Automated Security Rule Feedback via Historical Event Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IT security rule editing systems lack the ability to provide feedback on the viability and effectiveness of proposed security rules during the authoring process, leading to potential over- or under-inclusivity issues that can result in impractical or ineffective security measures.
Innovation Solution
A system and method that automatically generates feedback for proposed security rules by analyzing historical logged event data, determining the predicted performance of the rule, and providing recommendations for adjustments based on the analysis, ensuring the rule is neither overly inclusive nor under-inclusive.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security rules are made more comprehensive to catch all threats, then detection coverage is improved, but false positives increase making the system impractical
Solution Approach 1:
The system performs preliminary analysis of proposed security rules against historical event data before deployment. By simulating rule performance in advance and identifying potential false positives beforehand, administrators can adjust rules to achieve practical detection coverage without overwhelming false alarms.
2Ease of operation
If security rules are made more specific to reduce false positives, then ease of operation is improved, but detection coverage decreases creating false negatives
Solution Approach 1:
The system provides automated feedback on the expected performance of proposed security rules by analyzing historical event data. This feedback loop allows administrators to see both potential false positives and false negatives, enabling them to optimize rule specificity while maintaining adequate detection coverage.
3Manufacturing precision
If manual analysis of security events is performed to create accurate rules, then rule accuracy is improved, but time consumption increases
Solution Approach 1:
The system performs automated analysis of historical security events to generate performance predictions for proposed rules. This self-service capability eliminates the need for manual analysis of large volumes of event data, providing accurate rule performance estimates automatically while significantly reducing the time required for rule creation.
Data Source
AI summary
A computer determines a number of matches returned by a proposed security rule that result from application of the proposed security-rule to historical logged event data. The computer determines a predicted performance of the proposed security rule as part of a network security system based on the number of matches. The computer sends a message during a creation session of the proposed security-rule. The message includes a recommended change for a portion of the proposed security based on the predicted performance of the proposed security rule.


