communicate the remedial action prior to expiry of the validation period, if needed. Hence more generally, in some embodiments of the disclosure a computer-implemented method comprises: detecting, by one or more detection systems (e.g. any of detection systems 120-1, 120-2 and 120-3), events within a digital environment, each of the one or more detection systems detecting events as determined by a set of one or more event rules associate with that detection system; in response to detecting events by a detection system, the detection system communicating reports associated with detected event to a management hub (e.g. management hub 110); in which the management hub performs the steps of: communicating an update to a detection system, in which the update defines a change to the set of one or more event rules associated with that detection system; disabling generating of reports by the updated detection system during a validation period, during which events that would otherwise have resulted in a report being generated are logged without generating a report; and comparing the logged events to a threshold to determine whether a remedial action is required, and if not, enabling the updated detection system to generate reports. Figures 1-5 refer to systems and methods for deployment of one or more updates to one or more detection systems and control of reporting functionality of one or more of the detection systems that apply one or more of the updates. In some examples, processing for communicating an update to a detection system may be manually instructed by a user. For example, a user associated with the management hub may specify one or more updates to be applied to one or more detection systems (e.g. any of 120-1, 120-2, 120-3) and cause the management hub to communicate the one or more updates. In some examples, a user may specify one or more updates and processing for causing the one or more updates to be applied may be performed at a later time such as that of a prescheduled maintenance. The techniques to be discussed with reference to Figures 6-9 refer to systems and methods for detection of event rules currently used by one or more detection systems and deployment of one or more updates for improving detection coverage for one or more of the detection systems. It will be appreciated that any of the techniques discussed with respect to Figures 1-5 may be suitably combined with any of the techniques to be discussed with reference to Figures 6-9. In particular, the one or more updates discussed with respect to Figures 1-5 may be communicated responsive to an outcome of comparing a set of one or more active event rules to a predetermined set of event rules. Figure 6 schematically illustrates an example of flow of data and interaction between the management hub 110 and the detection system 120 (such as any of 120-1, 120-2, 120-3, for example). Figure 6 represents an example in which the management hub 110 is operable to provide functionality for improving detection coverage for one or more of the detection systems. The operations to be discussed with respect to Figure 6 may for example be performed in parallel for a number of respective detection systems so that a number of detection systems can be concurrently managed by the management hub. Figure 6 shows operations of the management hub 110 and the detection system 120 and it will be appreciated that the communications between the management hub 110 and the detection system 120 may be direct communications (i.e. without communicating via one or more intermediate devices) or may be indirect communications via one or more intermediate devices. At a step 610, the management hub determines a set of one or more active event rules associated with the detection system 120. In some cases, the management hub may determine the set of active event rules based on a history of updates previously communicated by the management hub to the detection system 120 (e.g. a history of updates sent to the detection system may be maintained at the management hub). More generally, the management hub may have knowledge of one or more previous updates deployed to the detection system 120 and on this basis may determine a set of active event rules associated with the detection system 120 (for example, the management hub may store a log or other similar dataset of previous updates sent to various detection systems). Alternatively or in addition, the management hub may query the detection system 120 to obtain information indicative of a set of active event rules associated with the detection system 120. Alternatively or in addition, detection system 120 may periodically communicate data indicative of a set of active event rules associated with the detection system 120 to the management hub. Any of the above-mentioned techniques may be used to determine a set of one or more active event rules associated with a detection system. References to determining a set of one or more active event rules may refer to determining metadata associated with a set of one or more active event rules. For example, the management hub may query the detection system 120 to obtain metadata associated with a set of active event rules associated with the detection system 120. At a step 620, the management hub evaluates the determined set of active event rules with respect to a predetermined set of event rules. The management hub may compare the set of one or more active event rules with one or more event rules of the predetermined set of event rules. Metadata associated with the set of active event rules may be compared with metadata associated with a predetermined set of event rules. At a step 630, the management hub determines whether there is a discrepancy for the evaluation of the set of active event rules with respectto the predetermined set of event rules. Generally speaking, the management hub uses the predetermined set of rules as a reference and a discrepancy between the set of active event rules and the predetermined set of event rules is indicative of one or more deficiencies in the detection coverage currently provided by the detection system. Whilst the steps 620 and 630 are shown as separate steps, these operations may in fact be performed as a single step. Hence, the management hub can be operable to evaluate the determined set of active event rules with respect to a predetermined set of event rules to establish a discrepancy. In some cases, the management hub may be operable to select the predetermined set of event rules from a plurality of candidate sets of event rules. For example, the management hub may store a plurality of predetermined event rule sets. The management hub may select a respective set in dependence upon one or more properties associated with the detection system and use the selected set for the evaluation at the step 620. One or more properties associated with the detection system such as one or more of a device type, event detection type, a protocol, programming language and service type may be used for selection of a predetermined set of event rules from a plurality of candidate sets of event rules. In response to determining that no discrepancy is present, it is thereby established that the set of active event rules already provide a desired detection coverage. The management hub therefore proceeds to a step 635 to end the processing in respect of the active event rules associated with the detection system 120. In response to determining that one or more discrepancies are present, the management hub proceeds to a step 640 at which the management hub communicates one or more updates to the detection system for updating a set of one or more event rules associated with the detection system. The management hub communicates an update to the detection system for updating a set of active event rules associated with the detection system. The update may specify one or more additional event rules (also referred to as new event rules) and / or one or more changes to one or more of the active event rules. The update may specify one or more updates to be used to modify, replace and / or supplement the set of active event rules associated with the detection system. More generally, the update specifies an update for a set of active event rules associated with the detection system so as to address the discrepancy. In some cases, the management hub may communicate an update comprising some or all of the predetermined set of event rules. An update comprising some or all of the predetermined set of event rules may be used to replace the set of active event rules or may be added to the set of active event rules. At a step 650, the detection system detects one or more events based on the event rules as updated by one or more of the updates communicated at the step 640. Therefore, Figure 6 provides an example in which the management hub provides one or more updates to the detection system to update detection coverage for the detection system. Following the update to the detection system, the detection system may proceed to provide event detection functionality and report generating functionality as determined by the updated set or one or more event rules associated with the detection system. In some cases, following the update, generating of reports by the updated detection system may be disabled during a validation period. Figure 7 schematically illustrates an example of this situation. The management hub may store a repository (e.g. one or more databases) of predetermined event rules which can be used for the