Security Event Level Estimation Using Cross-Device Similarity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number of events detected by security devices due to evolving cyberattacks leads to inaccurate level estimation when an event precedes an incident, as existing techniques underestimate the severity of such events.

Innovation Solution

A level estimation apparatus that processes event logs from network devices and applications to calculate degrees of similarity among events, using common events detected by different devices to accurately estimate the level of security events.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If the level is estimated based on the magnitude of a relationship between an event and a past incident, then the estimation process is simple, but the level estimation accuracy deteriorates when an event precedes an incident

Engineering Contradiction:
Improvelevel estimation accuracyVSAvoidestimation process complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the event analysis process into multiple dimensions: (1) relationship magnitude with past incidents, (2) temporal sequence analysis (whether event precedes or follows incident), and (3) degree of similarity calculation. This segmentation allows the system to capture both simple relationship-based estimation and complex temporal-prediction scenarios, resolving the contradiction between simplicity and accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary classification of events based on their temporal relationship with incidents (pre-event, concurrent, or post-event). For pre-events that precede incidents, the system applies preliminary identification and applies enhanced similarity analysis, allowing accurate prediction before the incident occurs while maintaining simple processing for other event types.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If event logs from multiple network devices or applications are analyzed, then the coverage of event detection is improved, but the difficulty of calculating similarity among events increases

Engineering Contradiction:
Improveevent detection coverageVSAvoidsimilarity calculation difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a standardized event representation model as an intermediary layer between diverse event logs from different sources and the similarity calculation mechanism. This model normalizes event attributes, temporal information, and relationship data into a unified format, enabling accurate similarity calculation across multi-vendor devices while maintaining broad detection coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms heterogeneous event log parameters into a standardized parameter set that captures essential characteristics (event type, temporal relationship, relationship magnitude) in a vendor-agnostic manner. This parameter transformation enables consistent similarity calculation across different network devices and applications without losing source-specific nuances.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12174951B2Level estimation device, level estimation method, and level estimation program
Publication Date: 2024.12.24 NIPPON TELEGRAPH & TELEPHONE CORP
  • US12174951B2 patent drawing
  • US12174951B2 patent drawing
  • US12174951B2 patent drawing

AI summary

A level estimation apparatus includes processing circuitry configured to receive event logs of events detected by a device or software, and calculate degrees of similarity among the events indicated by the event logs with use of the event logs, and estimate a level of a predetermined event based on the calculated degrees of similarity among the events and a level of at least one of the events, wherein in the calculation of the degrees of similarity among the events, when a degree of similarity between events detected by different devices or items of software is calculated, a degree of similarity to a common event is used, the common event being an event that has been detected mutually by the different devices or items of software.