Machine-Learned Investigation Query Prediction for SIEM Analysts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge of finding enough qualified and experienced security analysts to perform managed detection and response services is exacerbated by the need for analysts to manually generate queries in current SIEM systems, which new analysts lack the knowledge to do effectively.
Innovation Solution
A system and method that predicts investigation queries based on prior investigations using machine learning, leveraging the knowledge of experienced analysts to assist less experienced analysts by automatically executing queries similar to previous incidents, parsing variables, and displaying results.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual query generation by analysts is used in current SIEM systems, then analysts can perform incident investigations, but new analysts lack the knowledge to generate effective queries and experienced analysts are insufficient in number
Solution Approach 1:
The system copies effective queries from experienced analysts and stores them in a repository. When a new alert is detected, the system automatically retrieves and executes relevant queries from the repository, eliminating the need for analysts to manually create queries and ensuring consistent, effective query execution regardless of analyst experience level.
Solution Approach 2:
The system enables self-service by automatically generating and executing investigation queries without requiring analyst intervention. The automated query execution system retrieves relevant queries from the repository and executes them automatically, allowing the system to serve itself rather than relying on human analysts for every query generation task.
2Measurement precision
If experienced analysts manually investigate each incident, then accurate and comprehensive investigations are achieved, but the scarcity of experienced analysts limits productivity
Solution Approach 1:
The system copies the investigative knowledge embedded in queries created by experienced analysts. By storing these queries in a repository and automatically retrieving them for new incidents, the system replicates the accuracy and comprehensiveness of experienced analyst investigations without requiring their direct involvement in every case, thereby scaling productivity.
Solution Approach 2:
The system performs preliminary action by pre-processing and storing effective queries in the repository during off-peak times or when experienced analysts are available. This allows queries to be prepared in advance and automatically executed when incidents occur, enabling accurate investigations to be performed rapidly without requiring experienced analysts to be actively available for every incident.
3Adaptability or versatility
If new analysts are trained to generate effective queries, then sufficient personnel can fill open positions, but training time and resources are consumed
Solution Approach 1:
The system copies the expertise of experienced analysts into the query repository, making this knowledge immediately available to new analysts. Instead of requiring new analysts to spend time learning query generation through training, the system provides them with access to pre-crafted, effective queries that can be automatically executed, enabling new hires to become productive immediately.
Solution Approach 2:
The automated query execution system acts as an intermediary between experienced analysts and new analysts. Rather than requiring direct knowledge transfer through training, the system mediates by capturing queries from experienced analysts, storing them in the repository, and automatically applying them to incidents, thereby transferring expertise without requiring time-consuming training sessions.
Data Source
AI summary
An embodiment of the present invention is directed to predicting investigation queries based on prior investigations. An embodiment of the present invention leverages the knowledge of the existing experienced analysts to assist and guide newer or less experienced analysts through incident investigations. By analyzing queries that have been run previously, and utilizing machine learning, an embodiment of the present invention may mimic the knowledge of experienced and/or existing analysts by automatically running those queries against similar incidents.