purposes of steps 620 and 630. The repository may potentially store tens, hundreds or even thousands of predetermined event rules. The repository may also store mappings of predetermined event rules and / or predetermined sets of event rules to detection system types. Alternatively or in addition, the repository may store mappings of predetermined event rules and / or predetermined sets of event rules to tactics, techniques and procedures (TTPs). For example, the MITRE ATT&CK ® framework may be used. A detection system may similarly be associated with a TTP. For example, prior to onboarding, a detection system may undergo a MITRE ATT&CK ® data source mapping. Accordingly, predetermined event rules and / or predetermined sets of event rules can be mapped to TTPs, and similarly detection systems can also be mapped to TTPs. The management hub may thus be operable to: determine a set of active event rules associated with a detection system; determine at least one of a detection system type and a TTP associated with that detection system; determine, from the repository, a predetermined set of event rules associated with at least one of a same detection system type and a same TTP as the set of active event rules; and compare the set of active event rules to the predetermined set of event rules. More generally, the management hub may be operable to select the predetermined set of event rules based on one or more of detection system type mappings and TTP mappings. The management hub can thus compare the set of active event rules to the predetermined set of event rules. Various approaches may be used for comparison of a set of active event rules to a predetermined set of event rules. In some examples, metadata associated with the set of active event rules may be compared with metadata associated with a predetermined set of event rules. For example, event rule metadata may be indicative of one or more of: rule name, rule description; rule log sources, rule severity; rule detection query; rule mappings; and any combination thereof. One or more of these properties may be compared for determining differences between a set of active event rules and a predetermined set of event rules. As explained above, in some cases event rule metadata for a set of active event rules associated with a detection system may be stored at the management hub (e.g. known from historical updates communicated by the management hub) or the management hub may query a detection system to pull such metadata. Comparison of a set of active event rules and a predetermined set of event rules may indicate one or more differences such as one or more missing event rules and / or one or more different event rule sensitivities. More generally, one or more gaps in the detection coverage provided by the set of active event rules can be determined and the set of active event rules can be updated by adding one or more new event rules and / or modifying one or more of the set of active event rules using the predetermined set of event rules. In some examples, in response to determining presence of one or more differences, the management hub may communicate the predetermined set of event rules as an update for replacing (or supplementing) the set of active event rules. Any potential conflicts (e.g. duplication of event rules) may be resolved by the detection system. More generally, the detection coverage for a detection system can be updated based on the predetermined set of event rules. In some embodiments of the disclosure, the management hub may generate a detection system coverage report for one or more of the detection systems. A detection system coverage report for a respective detection system may comprise information indicative of at least one of: a deployed event rule TTP coverage for the detection system; and one or more available event rule TTP coverages for the detection system (i.e. available for being deployed based on the repository). The management hub may generate a detection system coverage report for a system comprising a plurality of detection systems. A detection system coverage report for a system comprising a plurality of detection systems may comprise information indicative of at least one of: one or more available detection systems and one or more associated TTP coverages (i.e. available for being deployed based on the repository); one or more new detection systems (different from the current detection systems) available based on the repository; and one or more detection systems currently having no detection coverage in the repository (i.e. no predetermined rules available in the repository for such detection systems). The management hub may generate the detection system coverage report for the system and this may be used to define a queue of work for a developer that outlines work to be carried out across the plurality of detection systems to allow for targeted development of custom event detection rules. A user may take action via a user interface of the management hub to react to one or more of the detection system coverage reports, and / or use further tools to investigate coverage discrepancies. Figure 7 schematically illustrates an example of flow of data and interaction between the management hub 110 and a detection system 120 (such as any of 120-1,120-2,120-3, for example). In Figure 7, the steps 610, 620, 630, 635, 640 and 650 are the same as discussed previously with respect to Figure 6. Figure 7 includes the additional steps 660,670, 680 and 690 which are the same as the steps 250, 260, 270 and 280 discussed previously with respect to Figure 2. In Figure 7, the steps 650 and 660 are performed as determined by the updated set of one or more event rules (i.e. the updated detection system). Generating of reports by the updated detection system is thus disabled during a validation period. Rather than generating reports, the updated detection system instead generates an event log for one or more detected events and communicates the event log (or metadata associated with the event log) at the step 660 to the management hub. In this way, following an update to the set of one or more event rules that seeks to update and improve detection coverage for the detection system, operations for generating reports and sending reports to the management hub are temporarily disabled. Instead, the management hub evaluates the event log(s) (or the metadata) against one or more thresholds. In the case that the update causes an undesired a change in behaviour of the detection system (e.g. by triggering over-reporting by the detection system), an action can be communicated to the detection system and performed so as to provide a corrective update. On the other hand, in the case that the update does not cause an undesired change (e.g. a suitable level of reporting that may achieve a balance between overcaution - of generating too many reports - and a lack of caution in which problematic events may go undetected), an action can be communicated to the detection system for enabling report generating functionality by the updated detection system. Still referring to Figure 7, in some cases the management hub may not need to communicate an action for enabling the updated system to generate reports. Instead, the updated system may, by default, enable report generating after an elapse of a predetermined period of time (e.g. as discussed previously with respect to Figure 3). In some examples, at the same time as communicating an update to the detection system, the management hub may specify a duration for the predetermined period of time for which report generating is to be disabled at the detection system. Alternatively or in addition, in some examples a detection system may be programmed so that in response to applying an update to the set of one or more event rules associated with that detection system, the detection system is operable to automatically disable generating of reports for the predetermined period of time. Hence, in this latter case the management hub may need only communicate an update to the detection system to thereby disable generating of reports for at least the predetermined period of time. Figures 8 and 9 are schematic flowcharts illustrating a method 800 that may be performed by the management hub 110 and a method 900 that may be performed by a detection system 120. In the following discussion, for brevity of explanation the methods 800 and 900 will be discussed with respect to a respective one of the one or more detection systems, however it will be appreciated that the methods may in fact be performed for any suitable number of detection systems. Referring to the method 800 in Figure 8, at a step 810 the management hub 110 determines a set of one or more active event rules associated with the detection system(s) 120. At a step 820, the management hub evaluates (e.g. compares) the determined set of active event rules with respect to a predetermined set of event rules to establish a discrepancy. At a step 830, the management hub determines one or more new event rules, and / or changes to active event rules, to be implemented to address the discrepancy. In some examples, in response to establishing presence of a discrepancy at the step 820, at the step 830 the management hub may determine some or all of the predetermined set of event rules as one or more of the new event rules to be implemented. For example, in response to establishing presence of a discrepancy with respect to the predetermined set of rules, the management hub may determine that the entirety