SIEM Field Mapping to Common Security Model
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The variability in how data is organized and stored across different Security Information and Event Management (SIEM) tools within organizations creates an infinite number of configuration options, making it challenging to create cross-platform information security content that can be usable by various entities, and requires manual customization of use cases for each technology infrastructure.
Innovation Solution
A system that maps customized security configurations of technology infrastructures to a generic content schema of a common information security model, allowing for the generation of a single global use case that can be converted into customized security configurations for each entity's technology infrastructure, using probabilistic fuzzy logic for automatic or assisted field mapping.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If SIEM tools are customized to organization's specific needs with flexible data organization and storage options, then the tool can be adapted to specific security environments and requirements, but the number of configuration options becomes infinite creating complexity in creating cross-platform security content
Solution Approach 1:
The patent creates a universal mapping system that can handle multiple SIEM tool configurations through a common framework. The system defines standardized field mappings that work across different SIEM platforms, allowing single security content to be deployed universally across various customized environments without requiring separate configurations for each tool.
Solution Approach 2:
The system transforms the infinite configuration space into a manageable set of standardized parameters by defining specific field mappings (e.g., source IP, destination IP, event time) that remain consistent across different SIEM tools. This parameter standardization allows customization at the data source level while maintaining uniform processing at the analysis level.
2Manufacturing precision
If manual customization of use cases is performed for each technology infrastructure, then the security content can be precisely tailored to specific environments, but the onboarding process becomes time-consuming and requires significant manual intervention
Solution Approach 1:
The system performs preliminary mapping of SIEM fields to standardized parameters during system initialization or first-time configuration. This upfront work creates a reusable mapping framework that automatically applies to all subsequent security content deployments, eliminating the need for manual customization of each new use case while maintaining precision through the predefined mapping rules.
Solution Approach 2:
The patent creates templates and reusable security content based on the standardized mappings. Once security content is created with proper field mappings, it can be copied and deployed across multiple infrastructures without requiring manual recreation or customization, significantly reducing onboarding time while maintaining consistency and precision across deployments.
3Ease of operation
If flexible field aggregation, tagging, naming, and enrichment options are provided in SIEM tools, then data can be organized according to specific organizational needs, but creating cross-platform information security content becomes challenging due to variability in data organization
Solution Approach 1:
The patent introduces an intermediary mapping layer between the flexible SIEM data organization and the standardized security content requirements. This mapping layer translates various SIEM field naming conventions and organization schemes into a unified set of standardized parameters, allowing organizations to maintain their preferred data organization while ensuring cross-platform compatibility of security content.
Data Source
AI summary
Systems, computer program products, and methods are described herein for mapping information security configurations across technology platforms. The present invention is configured to electronically receive, from a computing device associated with a technology infrastructure, one or more responses to one or more queries; extract one or more security information and event management (SIEM) fields from the one or more responses; map the one or more SIEM fields to a generic content schema of a common information security model; generate a unique SIEM map for the technology infrastructure based on at least mapping the one or more SIEM fields to the generic content schema of the common information security model; generate a use case for the technology infrastructure using the common information security model; and transform the use case generated using the common information security model using the unique SIEM map.


