Standard Metadata Model for Cross-System Log Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security management systems for detecting malicious activities across different products in enterprise computing networks cannot perform combined searches due to differing log structures and attributes, making it difficult to detect sophisticated attacks that exploit multiple vulnerabilities.
Innovation Solution
A standard metadata model is introduced to map log data from various computing systems to standardized attributes, creating connected metadata that allows for a central repository to associate and search across different systems, enabling correlated searches and event analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If different products use different log structures and attributes, then each product can be optimized for its specific security analysis needs, but combined search across multiple products becomes impossible
Solution Approach 1:
The patent introduces a normalized log structure as an intermediary layer between different security products. This normalized structure contains common attributes (such as event time, source system, target system, event type) that enable combined searches across multiple products while preserving access to product-specific attributes. The normalization layer acts as a mediator that translates diverse log formats into a unified representation without losing important product-specific information.
2Ease of operation
If a normalized log structure is implemented within each product, then common search across logs within that product is enabled, but combined search across different products remains impossible due to different attributes
Solution Approach 1:
The patent extends the normalized log structure to serve multiple products simultaneously by defining a universal set of common attributes that apply across all security products. This universal normalized structure enables a single search operation to query logs from multiple products while maintaining the ability to access product-specific attributes when needed. The design allows the same normalized structure to function for both intra-product and inter-product searches.
3Measurement precision
If sophisticated attacks exploit multiple vulnerabilities across different systems, then detection accuracy for individual vulnerabilities remains high, but detection of the combined attack chain becomes difficult
Solution Approach 1:
The patent segments the attack detection problem into two levels: individual vulnerability detection (maintaining high precision) and attack chain correlation (enabling combined analysis). The normalized log structure segments common attributes from product-specific attributes, allowing searches to operate at different granularities. This segmentation enables the system to detect individual vulnerabilities with high accuracy while also correlating events across multiple systems to identify coordinated attacks.
Data Source
AI summary
A standard metadata model for analyzing events with fraud, attack or other malicious background is disclosed. Log data for two or more computing systems is stored, and mapped to standardized attributes based on metadata entities defined for each computing system. A standard metadata model is defined for the computing systems, in which one or more standardized attributes of a first set of computing systems is associated with one or more standardized attributes of a second set of computing systems to define connected metadata that connects attributes of the associated metadata entities.