of the predetermined set of rules is to be communicated to the detection system as an update (e.g. to be used in place of or in addition to the active event rules). At a step 840, the management hub communicates the update to the detection system defining a change to one or more of the event rules associated with that detection system, and / or one or more additional event rules to be employed by that detection system. As mentioned above, the management hub may communicate the update to modify a set of active event rules currently associated with the detection system (e.g. by changing one or more active event rules of the set of active event rules and / or adding a new event rule to the set of active event rules) or the management hub may communicate the update specifying a new set of event rules. Referring to Figure 9, the method 900 provides an example in which the detection system receives a query from the management hub for determining a set of active event rules associated with the detection system. As explained above, in some cases the management hub may instead determine a set of active event rules associated with the detection system without querying the detection system. At a step 910, the detection system receives a query from the management server to request at least one set of active event rules associated with the detection system (in some examples, the detection system may in fact apply a plurality of respective sets of active event rules for varying purposes). At a step 920, the detection system communicates at least one set of active event rules associated with the detection system to the management hub (e.g. communicates metadata for the set of active event rules). As explained above, processing at the management hub can thus be performed to determine one or more updates for updating the set of active event rules. At a step 930, the detection system receives one or more updates. At a step 940, the detection system updates a set of active event rules associated with the detection system. The step 930 may comprise one or more of: changing one or more active event rules of the set of active event rules; adding one or more additional even rules to the set of active event rules; removing one or more active event rules of the set of active event rules; and replacing some (e.g. a subset) or all the set of active event rules with the predetermined set of active event rules. Figures 6-9 refer to systems and methods for detection of event rules currently used by one or more detection systems and deployment of one or more updates for improving detection coverage for one or more of the detection systems. In some examples, processing for improving detection coverage for one or more detection systems may be manually instructed by a user. For example, a user associated with the management hub may provide one or more user inputs (e.g. via a user interface associated with the management hub) to initiate this processing. In some examples, processing for improving detection coverage for one or more detection systems may be performed in accordance with a scheduled maintenance plan. For the techniques in Figures 6-9, detection systems may or may not perform report generating. With reference to Figures 1-9, communication between the management hub and a detection system may use any suitable wireless and / or wired communication technique. Any suitable wireless communication protocol may be used for communication between the management hub and a detection system. For example, various internet protocols may be used. In some cases, the In some embodiments of the disclosure, a system may comprise a management hub and a plurality of respective detection systems, in which the management hub may manage each of the plurality of the detection systems according to any of the techniques discussed above. For example, any of the techniques discussed with respect to Figures 1-9 may be performed for a system comprising a management hub and two or more respective detection systems. Any of the techniques discussed with respect to Figures 1-9 may be performed by a same management hub for two or more respective detection systems. The management hub may perform processing operations for two or more respective detection system according to a parallel execution or a serial execution. In some embodiments of the disclosure, one or more detection systems may run one or more processes for one or more different software applications for providing one or more of: access control; antivirus and anti-malware; cloud security; email security; application security; and intrusion prevention systems. One or more detection systems may run programs for providing one or more of these services. It will be appreciated that other services may also be provided. Accordingly, a set of one or more event rules may specify one or more event types associated with one or more such services for allowing detection systems to run services and provide event detection functionality for such services. In some embodiments of the disclosure, a system may comprise a management hub and a plurality of detection systems each operable to provide a different type of event detection functionality. For example, referring again to Figure 1, the detection system 120-1 may provide event detection functionality for a first event type, the detection system 120-2 may provide event detection functionality for a second event type, and the detection system 120-3 may provide event detection functionality for a third event type. In this case, a set of one or more event rules associated with a respective detection system may be associated with a single event type. In some embodiments of the disclosure, a system may comprise a management hub and at least one detection system operable to provide event detection functionality for two or more different event types. For example, referring again to Figure 1, the detection system 120-1 may provide event detection functionality for at least a first event type and a second event type, the first event type being different from the second event type. Moreover, a set of event rules associated with the detection system 120-1 may comprise one or more event rules defining a first event type to be detected and a report generating condition for the first event type. The set of event rules associated with the detection system 120-1 may further comprise one or more event rules defining a second event type to be detected and a report generating condition for the second event type. For example, a given detection system (e.g. 120-1) may be configured to provide email security detection, and another detection system (e.g. 120-2) may be configured to provide access control detection. In some cases, some of the plurality of respective detection systems may provide at least partially overlapping event detection functionality. At least some of the plurality of respective detection systems may have different operating systems (OS) and / or operate using different programming languages and / or different protocols. Event rule examples A set of one or more event rules associated with a detection system may define one or more event types to be detected. The set of event rules may define one or more event types and one or more detection sensitivities (e.g. detection conditions) for the event types. The set of one or more event rules can thus be used by the detection system to control event detection functionality. It will be appreciated that for a digital environment there are potentially wide range of event types that developers may want to monitor. Different event rules may be used for different use cases. Examples of suitable event types include: network anomalies, operating system (OS) anomalies, malicious command execution, abnormal user behaviour, potentially malicious cloud infrastructure changes, and so on. One or more event detection conditions may specify one or more event types to be detected. Generally speaking, an event rule may define one or more event types to be detected. For example, a first event rule may define a first event type to be detected, and a second event rule may define a second event type to be detected. A set of one or more event rules associated with a detection system may also specify one or more report generating conditions (e.g. one or more thresholds for triggering report generating). A report generating condition may specify a configurable threshold corresponding to a threshold number of detected events and / or a threshold rate of detected events. For example, a report generating condition may specify a threshold number of detected events for a given event type. Accordingly, based on a detection by a detection system of a number of events for the given event type, the report generating condition can be triggered (or not triggered) for generating one or more reports (or not generating one or more reports). During the validation period, detected events that may otherwise have resulted in a report being generated by the detection system are logged and report generating is disabled. In particular, during the validation period, the set of one or more event rules can be configured in a non-reporting configuration. For example, an event rule may comprise one or more first configurable parameters specifying one or more event detection conditions and also one or more second configurable parameters specifying on or more report generating conditions. During the validation period, the one or more second configurable parameters can be set to a disabled state