Semantic Parser for SIEM Log Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional centralized Security Information and Event Management (SIEM) systems face scalability issues, increased latency, and loss of application context, making them challenging to implement in large-scale cloud or distributed virtual infrastructure, and require manual human intervention for security analysis.

Innovation Solution

Implementing a behavioral security analysis system within a SIEM system that includes a computational semantic parser and a Bayesian learning engine to automate log parsing, generate logical descriptors, and provide predictive security alerts, reducing the need for manual intervention and enhancing detection capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If a centralized SIEM system collects and indexes raw log information in a single location, then comprehensive data collection is achieved, but system latency increases and scalability deteriorates

Engineering Contradiction:
Improvedata collection comprehensivenessVSAvoidsystem latency
Core Design Contradiction:
Quantity of substanceVSLoss of time

Solution Approach 1:

The patent segments the centralized SIEM system into multiple distributed SIEM nodes deployed across different locations. Each node independently collects, indexes, and processes log information locally, eliminating the single centralized collection point that causes latency. This segmentation allows parallel data processing and reduces the time required to analyze security events across the entire environment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a single-point centralized architecture to a multi-point distributed architecture, adding spatial dimensionality to the system. By deploying SIEM nodes across multiple dimensions (different locations, networks, or cloud environments), the system achieves both comprehensive data collection and reduced latency through parallel processing at multiple points simultaneously.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Loss of information

If a centralized SIEM system uses a single large database for all correlations, then complete environment context is maintained, but system performance slows and scalability is reduced

Engineering Contradiction:
Improveenvironment context completenessVSAvoidsystem performance
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The patent divides the single large centralized database into multiple distributed databases at different SIEM nodes. Each node maintains local context information and indexes relevant to its deployed applications or services, enabling fast local queries without scanning the entire environment database. This segmentation preserves necessary environment context while dramatically improving query performance and scalability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by having each SIEM node maintain and process only the context information relevant to its specific deployment area. Instead of uniformly processing all environment context across the entire system, each node optimizes for local relevance, improving overall system performance while maintaining adequate context for security correlations at each location.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If manual human analysis is performed for each suspicious event, then detailed security understanding is achieved, but analysis time increases and productivity decreases

Engineering Contradiction:
Improvesecurity analysis accuracyVSAvoidanalysis throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements automated self-service security analysis through machine learning models and correlation engines that automatically analyze suspicious events without requiring manual human intervention. The system performs self-diagnosis, automatically determines the nature of security events, and generates appropriate responses, thereby maintaining high analysis accuracy while dramatically increasing throughput and productivity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms where the automated analysis results are continuously refined through learning from analyst feedback and actual incident outcomes. This feedback loop allows the automated system to improve its accuracy over time while maintaining high productivity, as the machine learning models become increasingly proficient at security event analysis without requiring constant manual intervention.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9064210B1Semantically-aware behavioral security analysis system for security information and event management
Publication Date: 2015.06.23 EMC IP HLDG CO LLC
  • US9064210B1 patent drawing
  • US9064210B1 patent drawing
  • US9064210B1 patent drawing

AI summary

A behavioral security analysis system comprises a computational semantic parser configured to process data associated with a security information and event management (SIEM) system to generate a plurality of logical descriptors, and a learning engine coupled to the computational semantic parser and configured to generate a plurality of behavioral security descriptors based at least in part on at least a subset of the logical descriptors. The behavioral security descriptors are made accessible to an alerting engine of the SIEM system and utilized to generate one or more security alerts. The computational semantic parser may be operative, for example, to syntactically decompose a portion of the data into component elements, to assign lexical meanings and context denotation information to the component elements, and to apply semantic recomposition to generate a given logical descriptor based on a combinatorial tree having a structure determined using the assigned lexical meanings and context denotation information.