SIEM Rule Gap Analysis via Universal Format Translation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Security Information and Event Management (SIEM) systems lack a comprehensive security gap analysis, failing to detect cyber-attacks and breaches not covered by vendor-specific correlation rules, and do not generate new rules to fill these gaps, which is a common issue across organizational security detection systems.

Innovation Solution

A system and method that utilize a processing circuitry to provide a known cyber-attack techniques repository in a generic SIEM rules format, translate existing vendor-specific SIEM rules to a generic format, compare them to required rules, identify missing rules, and add the missing rules back to the SIEM system in the vendor-specific language using an encoder-decoder neural network, specifically trained for this purpose.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If vendor-specific correlation rules are used in SIEM systems, then the system can detect known attack patterns, but the system cannot identify missing rules for uncovered attack techniques

Engineering Contradiction:
Improvedetection coverageVSAvoidmissing security rules
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent creates a universal, vendor-agnostic rule format that can represent security detection logic independent of any specific SIEM platform. This universal format serves as a common language that can be translated to multiple vendor-specific formats, enabling the system to identify gaps in coverage across different vendors while maintaining broad applicability. The universal rule structure allows organizations to assess their security detection coverage without being locked into a single vendor's proprietary format.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If existing SIEM rules are kept in vendor-specific format, then they work with the specific SIEM system, but they cannot be compared across different vendors to identify security gaps

Engineering Contradiction:
Improvevendor compatibilityVSAvoidsecurity gap analysis
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a universal rule format as an intermediary layer between vendor-specific SIEM rules and security gap analysis. This intermediary format acts as a common denominator that allows rules from different vendors to be translated into a comparable format, enabling systematic comparison and identification of security gaps. The intermediary format preserves the essential detection logic while removing vendor-specific syntax and semantics that would otherwise prevent cross-vendor analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If comprehensive security rule coverage is achieved, then all known cyber-attack techniques are detected, but the system complexity increases due to rule translation and comparison processes

Engineering Contradiction:
Improveattack detection coverageVSAvoidrule translation system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security rule system into distinct layers: vendor-specific rule formats, a universal rule format, and vendor-specific target formats. This segmentation allows the complex translation and comparison operations to be performed on the universal format layer, which has standardized structure and semantics. By dividing the problem into manageable segments with clear interfaces, the system reduces overall complexity while maintaining comprehensive detection coverage across multiple vendors.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3876122B1System, method and computer readable medium for identifying missing organizational security detection system rules
Publication Date: 2023.11.01 CYBERPROOF ISRAEL LTD
  • EP3876122B1 patent drawingFigure 1~2
  • EP3876122B1 patent drawingFigure 3

AI summary

A system for identifying missing organizational security detection system rules, the system includes at least one processing circuitry configured to provide a known cyber-attack techniques repository including information of known cyber-attack techniques and required SIEM (or any other organizational security detection system such as EDR, firewall, etc.) rules required for protecting against each of the known cyber-attack techniques, the known rules being in a generic SIEM rules format; obtain existing SIEM rules of a SIEM of an organization, the existing SIEM rules being in a vendor-specific language, other than the generic SIEM rules format; translate the existing SIEM rules to the generic SIEM rules format, using a translation system, giving rise to translated SIEM rules; compare the translated SIEM rules to the required SIEM rules to identify missing rules, being the required SIEM rules not included in the translated SIEM rules.