Automated Use Case Selection for SIEM Subscribers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security analysts face a time-consuming and tedious process in identifying and responding to security threats due to the manual search through various data sources and the need for bespoke creation of relevant use cases in Security Incident and Event Management (SIEM) systems, which requires extensive human resources and time.

Innovation Solution

A computer-implemented method and system that stores use case records in a repository, metadata for subscriber attributes, and selects initial and updated use cases based on similarity with existing subscribers, using machine learning algorithms to automate the selection and deployment of relevant use cases in the SIEM environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security analysts manually search through data sources and create bespoke use cases, then they can identify and respond to security threats, but the process becomes time-consuming and requires extensive human resources

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidtime to identify and respond to threats
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service by automatically selecting and deploying use cases based on subscriber attributes without requiring manual analyst intervention. The automated use case selection system analyzes subscriber characteristics and autonomously identifies relevant use cases from the library, eliminating the need for analysts to manually search and create use cases while maintaining detection accuracy

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary action by pre-configuring use cases in a library with associated metadata and attributes. Use cases are prepared in advance and organized according to subscriber characteristics, so when a new subscriber is added, the system can quickly match and deploy appropriate pre-prepared use cases rather than creating them from scratch during threat incidents

Inventive Principle:
Principle #10Preliminary action

2Productivity

If a vendor supplies a library of pre-configured use cases, then the workload and time delay are reduced, but the security team must still manually select relevant use cases from the library

Engineering Contradiction:
Improveuse case deployment efficiencyVSAvoidease of use case selection
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The system performs self-service by automatically selecting relevant use cases from the vendor-supplied library based on subscriber attributes. The automated selection process eliminates the manual effort required for use case selection while maintaining the benefits of having a pre-configured library, allowing the system to autonomously identify and deploy the most relevant use cases for each subscriber

Inventive Principle:
Principle #25Self-service

3Reliability

If security analysts review past threat events, check for duplicates, and analyze knowledge databases, then they can determine appropriate response procedures, but the process becomes tedious and time-consuming

Engineering Contradiction:
Improveresponse procedure accuracyVSAvoidease of threat analysis
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements feedback by automatically analyzing subscriber attributes and use case performance data to continuously improve use case selection. The system learns from past deployments and outcomes, adjusting its selection criteria to provide more accurate recommendations over time, thereby maintaining high response accuracy while reducing the analytical burden on security teams

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11494488B2Security incident and event management use case selection
Publication Date: 2022.11.08 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11494488B2 patent drawing
  • US11494488B2 patent drawing
  • US11494488B2 patent drawing

AI summary

A method, system, and computer program product for adaptive network provisioning. The method may include storing a plurality of use case records in a use case repository, where each use case record provides a diagnostic definition of a security threat to a SIEM environment. The method may also include storing metadata for a plurality of attributes of subscribers to the SIEM environment. The method may also include storing use cases that the subscribers have deployed from the use case repository. The method may also include setting up a new subscriber, where setting up the new subscriber includes: receiving a set of attributes of the new subscriber; searching a metadata store to identify subscribers with attributes that are similar to the set of attributes; and selecting an initial set of use cases for the new subscriber based on use cases deployed by the identified subscribers.