IP Library › Granted Patent US 12,192,216
Granted Patent B2
US 12,192,216 · App. 17/973,137 · Granted Jan 7, 2025

System and method for SIEM rule sorting and conditional execution

Inventors: Tim Uwe Scheideler (Schoenenberg, CH); Ivan James Reedman (Cheltenham, GB); Arjun Udupi Raghavendra (Zürich, CH); Matthias Seul (Pleasant Hill, CA)
Assignee: Kyndryl, Inc.
H04L63/1416G06F11/327H04L63/0263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,192,216
App. No.
17/973,137
Filed
Oct 25, 2022
Granted
Jan 7, 2025
Kind
B2
Art Unit
2438
USPC
726/1
Abstract

A method for processing security events by applying a rule-based alarm scheme may be provided. The method includes generating a rule index of rules and an indicator of compromise index for each of the rules. The method includes also processing the incoming security event by applying the rules, increasing a current rule counter relating to a triggered rule, and increasing a current indicator of compromise counter pertaining to the triggered rule. Furthermore, the method includes generating a pseudo security event from received data about known attacks and related indicators of compromise, processing the pseudo security events by sequentially applying the rules, increasing a current rule counter of pseudo security events, and increasing a current indicator of compromise counter for pseudo security events, and sorting the rules and sorting within each rule the indicator of compromise values in the indicator of compromise index.

Claims (61)

1. A method for processing security events by applying a rule-based alarm scheme for determining whether a received security event is considered as offense, the method comprising:

generating a respective indicator of compromise index for each rule in a rule index, each respective indicator of compromise index comprising indicator values of indicators of compromise to be used for a comparison against an attribute of a security event;

processing an incoming security event by sequentially applying the rules in the rule index, wherein processing the incoming security event comprises:

increasing a current rule counter relating to a triggered rule, wherein the triggered rule comprises a respective one of the rules that triggered an offense during the processing, and

increasing a current indicator of compromise counter pertaining to the triggered rule, wherein the current indicator of compromise counter comprises a different counter than the current rule counter;

sorting the rules in the rule index according to a rule likelihood of triggering an offense, wherein the sorting the rules is based on respective weighted rule counter values;

sorting, for each rule, the indicators of compromise in the respective indicator of compromise index according to an indicator of compromise likelihood of triggering an offense, wherein the sorting the indicators of compromise is based on weighted current indicator of compromise counter values; and

processing another incoming security event by sequentially applying the sorted rules contained in the rule index.

2. The method according to claim 1 , wherein the sorting the rules also comprises:

determining the weighted rule counter values by combining weighted past rule counter values and weighted current rule counter values of the rule.

3. The method according to claim 1 , wherein the sorting, within each rule, the indicators of compromise also comprises:

determining the weighted indicator of compromise counter values by combining weighted past indicator of compromise value counter values and weighted current indicator of compromise counter values of the respective indicator of compromise.

4. The method according to claim 1 , wherein the increasing the current rule counter comprises:

increasing the current rule counter by a fixed number or by a number indicative of a severity of the offense.

5. The method according to claim 1 , wherein the increasing the current indicator of compromise counter also comprises:

increasing the current indicator of compromise counter by a fixed number.

6. The method according to claim 1 , further comprising:

generating a pseudo security event from received data about known attacks and related indicators of compromise; and

processing the pseudo security events by sequentially applying the rules in the rule index, wherein processing the pseudo security events comprises:

increasing a current rule counter of pseudo security events relating to the triggered rule which processing has triggered the offense, and

increasing a current indicator of compromise counter for pseudo security events pertaining to the triggered rule.

7. The method according to claim 6 , wherein the generating the pseudo security event comprises one selected from a group consisting of:

applying a tactic-technique-procedure (TTP) identifying data from the received data about known attacks, wherein the received data about known attacks are received via a structured threat information expression (STIX) protocol;

generating a pseudo security event for each phase of a sequence of partial cyber-attacks represented by attack patterns; and

generating a pseudo security event for each indicator of compromise relating to a respective rule.

8. The method according to claim 6 , where the generating a pseudo security event also comprises:

resetting a current rule counter of pseudo security events to zero; and

resetting a current indicator of compromise counter for pseudo security events to zero.

9. The method according to claim 1 , wherein the sorting the rules in the rule index comprises:

determining the weighted rule counter based on a predefined percentage value, predefined weighing factor values, a past rule counter comprising a number of offenses counted previously, an observed events counter comprising a number of offenses generated in a current time window for real events, and a pseudo security counter comprising a number offenses generated in the current time window for pseudo events.

10. The method according to claim 1 , also comprising:

buffering the incoming security event after a predetermined first number of rules have been processed and within each processed rule a predetermined second number of indicator of compromise counter groups have been processed; and

continue the processing of the buffered security event if a processing load of incoming security events decreases below a predefined load threshold value.

