SIEM Correlation Engine Asset Risk Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing SIEM devices generate excessive alarms due to the large number of security events collected from multiple security devices in a network, overwhelming administrators with non-essential information, as they lack efficient correlation with asset attributes to prioritize critical events.
Innovation Solution
Implementing a SIEM device with a correlation engine that calculates a risk level for security events based on asset attributes, prioritizing alarms only when the risk level meets a predetermined threshold, thereby filtering out less important events and focusing on core network assets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a SIEM device collects logs from multiple security devices to monitor network status, then the comprehensive security monitoring capability is improved, but the number of generated alarms increases excessively, overwhelming administrators
Solution Approach 1:
The patent extracts and identifies only the critical security events from the large volume of collected logs by comparing events against asset attributes and criticality levels. The SIEM device filters out non-essential alarms and retains only those events that pose actual risk to critical assets, thereby reducing alarm volume while maintaining monitoring effectiveness.
Solution Approach 2:
The patent applies different evaluation criteria and alarm thresholds to different types of assets based on their criticality levels. Critical assets receive higher priority monitoring and generate alarms more readily, while less critical assets have higher thresholds. This localized quality approach ensures alarms are generated appropriately based on the specific context and importance of each asset.
2Measurement precision
If a SIEM device generates alarms for all security events to ensure comprehensive coverage, then the detection completeness is improved, but the administrator's ability to focus on critical issues deteriorates due to alert fatigue
Solution Approach 1:
The patent changes the parameter of alarm generation from a binary on/off approach to a risk-based continuous spectrum. By calculating risk levels based on event correlation with asset attributes, the system dynamically adjusts which events trigger alarms. This parameter change allows the system to maintain detection completeness for all events while selectively presenting only high-risk events to administrators, eliminating alert fatigue.
3Loss of information
If a SIEM device reports all security events to administrators to provide complete information, then the information completeness is improved, but the reporting efficiency deteriorates due to inclusion of non-essential events
Solution Approach 1:
The patent performs preliminary analysis and filtering of security events before generating reports. By pre-evaluating events against asset attributes, criticality levels, and risk calculations, the system prepares a filtered set of relevant events in advance. This preliminary action ensures that when reports are generated, they contain complete information about critical events without including non-essential events, thereby improving reporting efficiency while maintaining necessary information completeness.
Data Source
AI summary
Systems and methods for conducting correlation analysis for security events with assets attributes of a network by a SIEM device to enable more efficient reporting are provided. According to one embodiment, when a SIEM device obtains a security event, a risk level of the security event is calculated based on at least a correlation of the security event with one or more asset attributes of a network that is managed by the SIEM device. When the risk level meets a predetermined or configurable threshold, the SIEM device causes the security event to be reported to an administrator of the network.