to thereby disable report generating functionality forthat event rule. In this way, the report generating functionality for the event rule can be enabled and disabled as needed by enabling and disabling one or more parameters associated with the report generating condition. In other examples, a respective event rule may be paired with an associated event rule, in which the respective event rule specifies an event detection condition, and the associated event rule specifies an associated report generating condition. In this way, the report generating functionality may be enabled and disabled as needed by enabling and disabling the associated event rule. More generally, in some embodiments of the disclosure, a respective event rule may comprise a plurality of parameters indicative of an event detection condition and a report generating condition, and a subset of the parameters corresponding to the report generating condition can be configurable between a disabled state and an enabled state. Alternatively or in addition, a detection system may have an associated reporting condition which may be used for controlling reporting by the detection system, and the associated reporting condition may be set to an enabled or disabled state as needed. A reporting condition may specify one or more thresholds for generating reports. In some examples, a reporting condition may specify one or more of a threshold number of detected events and / or a threshold rate of detected events. Accordingly, a detection system may detect events based on a respective event rule of the set of one or more event rules associated with the detection system and evaluate the detected events with respect to the reporting condition for that respective event rule, in which generating of one or more reports for the detected events is triggered in response to the detected events triggering one or more thresholds defined by the reporting condition. In response to the detected events triggering one or more of the threshold(s), the detection system may generate reports for the detected events (e.g. one report for each of the detected events). In some examples, each respective event rule of the set of set of event rules associated with a given detection system may have a same reporting condition (i.e. a same sensitivity for generating reports), or at least some of the event rules may have different reporting conditions. It will be appreciated that any suitable value may be used for these thresholds and that there are potentially wide range of event types that developers may want to generate reports for with differing sensitivities. For example, a higher sensitivity (e.g. smaller threshold number of detected events) may be desirable for use with a relatively uncommon or rare event type, whereas a lower sensitivity (e.g. higher threshold number of detected events) may be desirable for use with a relatively more common event type. More generally, prior to and / or after a validation period, a set of one or more event rules associated with a given detection system can be configured in a reporting configuration. Accordingly, the given detection system can be operable to provide event detection functionality within a digital environment, by detecting events as determined by the set of one or more event rules, and in response to detection of events, the given detection system can be operable to communicate reports associated with detected events to the management hub, in which the given detection system generates the reports as determined by one or more reporting conditions. In some embodiments of the disclosure, the management hub may store (or otherwise have access to) a repository of predetermined event rules. The repository may comprise of the order of hundreds, or thousands of predetermined event rules. Accordingly, event rules accessible to the management hub can be deployed to detection systems to replace, modify and / or supplement a current set of active event rules associated with a detection system. Event rule update examples In embodiments of the disclosure, the management hub is operable to communicate an update to a detection system, in which the update defines a change to the set of one or more event rules associated with that detection system. Generally, the management hub is operable to communicate an update which modifies the set of one or more event rules associated with a detection system to vary an event detection sensitivity. The update may for example cause the detection system to subsequently detect events with a higher or lower detection rate. More generally, the update modifies the behaviour of the detection system. In some embodiments of the disclosure, the management hub may communicate an update that defines a change to at least one event rule of the set of one or more event rules associated with a detection system. In other words, a current event rule associated the detection system may be modified. The modification may cause an increase or a decrease in event detection sensitivity for the event rule. Moreover, the modification may thus cause an increase or decrease in a number (and / or rate of) events detected for a given event type which may correspond to an increase or decrease in reporting with respect to that event type. For example, the update from the management hub may specify a change to at least one event rule by specifying one or more additional conditions for detection of an event (i.e. one or more additional event detection conditions to supplement one or more event conditions for a current event rule). Alternatively or in addition, the update from the management hub may specify a change to at least one event rule by specifying one or more current conditions for detection of an event that are to be omitted or replaced with one or more other less stringent conditions. In some embodiments of the disclosure, the management hub may communicate an update that defines one or more additional event rules to be included in the set of one or more event rules. Hence, an update may define an additional event rule to be added to the set of one or more event rules. The additional event rule may specify an additional event type (further event type) to be detected. Moreover, the initial set of event rules may define one or more initial event types to be detected, and the update may define an additional event rule specifying an additional event type not included in the one or more initial event types. Hence more generally, the management hub may communicate an update to the detection system defining at least one of: a change to at least one event rule of the set of one or more event rules associated with the detection system, and one or more additional event rules to be employed by the detection system. Following receiving an update from the management hub, the updated detection system is operable to provide event detection functionality, as determined by the updated set of one or more event rules, within the digital environment during the validation period. Accordingly, event detection behaviour may differ as a result of the update. For example, events may be logged at an increased rate and / or events for a new event type may be logged. The updated detection system can communicate an event log (or metadata associated with the event log) for the validation period (or a portion of the validation period) to the management hub for comparison with one or more thresholds. A decision can be made by the management hub as to whether to enable report generating by the detection system. For example, if the event log (or metadata) is indicative of a number of events (or event rate) exceeding a threshold then it can be determined that remedial action should be taken in respect of the updated set of one or more event rules. As explained above, one or more detection systems can be operable to communicate metadata associated with one or more event logs generated by the detection systems. Metadata indicative of a number of events and / or event rate for one or more event logs can be communicated to the management with for comparison with thresholds. The metadata associated with an event log may also comprise high-level security log metadata and / or a link back to log entries at a detection system. In some examples, event logs may be prevented from being transferred from detection systems for security purposes. Threshold examples In embodiments of the disclosure, the management hub is operable to compare logged events during the validation period to one or more thresholds to determine whether a remedial action is required. As explained above, the management hub may receive logged events or metadata associated with logged events from a detection system. In some embodiments of the disclosure, the set of event rules associated with a detection system may comprise a plurality of event rules. Accordingly, the detection system can be operable to log events in dependence upon a first event rule and log events in dependence upon a second event rule. More generally, the detection system can log events in dependence on each of the plurality of event rules. An event log associated with a given event rule may comprise information such as a number of detections and / or a rate of detections. The detection system can be operable to generate the metadata for an event log, in which the metadata is indicative of at least one of number of detections and / or a rate of detections. In some cases, an event log may also include other information such as security-relevant information. The