11. A SIEM system for processing security events by applying a rule-based alarm scheme for determining whether a received security event is considered as offense, the system comprising:

a processor;

one or more computer readable storage medium; and

program instructions stored on the one or more computer readable storage medium, the program instructions being executable by the processor to:

process an incoming security event by sequentially applying rules in a rule index, wherein processing the incoming security event comprises: increasing a current rule counter relating to a triggered rule and increasing a current indicator of compromise counter pertaining to the triggered rule, wherein the current indicator of compromise counter comprises a different counter than the current rule counter;

sort the rules in the rule index according to a rule likelihood of triggering an offense, wherein the sorting the rules is based on respective weighted rule counter values;

sort, for each rule, indicators of compromise in a respective indicator of compromise index according to an indicator of compromise likelihood of triggering an offense, wherein the sorting the indicators of compromise is based on weighted current indicator of compromise counter values; and

process another incoming security event by sequentially applying the sorted rules contained in the rule index.

12. The system according to claim 11 , wherein the indicators of compromise comprise respective artifacts observed on a network or in an operating system that indicate a computer intrusion.

13. The system according to claim 11 , wherein not all incoming security events are processed against all the rules.

14. The system according to claim 11 , wherein the sorting the rules in the rule index comprises:

determining the weighted rule counter based on a past rule counter comprising a number of offenses counted previously, an observed events counter comprising a number of offenses generated in a current time window for real events, and a pseudo security counter comprising a number offenses generated in the current time window for pseudo events.

15. The system according to claim 11 , wherein the program instructions are executable by the processor to:

buffer the incoming security event after a predetermined first number of rules have been processed and within each processed rule a predetermined second number of indicator of compromise counter groups have been processed; and

continue the processing of the buffered security event if a processing load of incoming security events decreases below a predefined load threshold value.

16. A computer program product for processing security events by applying a rule-based alarm scheme for determining whether a received security event is considered as offense, the computer program product comprising:

one or more computer readable storage medium and program instructions stored on at least one of the one or more computer readable storage medium, the program instructions executable by a processor to:

process an incoming security event by sequentially applying rules in a rule index, wherein processing the incoming security event comprises: increasing a current rule counter relating to a triggered rule and increasing a current indicator of compromise counter pertaining to the triggered rule, wherein the current indicator of compromise counter comprises a different counter than the current rule counter;

sort the rules in the rule index according to a rule likelihood of triggering an offense, wherein the sorting the rules is based on respective weighted rule counter values;

sort, for each rule, indicators of compromise in a respective indicator of compromise index according to an indicator of compromise likelihood of triggering an offense, wherein the sorting the indicators of compromise is based on weighted current indicator of compromise counter values; and

process another incoming security event by sequentially applying the sorted rules contained in the rule index.

17. The computer program product according to claim 16 , wherein the indicators of compromise comprise respective artifacts observed on a network or in an operating system that indicate a computer intrusion.

18. The computer program product according to claim 16 , wherein not all incoming security events are processed against all the rules.

19. The computer program product according to claim 16 , wherein the sorting the rules in the rule index comprises:

determining the weighted rule counter based on a past rule counter comprising a number of offenses counted previously, an observed events counter comprising a number of offenses generated in a current time window for real events, and a pseudo security counter comprising a number offenses generated in the current time window for pseudo events.

20. The computer program product according to claim 16 , wherein the program instructions are executable by the processor to:

buffer the incoming security event after a predetermined first number of rules have been processed and within each processed rule a predetermined second number of indicator of compromise counter groups have been processed; and

continue the processing of the buffered security event if a processing load of incoming security events decreases below a predefined load threshold value.

