Security Event Level Estimation Using Cross-Device Similarity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing number of events detected by security devices due to evolving cyberattacks leads to inaccurate level estimation when an event precedes an incident, as existing techniques underestimate the severity of such events.
Innovation Solution
A level estimation apparatus that processes event logs from network devices and applications to calculate degrees of similarity among events, using common events detected by different devices to accurately estimate the level of security events.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If the level is estimated based on the magnitude of a relationship between an event and a past incident, then the estimation process is simple, but the level estimation accuracy deteriorates when an event precedes an incident
Solution Approach 1:
The patent segments the event analysis process into multiple dimensions: (1) relationship magnitude with past incidents, (2) temporal sequence analysis (whether event precedes or follows incident), and (3) degree of similarity calculation. This segmentation allows the system to capture both simple relationship-based estimation and complex temporal-prediction scenarios, resolving the contradiction between simplicity and accuracy.
Solution Approach 2:
The patent performs preliminary classification of events based on their temporal relationship with incidents (pre-event, concurrent, or post-event). For pre-events that precede incidents, the system applies preliminary identification and applies enhanced similarity analysis, allowing accurate prediction before the incident occurs while maintaining simple processing for other event types.
2Adaptability or versatility
If event logs from multiple network devices or applications are analyzed, then the coverage of event detection is improved, but the difficulty of calculating similarity among events increases
Solution Approach 1:
The patent introduces a standardized event representation model as an intermediary layer between diverse event logs from different sources and the similarity calculation mechanism. This model normalizes event attributes, temporal information, and relationship data into a unified format, enabling accurate similarity calculation across multi-vendor devices while maintaining broad detection coverage.
Solution Approach 2:
The patent transforms heterogeneous event log parameters into a standardized parameter set that captures essential characteristics (event type, temporal relationship, relationship magnitude) in a vendor-agnostic manner. This parameter transformation enables consistent similarity calculation across different network devices and applications without losing source-specific nuances.
Data Source
AI summary
A level estimation apparatus includes processing circuitry configured to receive event logs of events detected by a device or software, and calculate degrees of similarity among the events indicated by the event logs with use of the event logs, and estimate a level of a predetermined event based on the calculated degrees of similarity among the events and a level of at least one of the events, wherein in the calculation of the degrees of similarity among the events, when a degree of similarity between events detected by different devices or items of software is calculated, a degree of similarity to a common event is used, the common event being an event that has been detected mutually by the different devices or items of software.


