Event Log Summarization for SIEM Efficiency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The exponential increase in event log data overwhelms SIEM tools, leading to performance degradation and increased costs, prompting enterprises to arbitrarily reduce data processing, which can result in security holes and inaccurate anomaly detection.

Innovation Solution

Creating summary logs that represent multiple event logs with similar characteristics, reducing the data volume while maintaining essential information, and processing these summary logs with SIEM tools for real-time monitoring and analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If SIEM tools process all event log data, then security monitoring accuracy is improved, but computation efficiency deteriorates and costs increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidcomputation efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent segments event log data into summary logs that represent multiple individual event logs. The summary log generation module creates condensed representations that group similar events together, reducing the total volume of data processed by SIEM tools while preserving essential security information for anomaly detection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces summary logs as an intermediary between raw event logs and SIEM tool analysis. These summary logs act as a mediating layer that pre-processes and condenses data before it reaches the SIEM tool, reducing computational burden while maintaining detection accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If SIEM tools process all event log data, then security monitoring completeness is improved, but costs increase

Engineering Contradiction:
Improvesecurity monitoring completenessVSAvoidprocessing costs
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments the processing workload by creating summary logs that represent multiple individual event logs. This segmentation allows the system to process a reduced set of summary logs instead of all raw event logs, reducing computational costs while maintaining security monitoring completeness through careful preservation of essential security information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of data representation from detailed individual event logs to condensed summary logs. This parameter change reduces the volume of data requiring processing while maintaining the essential security information needed for complete monitoring, thereby reducing processing costs.

Inventive Principle:
Principle #35Parameter changes

3Loss of energy

If enterprises reduce event log data processing, then costs are reduced, but security holes increase

Engineering Contradiction:
Improveprocessing costsVSAvoidsecurity monitoring reliability
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The patent changes the data representation parameter to summary logs that preserve essential security information while reducing volume. This allows enterprises to reduce processing costs by processing fewer summary logs instead of all raw event logs, while maintaining security monitoring reliability through the careful design of summary log content that retains critical security indicators.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent creates summary logs as condensed copies of multiple individual event logs. These copies retain the essential security information needed for reliable monitoring while reducing the total data volume, allowing cost reduction without creating security holes.

Inventive Principle:
Principle #26Copying

4Productivity

If summary logs are created to reduce data volume, then computation efficiency is improved, but data loss increases

Engineering Contradiction:
Improvecomputation efficiencyVSAvoidevent log data completeness
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent changes the parameter of data representation to summary logs that maintain essential security information while reducing volume. The summary log generation process is designed to preserve critical security indicators and event characteristics, ensuring that computation efficiency is improved without significant loss of information needed for security analysis.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240256421A1Log Data Summarization Techniques
Publication Date: 2024.08.01 SALESFORCE INC
  • US20240256421A1 patent drawing
  • US20240256421A1 patent drawing
  • US20240256421A1 patent drawing

AI summary

The disclosed techniques include the generation of a summary event log from multiple event logs that are identical. Event logs may be identical when the event logs include the same action by the same user using the same source. In various instances, multiple event logs accumulated over a predetermined period of time are summarized in the summary event log. The summary event log includes the information that is identical among the multiple event logs along with additional information about the time period the event logs are accumulated, the number of events that are identical, and memory usage by the event logs. Other information may also be annotated to the summary event log as necessary.