Validity Verification System for SIEM Event Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Intrusion detection systems (IDS) generate a high volume of detection results, many of which are ineffective, leading to inefficient manual verification processes for control personnel, wasting resources and time.
Innovation Solution
A validity verification method and system that automates the verification of detection results with low validity verification necessity by using a processor to receive events from a SIEM server, collect raw data, determine validity status based on location information, and generate exceptional processing messages to filter out uninfluential events, thereby reducing unnecessary resource usage and enhancing countermeasure efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual verification is performed on all detection results, then verification completeness is improved, but resource consumption and time consumption increase significantly
Solution Approach 1:
The system enables self-service verification by automatically analyzing detection results using location information and pre-stored reference data. The verification server independently determines validity status without requiring continuous manual intervention, allowing the system to verify its own detection results through automated comparison with reference location data.
Solution Approach 2:
A verification server acts as an intermediary between the SIEM server and control personnel. It receives detection results, automatically verifies them using location information, and only forwards valid results requiring manual handling. This intermediary filters out invalid results, reducing the workload on control personnel while maintaining verification completeness.
2Measurement precision
If manual verification is performed on all detection results, then detection accuracy is improved, but productivity decreases due to high workload
Solution Approach 1:
The system performs self-verification by automatically comparing detection result location information with reference data stored in the database. This automated self-service mechanism maintains high detection accuracy by systematically validating each result without human intervention, while significantly improving verification efficiency through parallel processing capabilities.
Solution Approach 2:
The verification server extracts and analyzes only the critical location information from detection results, comparing it with reference location data. By focusing verification efforts on the most important validating feature (location), the system maintains high detection accuracy while reducing overall verification complexity and improving throughput.
3Productivity
If automated verification is implemented, then verification efficiency is improved, but system complexity increases
Solution Approach 1:
The verification server serves as a dedicated intermediary component that handles automated verification tasks. It receives detection results from the SIEM server, performs automated validation using location information and reference data, and forwards only valid results requiring manual handling. This modular intermediary approach improves verification efficiency while containing system complexity within a dedicated component.
Solution Approach 2:
The verification system is segmented into distinct functional modules: receiving detection results, extracting location information, comparing with reference data, determining validity status, and forwarding results. This segmentation allows each module to be independently developed and maintained, improving overall verification efficiency while managing system complexity through modular architecture.
4Reliability
If all detection results are processed manually, then resource utilization is maximized for verification, but unnecessary resource wastage occurs on low-risk events
Solution Approach 1:
The verification server extracts and evaluates the location information from detection results, comparing it with reference location data to identify invalid or low-risk events. By extracting and analyzing this key validating feature, the system identifies which results require further manual verification and which can be automatically filtered out, preventing resource wastage on unnecessary verifications while maintaining thoroughness for valid threats.
Solution Approach 2:
The verification server acts as an intermediary filter between automated detection and manual verification processes. It uses location information to automatically filter out invalid detection results before they reach manual reviewers, thereby eliminating resource wastage on false positives while ensuring that all valid threats undergo thorough manual verification.
Data Source
AI summary
A validity verification method may include receiving an event to be analyzed from a security information & event management (SIEM) server, the event to be analyzed selected by the SIEM server from a plurality of events detected by different security devices based on a desired correlation rule; registering the event to be analyzed; collecting raw data associated with the registered event from a security device corresponding to the registered event among the different security devices; acquiring location information of an intended network location associated with an attack based on the collected raw data; determining a validity status of the registered event based on the acquired location information; generating an exceptional processing message of the registered event; and transmitting the generated exceptional processing message to the SIEM server based on results of the determining the validity status of the registered event.