detection system can be operable to generate the metadata not to include the security-relevant information. In this way, metadata can be communicated to the management hub for evaluation with one or more of the thresholds and security relevant information can be maintained at the detection system. References herein to comparison of logged events to one or more thresholds refer to arrangements in which one or both of an event log or metadata for that event log is received by the management hub from a detection system and compared with one or more thresholds. More generally, the management hub is able to access one or more event logs or metadata for one or more event logs during the validation period and compare this with one or more thresholds. A general threshold may be defined by a user that is considered a good-fit for being used to evaluate multiple different event rules. Alternatively or in addition, different thresholds may be specified for comparison with different event logs. In some examples, one or more of the thresholds used by the management hub may be defined in advance by a user, or may be set according to recommended levels defined by the software providers, or may be defined by the system (e.g. one or more default settings). One or more thresholds may be set based on historical data for previously detected events and / or previously generated reports. In some cases, a same threshold may be used for comparison with two or more event logs. Machine learning techniques may be used for calculating one or more of the thresholds. In some embodiments of the disclosure, the management hub may compare logged events detected based on a given event rule to a threshold defining at least one of a threshold number of detected events and a threshold rate of detected events. For example, metadata indicative of a number of logged events associated with a given event rule may compared with a threshold number of detected events. Similarly, metadata indicative of a rate of logged events associated with a given event rule may compared with a threshold rate of detected events. In response to determining that the threshold is is triggered (e.g. the metadata is indicative of a value exceeding a threshold value), the management hub determines that remedial action is required. For example, the management hub may use a threshold such as N detections for a duration of the validation period, or M detections in Y seconds (where N, M and Y may have any suitable values). In response to determining that the logged events associated with an event rule trigger such a threshold, the management hub may determine that remedial action is required for the set of event rules associated with the detection system. In some cases, the management hub is operable to determine that remedial action is required for one or more respective event rules of the set of event rules associated with the detection system based on the above mentioned comparison. For example, logged events associated with a first event rule may not trigger the threshold(s) whereas logged events associated with a second event rule may trigger the threshold(s), and accordingly it may be determined that remedial action is required, or more specifically that remedial action is required for the second event rule. In more detail, a set of event rules associated with a detection system may comprise a plurality of event rules comprising at least a first event rule and a second event rule. During the validation period the management hub may be operable to: compare logged events detected based on the first event rule to a first threshold to determine whether a remedial action is required for the first event rule; and compare logged events detected based on the second event rule to a second threshold to determine whether a remedial action is required for the second event rule. The first event rule and second event rule correspond to different event types and the first threshold and second threshold may be the same or different. More generally, during the validation period, some or all of the plurality of event rules associated with a detection system may be subjected to validation by comparison of logged events with thresholds to determine if remedial action is required for some or all of the plurality of event rules. In response to determining that remedial action is not required for any of the plurality of event rules, the system (e.g. management hub) may enable the updated detection system to generate reports. Alternatively, in response to determining that remedial action is required for at least one of the plurality of event rules, the management hub communicate a second update to the detection system defining a remedial change to some or all of the plurality of event rules. In some embodiments of the disclosure, the management hub may compare logged events detected based on a given event rule to a threshold range. Moreover, the management hub may compare logged events detected based on a given event rule to a threshold upper value and a threshold lower value defining a range. Any of the above-mentioned techniques referring to the management hub using one or more thresholds may similarly be performed using a threshold upper value and a threshold lower value. In some embodiments of the disclosure, in response to the logged events corresponding to a value within the range defined by the threshold upper value and the threshold lower value, the management hub may determine a remedial action is not required. In response to the logged events corresponding to a value not within the range, the management hub may determine a remedial action is required. For example, the threshold upper value may define a number of detections A for a period of time Y, and the threshold lower value may define a number of detections B for the period of time Y, where A is a value greater than B. Hence, the threshold upper value and the threshold lower value can be set to define a range of acceptable behaviour so that behaviour within that range during the validation period corresponds to determining that no remedial action is required and reporting can be enabled. Conversely, behaviour not within that range during the validation period corresponds to determining that remedial action is required. Generally, behaviour falling within the range defined by the threshold upper value and a threshold lower value can be considered to provide a balance between overcaution - of generating too many reports - and a lack of caution in which problematic events may go undetected. In some embodiments of the disclosure, in response to logged events corresponding to a value exceeding the threshold upper value, the management hub may determine a remedial action is required for decreasing event detection sensitivity. Behaviour exceeding the threshold upper value can be considered overcautious and likely to result in subsequently generating too many reports (if reporting were subsequently enabled). Accordingly, the management hub can determine a remedial action is required for decreasing event detection sensitivity for one or more event rules in response to logged events associated with one or more of the event rules exceeding the threshold upper value. In some cases, when determining that a remedial action is required for decreasing event detection sensitivity, the management hub may automatically communicate a remedial action comprising a second update for decreasing event detection sensitivity for one or more event rules (e.g. by changing a current event rule and / or replacing a current event rule and / or removing a current event rule). Alternatively or in addition, the management hub may store information identifying an event rule that has not passed the validation and indicating that a remedial action is required for decreasing event detection sensitivity for that event rule. For event rules that do not pass the validation, the management hub may store identifiers for those event rules for allowing manual assessment by a system user. More generally, the management hub may maintain a queue of identifiers for event rules deemed to have not passed the validation. Accordingly, in response to the logged events for a given event rule triggering the threshold upper value, the management hub can be operable to store an identifier for the given event rule and indicator data to indicate that the given event rule triggered the threshold upper value. In some embodiments of the disclosure, in response to logged events corresponding to a value less the threshold lower value, the management hub may determine a remedial action is required for increasing event detection sensitivity. Behaviour below the threshold lower value can be considered to result in potentially problematic issues going unreported or under-reported. Accordingly, the management hub can determine a remedial action is required for increasing event detection sensitivity for one or more event rules in response to comparison of logged events associated with one or more of the event rules being less than the threshold lower value. Similar to that discussed above for the case of determining that a remedial action is required for decreasing event detection sensitivity, the management hub may automatically communicate a remedial action comprising a second update for increasing event detection sensitivity for one or more event rules. Alternatively or in addition, the management hub may store an identifier for the given event rule and indicator data to indicate that the given event rule triggered (was below) the lower threshold value. Remedial action examples In some embodiments of the disclosure, in response to determining remedial action is required, the management hub can communicate one or more updates to a detection system. In addition to communicating one or more updates, the management hub may also store one or more identifiers for one or more event rules that fail the validation, as already explained above. Stored identifiers can be accessed by system users for event rule assessment. For example, the management hub may store a queue of event rules (and / or event rule identifiers) for manual assessment to allow changes to be applied by a user prior to event rules being subjected to further validation(s). More generally, in some embodiments of the disclosure the management hub may generate a ticket in respect of an event rule determined to require a remedial action and store the ticket. The management hub is operable to communicate an update to a detection system in response to determining that remedial action is required, wherein the update defines a remedial change to the set of one or more event rules associated with that detection system. A remedial change to the set of one or more event rules may take a number of different forms. Following the remedial change being applied at the detection system, the detection system may repeat the validation techniques discussed herein (e.g. a new validation period may start upon applying the remedial change), or report generating by the detection system may be enabled to allow event detection and report generating according to the modified set of one or more event rules. A remedial change to a set of one or more event rules may comprise one or more of: returning at least a subset (some) of the set of event rules to their previous configuration (the previous configuration prior to the most recent update from the management hub); removing one or more event rules from the set of event rules; returning the set of event rules to the previous configuration; and replacing or modifying an event rule with an updated event rule. In some embodiments of the disclosure, the management hub may determine a remedial action is required and communicate an update to a detection system to cause a set of one or more event rules to return to a previous configuration. The update may cause the set of one or more event rules to revert to a previous configuration for the set of one or more event rules immediately prior to a last update. For example, referring to Figure 2 the remedial action at the step 208 may cause the set of event rules to revert to the previous configuration used for the steps 210 and 220. The management hub may communicate one or more updates targeted to one or more event rules determined not to have passed the validation (i.e. determined to have triggered one or more of the threshold). For example, for a set of N event rules used during the validation period, a subset (some) of the event rules may not have passed the validation, and accordingly one or more updates may target the subset of the event rules. More generally, one or more current event rules associated with a detection system can be targeted for removal, replacement or modification. In some embodiments of the disclosure, a plurality of event rules may be associated with a detection system, and the remedial change may cause at least a subset of the plurality of event rules to return to a previous configuration. The subset of the plurality of event rules each determined not to have passed the validation can each be specifically targeted to cause a return the previous configuration(s). A remaining subset of the plurality of event rules, each of which has passed the validation or may not have been subjected to the validation techniques, can thus be left unchanged. In some cases, this may cause the set of one or more event rules to revert to the previous configuration for the set, as already discussed above, or this may result in one or more event rule changes which resulted in acceptable behaviour being retained and one or more event rule changes which resulted in unacceptable behaviour being reversed. In other words, acceptable changes may be retained and deployed whilst unacceptable changes are reverted. In some embodiments of the disclosure, a remedial change causes removal from the set of one or more event rules of one or more additional event rules added to the set of one or more event rules in response to the update. For example, referring to Figure 2, the update communicated at the step 230 may add one or more new event rules to the set of event rules associated with the detection system 120. At the step 280, the second update may cause at least one of the additional event rules to be removed. More generally, for an additional event rule determined not to have passed the validation, the management hub can communicate a second update to remove the additional event rule. In some embodiments of the disclosure, a remedial change causes at least one event rule of the set of one or more event rules to be replaced or modified with an updated event rule. The management hub may store a repository of event rules (as discussed previously). In response to a current event rule that does not pass the validation, the management hub may communicate an update to cause that current event rule to be replaced or modified with an updated event rule. The updated event rule may correspond to a same event type as the event rule that is to be replaced (or modified), and the updated event rule has an increased or decreased event detection sensitivity for the event type. Moreover, the management hub may potentially store a number of event rules corresponding to a same event type and each having a different event detection sensitivity for the event type. For example, the current event rule may trigger the threshold upper value (as already discussed) and in response the management hub may select a predetermined event rule corresponding to the same event type and with a reduced event detection sensitivity for replacing or modifying the current event rule. In this way the remedial change can improve a likelihood of a next validation operation being successful. In a similar manner, a current event rule may trigger the threshold lower value (as already discussed) and in response the management hub may select a predetermined event rule corresponding to the same event type and with an increased event detection sensitivity for replacing or modifying the current event rule. In this way the remedial change can improve a likelihood of a next validation operation being successful. In some embodiments of the disclosure, in response to determining remedial action is required, the management hub may communicate one or more updates defining one or more remedial changes. Subsequently, the above-mentioned validation techniques may be repeated. The validation techniques may be repeated any number of times until the set of one or more active event rules passes the validation. Alternatively, in response to determining remedial action is required, the management hub may communicate one or more updates to change the set of event rules in a way that is known to pass the validation, and report generating may be enabled following the validation period, with identifiers being stored for one or more event rules that did not pass the validation for allowing manual assessment by a user. It will be appreciated that example embodiments can be implemented by computer software operating on a general purpose a computing system. In these examples, computer software, which when executed by a computer, causes the computer to carry out any of the methods discussed above is considered as an embodiment of the present disclosure. Similarly, embodiments of the disclosure are provided by a non-transitory, machine-readable storage medium which stores such computer software. When used in this specification and claims, the terms "comprises" and "comprising" and variations thereof mean that the specified features, steps or integers are included. The terms are not to be interpreted to exclude the presence of other features, steps or components. The invention may also broadly consist in the parts, elements, steps, examples and / or features referred to or indicated in the specification individually or collectively in any and all combinations of two or more said parts, elements, steps, examples and / or features. In particular, one or more features in any of the embodiments described herein may be combined with one or more features from any other embodiment(s) described herein. Although certain example embodiments of the invention have been described, the scope of the appended claims is not intended to be limited solely to these embodiments. It will also be apparent that numerous modifications and variations of the present disclosure are possible in light of the above teachings. The claims are to be construed literally, purposively, and / or to encompass equivalents. It is to be understood that within the scope of the appended claims, the disclosure may be practised otherwise than as specifically described herein. Clauses: 1. A system for managing a digital environment, comprising: a management hub; and one or more detection systems configured to provide event detection functionality within the digital environment, each operable to detect events as determined by a set of one or more event rules, and in response to communicate reports associated with detected events to the management hub; wherein the management hub is operable to: communicate an update to a detection system, in which the update defines a change to the set of one or more event rules associated with that detection system; disable generating of reports by the updated detection system during a validation period, during which events that would otherwise have resulted in a report being generated are logged without generating a report; and compare the logged events to a threshold to determine whether a remedial action is required, and if not, enable the updated detection system to generate reports. 