Forensic Data Collection for Security Event Categorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed computer infrastructures, security event management systems often struggle to accurately categorize security events due to insufficient information, leading to erroneous associations and time-consuming manual examinations, which can result in unclassifiable events being suppressed or incorrectly rated as malicious or innocent.

Innovation Solution

A method and apparatus where computation apparatuses detect security events, send them to a monitoring unit for initial evaluation, and collect additional forensic data when necessary, using a software agent to gather specific data based on event types, which is then evaluated and used to reassess and categorize the events with weighting factors to determine danger categories.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If security events are categorized based on available data alone, then the categorization process is fast and automated, but the accuracy is low leading to false positives and false negatives

Engineering Contradiction:
Improvecategorization speedVSAvoidcategorization accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system performs preliminary automated categorization of security events based on available data, then proactively identifies events that require additional forensic data collection. This preliminary action maintains high processing speed for clear cases while flagging ambiguous events for deeper analysis, thus preserving productivity while improving accuracy for problematic cases.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements a feedback loop where initial categorization results are evaluated, and events with insufficient information are automatically flagged for additional forensic data collection. The categorization accuracy is continuously improved by feeding back lessons learned from manual examinations and additional data analysis into the automated classification algorithms.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If manual forensic examinations are performed for unclassifiable events, then categorization accuracy improves, but time consumption and resource requirements increase significantly

Engineering Contradiction:
Improvecategorization accuracyVSAvoidexamination time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

Instead of performing full manual forensic examinations on all ambiguous events, the system applies partial action by automatically collecting and analyzing additional forensic data only for events that fall into gray areas. This selective approach improves accuracy for problematic cases while avoiding the time cost of examining every single event manually.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs self-service by automatically collecting additional forensic data, evaluating it, and reassessing ambiguous security events without requiring constant human intervention. The automated forensic data collection and analysis capabilities enable the system to handle unclassifiable events independently, reducing the time and resources needed for manual examinations.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If additional forensic data are collected and evaluated, then the error rate in categorization is reduced, but the complexity of the system increases

Engineering Contradiction:
Improvecategorization accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the security event processing into distinct modules: initial automated categorization, forensic data collection, forensic data evaluation, and reassessment. Each module handles specific tasks independently, which manages complexity by breaking down the overall process into manageable, specialized components that can be developed and maintained separately.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary forensic data evaluation layer between the initial categorization and the final decision-making process. This intermediary layer collects and analyzes additional forensic data, acting as a mediator that bridges the gap between automated classification and accurate threat assessment, thereby improving accuracy without directly complicating the core categorization logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If unclassifiable events are suppressed or given indistinct ratings, then the system maintains simplicity and speed, but the error rate increases due to insufficient information

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidsecurity assessment reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system dynamically adjusts its processing approach based on the characteristics of each security event. For clear-cut events, it maintains fast automated processing with distinct ratings. For ambiguous events, it automatically transitions to a more detailed analysis mode, collecting and evaluating additional forensic data before assigning final ratings, thus maintaining both efficiency and reliability adaptively.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10257216B2Method and system for obtaining and analyzing forensic data in a distributed computer infrastructure
Publication Date: 2019.04.09 SIEMENS AG
  • US10257216B2 patent drawing
  • US10257216B2 patent drawing

AI summary

A system for obtaining and analyzing forensic data in a distributed computer infrastructure. The system includes a plurality of computing devices and at least one monitoring unit, which are connected to each other via a communication network. Every computing device is configured to detect security events and send same to the monitoring unit. The monitoring unit is configured to evaluate the received security events and assign same to a danger category, wherein if there is a lack of information for assigning a danger category, the computing device is configured in such a manner as to receive instructions for gathering additional forensic data and to send the additional data via an analysis unit to the monitoring unit. The monitoring unit is configured in such a manner as to transmit instructions to the computing device for gathering additional data and to use same for re-evaluation and assigning of a danger category.