Automated Security Rule Feedback via Historical Event Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IT security rule editing systems lack the ability to provide feedback on the viability and effectiveness of proposed security rules during the authoring process, leading to potential over- or under-inclusivity issues that can result in impractical or ineffective security measures.

Innovation Solution

A system and method that automatically generates feedback for proposed security rules by analyzing historical logged event data, determining the predicted performance of the rule, and providing recommendations for adjustments based on the analysis, ensuring the rule is neither overly inclusive nor under-inclusive.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security rules are made more comprehensive to catch all threats, then detection coverage is improved, but false positives increase making the system impractical

Engineering Contradiction:
Improvedetection coverageVSAvoidpracticality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary analysis of proposed security rules against historical event data before deployment. By simulating rule performance in advance and identifying potential false positives beforehand, administrators can adjust rules to achieve practical detection coverage without overwhelming false alarms.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If security rules are made more specific to reduce false positives, then ease of operation is improved, but detection coverage decreases creating false negatives

Engineering Contradiction:
ImprovepracticalityVSAvoiddetection coverage
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system provides automated feedback on the expected performance of proposed security rules by analyzing historical event data. This feedback loop allows administrators to see both potential false positives and false negatives, enabling them to optimize rule specificity while maintaining adequate detection coverage.

Inventive Principle:
Principle #23Feedback

3Manufacturing precision

If manual analysis of security events is performed to create accurate rules, then rule accuracy is improved, but time consumption increases

Engineering Contradiction:
Improverule accuracyVSAvoidtime consumption
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The system performs automated analysis of historical security events to generate performance predictions for proposed rules. This self-service capability eliminates the need for manual analysis of large volumes of event data, providing accurate rule performance estimates automatically while significantly reducing the time required for rule creation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9344457B2Automated feedback for proposed security rules
Publication Date: 2016.05.17 KYNDRYL INC
  • US9344457B2 patent drawing
  • US9344457B2 patent drawing
  • US9344457B2 patent drawing

AI summary

A computer determines a number of matches returned by a proposed security rule that result from application of the proposed security-rule to historical logged event data. The computer determines a predicted performance of the proposed security rule as part of a network security system based on the number of matches. The computer sends a message during a creation session of the proposed security-rule. The message includes a recommended change for a portion of the proposed security based on the predicted performance of the proposed security rule.