Security Event Association Rule Refresh for Ambiguous User Mappings
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security awareness training methods lack context and timeliness, leading to ineffective cybersecurity threat association with users, resulting in ambiguous rule mappings that hinder targeted security training and actions.
Innovation Solution
The system implements a method for refreshing security event association rules by identifying and addressing ambiguous rule matches, updating rule lists, and triggering new rule executions based on user metadata changes, ensuring unambiguous user-event mappings for targeted training and security actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If security event association rules are executed against user records to match security events with users, then user-security event mapping is achieved, but ambiguous rule mappings occur when rules identify multiple different users, reducing mapping accuracy
Solution Approach 1:
The system calculates an ambiguity score for each rule based on the number of users it identifies and feeds this information back to the user interface. This feedback mechanism allows administrators to see which rules are causing ambiguous mappings and take corrective action, thereby improving overall mapping accuracy while maintaining the reliability of the rule execution process.
Solution Approach 2:
The patent replaces manual rule management and ambiguity detection with an automated system that executes rules, calculates ambiguity scores, and presents ranked lists of ambiguous rules to administrators. This substitution of manual processes with automated computational methods improves both the precision of mapping and the reliability of rule execution.
2Adaptability or versatility
If comprehensive rule lists are maintained for security event association, then complete user-event mapping coverage is achieved, but system complexity increases due to multiple rules and thresholds
Solution Approach 1:
The system introduces an intermediary layer between the rule execution engine and the user interface, which calculates ambiguity scores and manages the presentation of rules. This intermediary simplifies the user experience by filtering and ranking ambiguous rules, thereby reducing the perceived complexity while maintaining comprehensive mapping coverage through the underlying extensive rule list.
3Speed
If real-time rule execution is performed against user metadata changes, then timely security training delivery is achieved, but processing time and computational resources increase
Solution Approach 1:
The system performs preliminary actions by maintaining a pre-configured list of security event association rules and their thresholds. When user metadata changes occur, the system can quickly execute relevant rules without needing to recreate or reanalyze the entire rule set, thereby achieving real-time training delivery while minimizing processing time through pre-prepared rule structures.
Data Source
AI summary
Systems and methods are described for security event association rule refresh. One or more rules are executed against one or more user records in a user metadata store. The one or more rules may be configured to match a security event of one or more security events with a user of one or more users using user metadata. A count is determined of a number of times a rule of the one or more rules identifies a plurality of different users. It is further determined that one of the count exceeds a first threshold or a number of the plurality of different users exceeds a second threshold. Responsive to the determination, the rule via a user interface may display a prompt to take an action to one or more of review, remove or modify the rule by a system administrator.


