Security Event Log Summarization Using Gen-AI Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Analyzing the operation of security systems involves tedious and error-prone manual correlation of events across different event logs, which is time-consuming.
Innovation Solution
Utilizing generative artificial intelligence (Gen-AI) to summarize operational characteristics of security systems by identifying relevant log entries and calculating summarized operational characteristics based on natural language queries.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual correlation of events across different event logs is performed, then operational characteristics can be analyzed, but the process becomes tedious, time-consuming and error-prone
Solution Approach 1:
The patent replaces the manual mechanical process of correlating events with an automated system comprising a controller, natural language interface, and event log analysis software. The controller automatically retrieves events from multiple logs, correlates them based on temporal and contextual relationships, and generates summaries without human intervention, thereby eliminating time loss and errors associated with manual correlation.
Solution Approach 2:
The patent introduces an intermediary natural language interface between the user and the event logs. This intermediary translates user queries into automated analysis operations, retrieves relevant events from multiple logs, correlates them systematically, and presents results in comprehensible summaries, thereby resolving the contradiction between analysis accuracy and time efficiency.
2Adaptability or versatility
If multiple event logs are correlated to provide comprehensive operational characteristics, then the analysis becomes more complete, but the complexity of the analysis process increases
Solution Approach 1:
The patent implements a universal analysis platform that can handle multiple types of event logs (intrusion events, access events, video analytics events, user interaction events) through a single integrated controller. The system provides multi-functional capabilities including event retrieval, temporal correlation, contextual analysis, and various output formats, thereby achieving comprehensive operational analysis without proportionally increasing process complexity.
Solution Approach 2:
The patent segments the complex correlation process into distinct automated modules: event retrieval from individual logs, temporal relationship establishment, contextual matching, and summary generation. Each module handles a specific aspect of the analysis, making the overall complex process manageable and systematic while maintaining completeness across multiple event log types.
3Loss of information
If detailed event data is provided to users, then comprehensive information is available, but the information becomes difficult to interpret and use
Solution Approach 1:
The patent implements a feedback mechanism where the system analyzes user natural language queries, retrieves relevant events from multiple logs, correlates them systematically, and generates comprehensible summaries with key findings highlighted. The system provides feedback in the form of structured summaries that maintain information completeness while enhancing interpretability through organized presentation and natural language explanations.
Solution Approach 2:
The patent transforms raw event data parameters into meaningful operational characteristics through automated analysis. The system changes the parameter representation from individual event details to aggregated operational metrics, temporal patterns, and contextual relationships, thereby maintaining information completeness while significantly improving ease of interpretation for users.
Data Source
AI summary
One or more summarized operational characteristics of a security system may be determined based at least in part on two or more log entries captured in one or more event logs of the security system. A natural language query from a user requesting one or more summarized operational characteristics of the security system may be submitted to a Generative Artificial Intelligence (Gen-AI) model. The Gen-AI model identifies two or more log entries captured in the one or more event logs that are relevant to calculating the one or more summarized operational characteristics of the security system and calculates the one or more summarized operational characteristics of the security system based at least in part on the identified two or more log entries. A summary is provided that includes the one or more summarized operational characteristics of the security system to the user.


