Security Event Log Summarization Using Gen-AI Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Analyzing the operation of security systems involves tedious and error-prone manual correlation of events across different event logs, which is time-consuming.

Innovation Solution

Utilizing generative artificial intelligence (Gen-AI) to summarize operational characteristics of security systems by identifying relevant log entries and calculating summarized operational characteristics based on natural language queries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual correlation of events across different event logs is performed, then operational characteristics can be analyzed, but the process becomes tedious, time-consuming and error-prone

Engineering Contradiction:
Improveaccuracy of event correlationVSAvoidtime required for analysis
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces the manual mechanical process of correlating events with an automated system comprising a controller, natural language interface, and event log analysis software. The controller automatically retrieves events from multiple logs, correlates them based on temporal and contextual relationships, and generates summaries without human intervention, thereby eliminating time loss and errors associated with manual correlation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an intermediary natural language interface between the user and the event logs. This intermediary translates user queries into automated analysis operations, retrieves relevant events from multiple logs, correlates them systematically, and presents results in comprehensible summaries, thereby resolving the contradiction between analysis accuracy and time efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple event logs are correlated to provide comprehensive operational characteristics, then the analysis becomes more complete, but the complexity of the analysis process increases

Engineering Contradiction:
Improvecompleteness of operational analysisVSAvoidcomplexity of correlation process
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal analysis platform that can handle multiple types of event logs (intrusion events, access events, video analytics events, user interaction events) through a single integrated controller. The system provides multi-functional capabilities including event retrieval, temporal correlation, contextual analysis, and various output formats, thereby achieving comprehensive operational analysis without proportionally increasing process complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the complex correlation process into distinct automated modules: event retrieval from individual logs, temporal relationship establishment, contextual matching, and summary generation. Each module handles a specific aspect of the analysis, making the overall complex process manageable and systematic while maintaining completeness across multiple event log types.

Inventive Principle:
Principle #1Segmentation

3Loss of information

If detailed event data is provided to users, then comprehensive information is available, but the information becomes difficult to interpret and use

Engineering Contradiction:
Improvecompleteness of informationVSAvoidease of information interpretation
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent implements a feedback mechanism where the system analyzes user natural language queries, retrieves relevant events from multiple logs, correlates them systematically, and generates comprehensible summaries with key findings highlighted. The system provides feedback in the form of structured summaries that maintain information completeness while enhancing interpretability through organized presentation and natural language explanations.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent transforms raw event data parameters into meaningful operational characteristics through automated analysis. The system changes the parameter representation from individual event details to aggregated operational metrics, temporal patterns, and contextual relationships, thereby maintaining information completeness while significantly improving ease of interpretation for users.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20260065031A1Using generative artificial intelligence to summarize operational characteristics of a security system
Publication Date: 2026.03.05 HONEYWELL INTERNATIONAL INC
  • US20260065031A1 patent drawing
  • US20260065031A1 patent drawing
  • US20260065031A1 patent drawing

AI summary

One or more summarized operational characteristics of a security system may be determined based at least in part on two or more log entries captured in one or more event logs of the security system. A natural language query from a user requesting one or more summarized operational characteristics of the security system may be submitted to a Generative Artificial Intelligence (Gen-AI) model. The Gen-AI model identifies two or more log entries captured in the one or more event logs that are relevant to calculating the one or more summarized operational characteristics of the security system and calculates the one or more summarized operational characteristics of the security system based at least in part on the identified two or more log entries. A summary is provided that includes the one or more summarized operational characteristics of the security system to the user.