Validity Verification System for SIEM Event Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Intrusion detection systems (IDS) generate a high volume of detection results, many of which are ineffective, leading to inefficient manual verification processes for control personnel, wasting resources and time.

Innovation Solution

A validity verification method and system that automates the verification of detection results with low validity verification necessity by using a processor to receive events from a SIEM server, collect raw data, determine validity status based on location information, and generate exceptional processing messages to filter out uninfluential events, thereby reducing unnecessary resource usage and enhancing countermeasure efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual verification is performed on all detection results, then verification completeness is improved, but resource consumption and time consumption increase significantly

Engineering Contradiction:
Improveverification completenessVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service verification by automatically analyzing detection results using location information and pre-stored reference data. The verification server independently determines validity status without requiring continuous manual intervention, allowing the system to verify its own detection results through automated comparison with reference location data.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A verification server acts as an intermediary between the SIEM server and control personnel. It receives detection results, automatically verifies them using location information, and only forwards valid results requiring manual handling. This intermediary filters out invalid results, reducing the workload on control personnel while maintaining verification completeness.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If manual verification is performed on all detection results, then detection accuracy is improved, but productivity decreases due to high workload

Engineering Contradiction:
Improvedetection accuracyVSAvoidverification efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system performs self-verification by automatically comparing detection result location information with reference data stored in the database. This automated self-service mechanism maintains high detection accuracy by systematically validating each result without human intervention, while significantly improving verification efficiency through parallel processing capabilities.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The verification server extracts and analyzes only the critical location information from detection results, comparing it with reference location data. By focusing verification efforts on the most important validating feature (location), the system maintains high detection accuracy while reducing overall verification complexity and improving throughput.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If automated verification is implemented, then verification efficiency is improved, but system complexity increases

Engineering Contradiction:
Improveverification efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The verification server serves as a dedicated intermediary component that handles automated verification tasks. It receives detection results from the SIEM server, performs automated validation using location information and reference data, and forwards only valid results requiring manual handling. This modular intermediary approach improves verification efficiency while containing system complexity within a dedicated component.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The verification system is segmented into distinct functional modules: receiving detection results, extracting location information, comparing with reference data, determining validity status, and forwarding results. This segmentation allows each module to be independently developed and maintained, improving overall verification efficiency while managing system complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

4Reliability

If all detection results are processed manually, then resource utilization is maximized for verification, but unnecessary resource wastage occurs on low-risk events

Engineering Contradiction:
Improveverification thoroughnessVSAvoidresource wastage
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The verification server extracts and evaluates the location information from detection results, comparing it with reference location data to identify invalid or low-risk events. By extracting and analyzing this key validating feature, the system identifies which results require further manual verification and which can be automatically filtered out, preventing resource wastage on unnecessary verifications while maintaining thoroughness for valid threats.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The verification server acts as an intermediary filter between automated detection and manual verification processes. It uses location information to automatically filter out invalid detection results before they reach manual reviewers, thereby eliminating resource wastage on false positives while ensuring that all valid threats undergo thorough manual verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11956264B2Method and system for verifying validity of detection result
Publication Date: 2024.04.09 LY CORP
  • US11956264B2 patent drawing
  • US11956264B2 patent drawing
  • US11956264B2 patent drawing

AI summary

A validity verification method may include receiving an event to be analyzed from a security information & event management (SIEM) server, the event to be analyzed selected by the SIEM server from a plurality of events detected by different security devices based on a desired correlation rule; registering the event to be analyzed; collecting raw data associated with the registered event from a security device corresponding to the registered event among the different security devices; acquiring location information of an intended network location associated with an attack based on the collected raw data; determining a validity status of the registered event based on the acquired location information; generating an exceptional processing message of the registered event; and transmitting the generated exceptional processing message to the SIEM server based on results of the determining the validity status of the registered event.