IoT Log Output Device Selective Filtering for SIEM Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number of IoT devices reporting logs to SIEM services leads to a significant increase in communication network traffic and processing load, potentially causing processing delays and adverse effects on IoT device functionality, as existing technologies do not provide adequate countermeasures to manage this traffic and suppress unnecessary log outputs.

Innovation Solution

A log output device and system that generates logs indicating processing history, utilizing a memory to store static lists for abnormal and normal processing information and a dynamic list to determine the necessity of log output, selectively outputting logs based on these lists to reduce unnecessary traffic and maintain IoT device functionality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all logs from IoT devices are reported to SIEM services, then security monitoring capability is improved, but communication network traffic and processing load increase significantly

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidcommunication network traffic
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the necessary and important logs from the total log set generated by IoT devices. The log selection unit selectively outputs logs based on predetermined conditions (such as error logs, warning logs, or logs containing specific keywords) while filtering out redundant normal operation logs. This extraction approach maintains security monitoring effectiveness while significantly reducing the volume of logs transmitted to SIEM services.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the log output process into multiple stages: log generation by IoT devices, log selection and filtering by the log selection unit, and final output to SIEM services. By dividing the log management flow into distinct segments with specific functions, the system can apply different processing rules to different log types, ensuring that only critical logs are transmitted while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

2Reliability

If all logs from IoT devices are reported to SIEM services, then security monitoring capability is improved, but processing load on SIEM service increases

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidprocessing load
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The log selection unit extracts only logs that meet predetermined selection criteria (such as error conditions, warning conditions, or logs containing specific patterns) before transmitting them to the SIEM service. This extraction mechanism ensures that the SIEM service receives a reduced set of high-value logs, thereby maintaining security monitoring capability while significantly reducing the processing load on the SIEM service.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of transmitting all generated logs (excessive action), the patent applies partial action by selectively transmitting only a subset of logs that are deemed necessary for security monitoring. This partial transmission approach prevents the SIEM service from being overwhelmed by unnecessary log data while ensuring that all critical security-relevant logs are captured.

Inventive Principle:
Principle #16Partial or excessive action

3Quantity of substance

If log output is suppressed to reduce traffic, then communication network traffic is reduced, but necessary security information may be lost

Engineering Contradiction:
Improvecommunication network trafficVSAvoidsecurity information
Core Design Contradiction:
Quantity of substanceVSLoss of information

Solution Approach 1:

The log selection unit is configured with predetermined selection conditions that specifically target logs containing security-relevant information (such as error logs, warning logs, authentication failures, or logs matching known attack patterns). By extracting logs based on these targeted conditions, the system reduces communication traffic while ensuring that no critical security information is lost in the filtering process.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system implements a feedback mechanism where the log selection conditions can be adjusted based on observed security threats and patterns. When new types of attacks or security issues are detected, the selection criteria can be updated to ensure that relevant logs are captured. This feedback loop maintains the accuracy of log selection and prevents loss of security information while continuing to reduce unnecessary traffic.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3848831B1Log output device, log output method and log output system
Publication Date: 2023.11.29 PANASONIC HOLDINGS CORP
  • EP3848831B1 patent drawingFigure 1
  • EP3848831B1 patent drawingFigure 2
  • EP3848831B1 patent drawingFigure 3A

AI summary

A log output device includes a generation unit that generates a log indicating history information of execution of processing, a memory that stores a first list including first static information indicating that the processing is abnormal; a second list including second static information indicating that the processing is normal; and a third list including dynamic information to be used for determining the necessity of output of the log according to the log, and a selection unit that determines to output the generated log when the log has the first static information, and decides not to output the generated log when the log has the second static information. The selection unit determines the necessity of output of the generated log on the basis of the log and the third list.