Event Log Summarization for SIEM Efficiency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The exponential increase in event log data overwhelms SIEM tools, leading to performance degradation and increased costs, prompting enterprises to arbitrarily reduce data processing, which can result in security holes and inaccurate anomaly detection.
Innovation Solution
Creating summary logs that represent multiple event logs with similar characteristics, reducing the data volume while maintaining essential information, and processing these summary logs with SIEM tools for real-time monitoring and analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If SIEM tools process all event log data, then security monitoring accuracy is improved, but computation efficiency deteriorates and costs increase
Solution Approach 1:
The patent segments event log data into summary logs that represent multiple individual event logs. The summary log generation module creates condensed representations that group similar events together, reducing the total volume of data processed by SIEM tools while preserving essential security information for anomaly detection.
Solution Approach 2:
The patent introduces summary logs as an intermediary between raw event logs and SIEM tool analysis. These summary logs act as a mediating layer that pre-processes and condenses data before it reaches the SIEM tool, reducing computational burden while maintaining detection accuracy.
2Reliability
If SIEM tools process all event log data, then security monitoring completeness is improved, but costs increase
Solution Approach 1:
The patent segments the processing workload by creating summary logs that represent multiple individual event logs. This segmentation allows the system to process a reduced set of summary logs instead of all raw event logs, reducing computational costs while maintaining security monitoring completeness through careful preservation of essential security information.
Solution Approach 2:
The patent changes the parameter of data representation from detailed individual event logs to condensed summary logs. This parameter change reduces the volume of data requiring processing while maintaining the essential security information needed for complete monitoring, thereby reducing processing costs.
3Loss of energy
If enterprises reduce event log data processing, then costs are reduced, but security holes increase
Solution Approach 1:
The patent changes the data representation parameter to summary logs that preserve essential security information while reducing volume. This allows enterprises to reduce processing costs by processing fewer summary logs instead of all raw event logs, while maintaining security monitoring reliability through the careful design of summary log content that retains critical security indicators.
Solution Approach 2:
The patent creates summary logs as condensed copies of multiple individual event logs. These copies retain the essential security information needed for reliable monitoring while reducing the total data volume, allowing cost reduction without creating security holes.
4Productivity
If summary logs are created to reduce data volume, then computation efficiency is improved, but data loss increases
Solution Approach 1:
The patent changes the parameter of data representation to summary logs that maintain essential security information while reducing volume. The summary log generation process is designed to preserve critical security indicators and event characteristics, ensuring that computation efficiency is improved without significant loss of information needed for security analysis.
Data Source
AI summary
The disclosed techniques include the generation of a summary event log from multiple event logs that are identical. Event logs may be identical when the event logs include the same action by the same user using the same source. In various instances, multiple event logs accumulated over a predetermined period of time are summarized in the summary event log. The summary event log includes the information that is identical among the multiple event logs along with additional information about the time period the event logs are accumulated, the number of events that are identical, and memory usage by the event logs. Other information may also be annotated to the summary event log as necessary.


