Forensic Data Collection for Security Event Categorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In distributed computer infrastructures, security event management systems often struggle to accurately categorize security events due to insufficient information, leading to erroneous associations and time-consuming manual examinations, which can result in unclassifiable events being suppressed or incorrectly rated as malicious or innocent.
Innovation Solution
A method and apparatus where computation apparatuses detect security events, send them to a monitoring unit for initial evaluation, and collect additional forensic data when necessary, using a software agent to gather specific data based on event types, which is then evaluated and used to reassess and categorize the events with weighting factors to determine danger categories.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If security events are categorized based on available data alone, then the categorization process is fast and automated, but the accuracy is low leading to false positives and false negatives
Solution Approach 1:
The system performs preliminary automated categorization of security events based on available data, then proactively identifies events that require additional forensic data collection. This preliminary action maintains high processing speed for clear cases while flagging ambiguous events for deeper analysis, thus preserving productivity while improving accuracy for problematic cases.
Solution Approach 2:
The system implements a feedback loop where initial categorization results are evaluated, and events with insufficient information are automatically flagged for additional forensic data collection. The categorization accuracy is continuously improved by feeding back lessons learned from manual examinations and additional data analysis into the automated classification algorithms.
2Measurement precision
If manual forensic examinations are performed for unclassifiable events, then categorization accuracy improves, but time consumption and resource requirements increase significantly
Solution Approach 1:
Instead of performing full manual forensic examinations on all ambiguous events, the system applies partial action by automatically collecting and analyzing additional forensic data only for events that fall into gray areas. This selective approach improves accuracy for problematic cases while avoiding the time cost of examining every single event manually.
Solution Approach 2:
The system performs self-service by automatically collecting additional forensic data, evaluating it, and reassessing ambiguous security events without requiring constant human intervention. The automated forensic data collection and analysis capabilities enable the system to handle unclassifiable events independently, reducing the time and resources needed for manual examinations.
3Measurement precision
If additional forensic data are collected and evaluated, then the error rate in categorization is reduced, but the complexity of the system increases
Solution Approach 1:
The system segments the security event processing into distinct modules: initial automated categorization, forensic data collection, forensic data evaluation, and reassessment. Each module handles specific tasks independently, which manages complexity by breaking down the overall process into manageable, specialized components that can be developed and maintained separately.
Solution Approach 2:
The system introduces an intermediary forensic data evaluation layer between the initial categorization and the final decision-making process. This intermediary layer collects and analyzes additional forensic data, acting as a mediator that bridges the gap between automated classification and accurate threat assessment, thereby improving accuracy without directly complicating the core categorization logic.
4Productivity
If unclassifiable events are suppressed or given indistinct ratings, then the system maintains simplicity and speed, but the error rate increases due to insufficient information
Solution Approach 1:
The system dynamically adjusts its processing approach based on the characteristics of each security event. For clear-cut events, it maintains fast automated processing with distinct ratings. For ambiguous events, it automatically transitions to a more detailed analysis mode, collecting and evaluating additional forensic data before assigning final ratings, thus maintaining both efficiency and reliability adaptively.
Data Source
AI summary
A system for obtaining and analyzing forensic data in a distributed computer infrastructure. The system includes a plurality of computing devices and at least one monitoring unit, which are connected to each other via a communication network. Every computing device is configured to detect security events and send same to the monitoring unit. The monitoring unit is configured to evaluate the received security events and assign same to a danger category, wherein if there is a lack of information for assigning a danger category, the computing device is configured in such a manner as to receive instructions for gathering additional forensic data and to send the additional data via an analysis unit to the monitoring unit. The monitoring unit is configured in such a manner as to transmit instructions to the computing device for gathering additional data and to use same for re-evaluation and assigning of a danger category.

