SIEM Correlation Engine Asset Risk Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing SIEM devices generate excessive alarms due to the large number of security events collected from multiple security devices in a network, overwhelming administrators with non-essential information, as they lack efficient correlation with asset attributes to prioritize critical events.

Innovation Solution

Implementing a SIEM device with a correlation engine that calculates a risk level for security events based on asset attributes, prioritizing alarms only when the risk level meets a predetermined threshold, thereby filtering out less important events and focusing on core network assets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a SIEM device collects logs from multiple security devices to monitor network status, then the comprehensive security monitoring capability is improved, but the number of generated alarms increases excessively, overwhelming administrators

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidnumber of alarms
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts and identifies only the critical security events from the large volume of collected logs by comparing events against asset attributes and criticality levels. The SIEM device filters out non-essential alarms and retains only those events that pose actual risk to critical assets, thereby reducing alarm volume while maintaining monitoring effectiveness.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different evaluation criteria and alarm thresholds to different types of assets based on their criticality levels. Critical assets receive higher priority monitoring and generate alarms more readily, while less critical assets have higher thresholds. This localized quality approach ensures alarms are generated appropriately based on the specific context and importance of each asset.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If a SIEM device generates alarms for all security events to ensure comprehensive coverage, then the detection completeness is improved, but the administrator's ability to focus on critical issues deteriorates due to alert fatigue

Engineering Contradiction:
Improvedetection completenessVSAvoidadministrator focus and efficiency
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent changes the parameter of alarm generation from a binary on/off approach to a risk-based continuous spectrum. By calculating risk levels based on event correlation with asset attributes, the system dynamically adjusts which events trigger alarms. This parameter change allows the system to maintain detection completeness for all events while selectively presenting only high-risk events to administrators, eliminating alert fatigue.

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If a SIEM device reports all security events to administrators to provide complete information, then the information completeness is improved, but the reporting efficiency deteriorates due to inclusion of non-essential events

Engineering Contradiction:
Improveinformation completenessVSAvoidreporting efficiency
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The patent performs preliminary analysis and filtering of security events before generating reports. By pre-evaluating events against asset attributes, criticality levels, and risk calculations, the system prepares a filtered set of relevant events in advance. This preliminary action ensures that when reports are generated, they contain complete information about critical events without including non-essential events, thereby improving reporting efficiency while maintaining necessary information completeness.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10616258B2Security information and event management
Publication Date: 2020.04.07 FORTINET INC
  • US10616258B2 patent drawing
  • US10616258B2 patent drawing
  • US10616258B2 patent drawing

AI summary

Systems and methods for conducting correlation analysis for security events with assets attributes of a network by a SIEM device to enable more efficient reporting are provided. According to one embodiment, when a SIEM device obtains a security event, a risk level of the security event is calculated based on at least a correlation of the security event with one or more asset attributes of a network that is managed by the SIEM device. When the risk level meets a predetermined or configurable threshold, the SIEM device causes the security event to be reported to an administrator of the network.