2. The system according to clause 1, wherein the update defines at least one of: one or more additional event rules to be included in the set of one or more event rules; and a change to at least one event rule of the set of one or more event rules. 3. The system according to clause 2, wherein the set of one or more event rules defines one or more event types to be detected, and wherein an additional event rule defines an additional event type to be detected. 4. The system according to any preceding clause, wherein the set of one or more event rules comprises a plurality of event rules comprising at least a first event rule and a second event rule, and wherein during the validation period the management hub is configured to: compare logged events detected based on the first event rule to a first threshold to determine whether a remedial action is required for the first event rule; and compare logged events detected based on the second event rule to a second threshold to determine whether a remedial action is required for the second event rule, wherein the first threshold and second threshold are the same or different. 5. The system according to any preceding clause, wherein the management hub is configured to communicate a second update to the detection system in response to determining that remedial action is required, wherein the second update defines a remedial change to the set of one or more event rules associated with that detection system. 6. The system according to clause 5, wherein the set of one or more event rules comprises a plurality of event rules, and wherein the remedial change causes at least a subset of the plurality of event rules to return to a previous configuration. 7. The system according to clause 5 or clause 6, wherein the remedial change causes removal from the set of one or more event rules of one or more additional event rules added to the set of one or more event rules in response to the update. 8. The system according to any one of clauses 5 to 7, wherein the remedial change to the set of one or more event rules causes the set of one or more event rules to return to a previous configuration for the set of one or more event rules. 9. The system according to clause 5, wherein the remedial change to the set of one or more event rules causes at least one event rule of the set of one or more event rules to be replaced with an updated event rule. 10. The system according to clause 9, wherein the updated event rule corresponds to a same event type as the at least one event rule to be replaced, and the updated event rule has an increased or decreased event detection sensitivity for the event type. 11. The system according to any preceding clause, wherein the management hub is configured to compare the logged events to a threshold defining at least one of a threshold number of detected events and a threshold rate of detected events. 12. The system according to any one of clauses 1-10, wherein the management hub is configured to compare the logged events to a threshold upper value and a threshold lower value defining a range. 13. The system according to clause 12, wherein in response to the logged events corresponding to a value within the range, the management hub is configured to determine the remedial action is not required, and wherein in response to the logged events corresponding to a value not within the range, the management hub is configured to determine the remedial action is required. 14. The system according to clause 13, wherein in response to the logged events corresponding to a value exceeding the threshold upper value, the management hub is configured to determine the remedial action is required for decreasing event detection sensitivity. 15. The system according to clause 13 or clause 14, wherein in response to the logged events corresponding to a value less the threshold lower value, the management hub is configured to determine the remedial action is required for increasing event detection sensitivity. 16. The system according to any preceding clause, wherein the set of one or more event rules defines one or more event detection conditions for triggering detection of events for one or more event types. 17. The system according to any preceding clause, comprising a plurality of detection systems each configured to provide event detection functionality within the digital environment, wherein the management hub is operable to manage each of the plurality of the detection systems. 18. The system according to clause 17, wherein the plurality of the detection systems comprises a first detection system configured to provide a first type of event detection functionality and a second detection system configured to provide a second type of event detection functionality, the first type of event detection functionality being different from the second type of event detection functionality. 19. The system according to any preceding clause, wherein the management hub is further configured to: determine the set of active event rules associated with the detection system, compare the determined set of active event rules to a predetermined set of event rules to establish a discrepancy, determine a change to the set of active event rules, to be implemented to address the discrepancy, and communicate the update to the detection system defining the change to the set of active event rules associated with the detection system, wherein the change defines at least one of: one or more additional event rules to be included in the set of active event rules; and a change to at least one event rule of the set of one or more event rules. 20. A system for managing a digital environment, comprising: a management hub; and one or more detection systems configured to provide event detection functionality within the digital environment, each operable to detect events as determined by one or more event rules, and in response to communicate reports associated with detected events to the management hub; wherein the management hub is configured to: determine a set of active event rules associated with at least one detection system of the one or more detection systems, compare the determined set of active event rules to a predetermined set of event rules to establish a discrepancy, determine a change to the set of active event rules, to be implemented to address the discrepancy, and communicate an update to the at least one detection system defining the change to the set of active event rules associated with that detection system, wherein the change defines at least one of: one or more additional event rules to be included in the set of active event rules; and a change to at least one event rule of the set of active event rules. 21. A computer-implemented method comprising: detecting, by one or more detection systems, events within a digital environment, each of the one or more detection systems detecting events as determined by a set of one or more event rules associate with that detection system; in response to detecting events by a detection system, the detection system communicating reports associated with detected events to a management hub; in which the management hub performs the steps of: communicating an update to a detection system, in which the update defines a change to the set of one or more event rules associated with that detection system; disabling generating of reports by the updated detection system during a validation period, during which events that would otherwise have resulted in a report being generated are logged without generating a report; and comparing the logged events to a threshold to determine whether a remedial action is required, and if not, enabling the updated detection system to generate reports. 22. A computer-implemented method for a system comprising a management hub and one or more detection systems configured to provide event detection functionality within a digital environment, each of the one or more detection systems being operable to detect events as determined by one or more event rules, the method comprising the management hub performing the steps of: determining a set of active event rules associated with at least one detection system of the one or more detection systems, comparing the determined set of active event rules to a predetermined set of event rules to establish a discrepancy, determining a change to the set of active event rules, to be implemented to address the discrepancy, and communicating an update to the at least one detection system defining the change to the set of active event rules associated with that detection system, wherein the change defines at least one 5 of: one or more additional event rules to be included in the set of active event rules; and a change to at least one event rule of the set of active event rules. 23. A computer program comprising instructions which, when executed by a computer, cause the computer to perform the method according to any one of clauses 21 and 22. 10

