Security Log Lineage Mapping for Cost-Effective Alert Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity and volume of cyber security threats require efficient management of security logs and data to identify high-value alerts and reduce unnecessary data processing costs, as existing systems struggle to track data lineage and determine the cost-effectiveness of security data sources.

Innovation Solution

A security event management system that aggregates and processes network security data to determine data lineage from log data to alerts, using a graphing unit to map data fields and models, and a cost estimation unit to assess the cost of monitoring security data, enabling users to identify high-value and low-value data sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security logs from multiple sources are aggregated and processed, then comprehensive security monitoring capability is improved, but data processing cost and system complexity increase

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments security log processing by creating separate processing pipelines for different data sources (firewalls, IDS/IPS, antivirus, etc.) and organizing logs into categorized groups. Each log source is processed independently through standardized procedures, reducing overall system complexity while maintaining comprehensive monitoring capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediate components including log normalization layers, standardized data formats, and intermediary processing modules that mediate between diverse log sources and the analysis engine. These intermediaries standardize varying log formats into unified structures, simplifying downstream processing while preserving comprehensive security monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If all security log data is processed and stored, then complete security audit trail is improved, but storage cost and processing time increase

Engineering Contradiction:
Improvesecurity audit trail completenessVSAvoidprocessing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system extracts and prioritizes high-value security events from the comprehensive log stream using filtering rules and anomaly detection algorithms. Critical security incidents are extracted for immediate analysis while routine logs are processed in batches or archived, reducing processing time while maintaining complete audit trails through selective extraction of important events.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements periodic processing cycles where logs are analyzed at different frequencies based on their importance and type. Critical security events trigger immediate analysis, while routine logs are processed in scheduled batches. This periodic action reduces overall processing time while ensuring complete audit trail maintenance through systematic periodic review.

Inventive Principle:
Principle #19Periodic action

3Measurement precision

If advanced analytics and machine learning are applied to security logs, then threat detection accuracy is improved, but computational cost and resource requirements increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidcomputational cost
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system applies advanced analytics and machine learning selectively to specific log types and security events rather than processing all logs uniformly. High-value targets such as authentication failures, intrusion detection alerts, and anomalous behavior patterns receive intensive analytical processing, while routine logs use simpler analysis methods, reducing overall computational cost while maintaining high threat detection accuracy for critical events.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent implements local quality by applying different levels of analytical processing to different log sources and event types based on their security value. Critical security logs from high-risk sources receive advanced machine learning analysis, while logs from lower-risk sources use rule-based filtering. This localized application of computational resources optimizes threat detection accuracy while controlling computational costs.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12556557B2Security event management system and associated method
Publication Date: 2026.02.17 KPMG LLP
  • US12556557B2 patent drawing
  • US12556557B2 patent drawing
  • US12556557B2 patent drawing

AI summary

A network security monitoring system having a plurality of data sources for providing security data, an extraction unit for extracting the security data from the sources of the security data to form extracted security data, a graphing unit for mapping the extracted security data to at least one or more data fields and data models to form graph data, and a data lineage determination unit for determining a data lineage between the log data and one or more of the alerts based on the graph data.