Claims

1. A system for managing a digital environment, comprising:a management hub; andone or more detection systems configured to provide event detection functionality within the digital environment, each operable to detect events as determined by one or more event rules, and in response to communicate reports associated with detected events to the management hub;wherein the management hub is configured to:determine a set of active event rules associated with at least one detection system of the one or more detection systems,compare the determined set of active event rules to a predetermined set of event rules to establish a discrepancy,determine a change to the set of active event rules, to be implemented to address the discrepancy, andcommunicate an update to the at least one detection system defining the change to the set of active event rules associated with that detection system, wherein the change defines at least one of: one or more additional event rules to be included in the set of active event rules; and a change to at least one event rule of the set of active event rules.

2. The system according to claim 1, wherein the management hub is further operable to:disable generating of reports by an updated detection system during a validation period, during which events that would otherwise have resulted in a report being generated are logged without generating a report; andcompare the logged events to a threshold to determine whether a remedial action is required, and if not, enable the updated detection system to generate reports.

3. The system according to claim 1 or claim 2, wherein the set of active event rules defines one or more event types to be detected, and wherein an additional event rule defines an additional event type to be detected.

4. The system according to claim 2 or claim 3, wherein the set of active event rules comprises a plurality of event rules comprising at least a first event rule and a second event rule, and wherein during the validation period the management hub is configured to:compare logged events detected based on the first event rule to a first threshold to determine whether a remedial action is required for the first event rule; andcompare logged events detected based on the second event rule to a second threshold to determine whether a remedial action is required for the second event rule, wherein the first threshold and second threshold are the same or different.

5. The system according to any one of claims 2 to 4, wherein the management hub is configured to communicate a second update to the detection system in response to determining that remedial action is required, wherein the second update defines a remedial change to the set of active event rules associated with that detection system.

6. The system according to claim 5, wherein the set of active event rules comprises a plurality of event rules, and wherein the remedial change causes at least a subset of the plurality of event rules to return to a previous configuration.

7. The system according to claim 5 or claim 6, wherein the remedial change causes removal from the set of active event rules of one or more additional event rules added to the set of active event rules in response to the update.

8. The system according to any one of claims 5 to 7, wherein the remedial change to the set of active event rules causes the set of active event rules to return to a previous configuration for the set of active event rules.

9. The system according to claim 5, wherein the remedial change to the set of active event rules causes at least one event rule of the set of active event rules to be replaced with an updated event rule.

10. The system according to claim 9, wherein the updated event rule corresponds to a same event type as the at least one event rule to be replaced, and the updated event rule has an increased or decreased event detection sensitivity for the event type.

11. The system according to any one of claims 2 to 10, wherein the management hub is configured to compare the logged events to a threshold defining at least one of a threshold number of detected events and a threshold rate of detected events.

12. The system according to any one of claims 2-10, wherein the management hub is configured to compare the logged events to a threshold upper value and a threshold lower value defining a range.

13. The system according to claim 12, wherein in response to the logged events corresponding to a value within the range, the management hub is configured to determine the remedial action is not required, and wherein in response to the logged events corresponding to a value not within the range, the management hub is configured to determine the remedial action is required.

14. The system according to claim 13, wherein in response to the logged events corresponding to a value exceeding the threshold upper value, the management hub is configured to determine the remedial action is required for decreasing event detection sensitivity.

15. The system according to claim 13 or claim 14, wherein in response to the logged events corresponding to a value less the threshold lower value, the management hub is configured to determine the remedial action is required for increasing event detection sensitivity.

16. The system according to any preceding claim, wherein the set of active event rules defines one or more event detection conditions for triggering detection of events for one or more event types.

17. The system according to any preceding claim, comprising a plurality of detection systems each configured to provide event detection functionality within the digital environment, wherein the management hub is operable to manage each of the plurality of the detection systems.

18. The system according to claim 17, wherein the plurality of the detection systems comprises a first detection system configured to provide a first type of event detection functionality and a second detection system configured to provide a second type of event detection functionality, the first type of event detection functionality being different from the second type of event detection functionality.

19. The system according to any preceding claim, wherein the management hub is configured to:store a plurality of predetermined event rule sets;select a respective predetermined set of event rules in dependence upon one or more properties associated with a detection system; andcompare the determined set of active event rules to the selected predetermined set of event rules to establish a discrepancy.

20. The system according to claim 19, wherein the one or more properties associated with the detection system comprise at least one of: device type, event detection type, protocol, programming language, and service type.

21. The system according to any preceding claim, wherein the management hub is configured to communicate the update, in which the update comprises some or all of the predetermined set of event rules.

22. A computer-implemented method for a system comprising a management hub andone or more detection systems configured to provide event detection functionality within a digital environment, each of the one or more detection systems being operable to detect events asdetermined by one or more event rules, the method comprising the management hub performing the steps of:determining a set of active event rules associated with at least one detection system of the one or more detection systems,comparing the determined set of active event rules to a predetermined set of event rules to establish a discrepancy,determining a change to the set of active event rules, to be implemented to address the discrepancy, andcommunicating an update to the at least one detection system defining the change to the set of active event rules associated with that detection system, wherein the change defines at least one of: one or more additional event rules to be included in the set of active event rules; and a change to at least one event rule of the set of active event rules.

23. The computer-implemented method according to claim 22, further comprising:disabling generating of reports by an updated detection system during a validation period, during which events that would otherwise have resulted in a report being generated are logged without generating a report; andcomparing the logged events to a threshold to determine whether a remedial action is required, and if not, enabling the updated detection system to generate reports.

24. A computer program comprising instructions which, when executed by a computer, cause the computer to perform the method according to any one of claims 22 and 23.

Citation Information

Patent Citations

  • Advanced Rule Analyzer to Identify Similarities in Security Rules, Deduplicate Rules, and Generate New Rules

    US20200272741A1

  • System, method and computer readable medium for identifying missing organizational security detection system rules

    US20210273970A1