Continuity (2)
Continuation 16424952 · May 29, 2019
Related Publication 20230049773A1 · Feb 16, 2023
References Cited (104)
US 6633835B1 · Moran et al. · 2003 [cited by applicant]
US 8418240B2 · Wool · 2013 [cited by examiner]
US 8819762B2 · Harrison · 2014 [cited by examiner]
US 9298918B2 · Glew · 2016 [cited by examiner]
US 9537841B2 · Schütz · 2017 [cited by examiner]
US 9584379B2 · Klimov et al. · 2017 [cited by applicant]
US 9601000B1 · Gruss · 2017 [cited by examiner]
US 9807109B2 · Laidlaw · 2017 [cited by examiner]
US 9866426B2 · Shelton · 2018 [cited by examiner]
US 9900335B2 · Desch · 2018 [cited by examiner]
US 9965627B2 · Ray · 2018 [cited by examiner]
US 9967264B2 · Harris · 2018 [cited by examiner]
US 9967282B2 · Thomas · 2018 [cited by examiner]
US 9967283B2 · Ray · 2018 [cited by examiner]
US 9985982B1 · Bartos · 2018 [cited by examiner]
US 9992228B2 · Ray · 2018 [cited by examiner]
US 10063373B2 · Schütz · 2018 [cited by examiner]
US 10122687B2 · Thomas · 2018 [cited by examiner]
US 10135862B1 · McClintock et al. · 2018 [cited by applicant]
US 10148677B2 · Muddu · 2018 [cited by examiner]
US 10225286B2 · Ray · 2019 [cited by examiner]
US 10382459B2 · Harris · 2019 [cited by examiner]
US 10469509B2 · Nachenberg · 2019 [cited by examiner]
US 10516531B2 · Schütz · 2019 [cited by examiner]
US 10558800B2 · Ray · 2020 [cited by examiner]
US 10666668B2 · Muddu · 2020 [cited by examiner]
US 10673902B2 · Thomas · 2020 [cited by examiner]
US 10728273B1 · Okubo · 2020 [cited by examiner]
US 10778703B2 · Muddu · 2020 [cited by examiner]
US 10778725B2 · Ray · 2020 [cited by examiner]
US 10789367B2 · Joseph Durairaj et al. · 2020 [cited by examiner]
US 10798113B2 · Muddu · 2020 [cited by examiner]
US 10841339B2 · Ray · 2020 [cited by examiner]
US 10911468B2 · Muddu · 2021 [cited by examiner]
US 10965711B2 · Schiappa · 2021 [cited by examiner]
US 10986106B2 · Muddu · 2021 [cited by examiner]
US 11012472B2 · Milazzo · 2021 [cited by examiner]
US 11057411B2 · Nakata · 2021 [cited by examiner]
US 11140130B2 · Thomas · 2021 [cited by examiner]
US 20030051165A1 · Krishnan · 2003 [cited by examiner]
US 20030120652A1 · Tifft · 2003 [cited by examiner]
US 20040255151A1 · Mei · 2004 [cited by examiner]
US 20080010225A1 · Gonsalves et al. · 2008 [cited by applicant]
US 20090138938A1 · Harrison · 2009 [cited by examiner]
US 20090172800A1 · Wool · 2009 [cited by examiner]
US 20130139262A1 · Glew · 2013 [cited by examiner]
US 20130227689A1 · Pietrowicz et al. · 2013 [cited by applicant]
US 20140096184A1 · Zaitsev · 2014 [cited by applicant]
US 20140157405A1 · Joll et al. · 2014 [cited by applicant]
US 20140201836A1 · Amsler · 2014 [cited by examiner]
US 20150213358A1 · Shelton · 2015 [cited by examiner]
US 20150365438A1 · Carver · 2015 [cited by examiner]
US 20160078225A1 · Ray · 2016 [cited by examiner]
US 20160080399A1 · Harris · 2016 [cited by examiner]
US 20160080417A1 · Thomas · 2016 [cited by examiner]
US 20160080418A1 · Ray · 2016 [cited by examiner]
US 20160080419A1 · Schiappa · 2016 [cited by examiner]
US 20160080420A1 · Ray · 2016 [cited by examiner]
US 20160191465A1 · Thomas · 2016 [cited by examiner]
US 20160191466A1 · Pernicha · 2016 [cited by examiner]
US 20160191476A1 · Schütz · 2016 [cited by examiner]
US 20170032130A1 · Joseph Durairaj et al. · 2017 [cited by examiner]
US 20170078093A1 · Schütz · 2017 [cited by examiner]
US 20170085588A1 · Laidlaw · 2017 [cited by examiner]
US 20170116416A1 · Pearcy · 2017 [cited by examiner]
US 20170187741A1 · Desch · 2017 [cited by examiner]
US 20170223037A1 · Singh · 2017 [cited by examiner]
US 20170264627A1 · Hunt et al. · 2017 [cited by applicant]
US 20170286671A1 · Chari et al. · 2017 [cited by applicant]
US 20180020021A1 · Gilmore et al. · 2018 [cited by applicant]
US 20180191747A1 · Nachenberg · 2018 [cited by examiner]
US 20180234457A1 · Rajkumar · 2018 [cited by applicant]
US 20180276378A1 · Ray · 2018 [cited by examiner]
US 20180278631A1 · Harris · 2018 [cited by examiner]
US 20180278649A1 · Thomas · 2018 [cited by examiner]
US 20180278650A1 · Ray · 2018 [cited by examiner]
US 20180324220A1 · Ray · 2018 [cited by examiner]
US 20180367299A1 · Schütz · 2018 [cited by examiner]
US 20190028438A1 · Thomas · 2019 [cited by examiner]
US 20190095599A1 · Iliofotou · 2019 [cited by examiner]
US 20190098068A1 · Iliofotou · 2019 [cited by examiner]
US 20190149580A1 · Ray · 2019 [cited by examiner]
US 20190182283A1 · Nakata · 2019 [cited by examiner]
US 20200186569A1 · Milazzo · 2020 [cited by examiner]
US 20200327225A1 · Nguyen · 2020 [cited by examiner]
US 20200334498A1 · Pan · 2020 [cited by examiner]
US 20200364223A1 · Pal · 2020 [cited by examiner]
US 20200382525A1 · Scheideler et al. · 2020 [cited by applicant]
US 20210240836A1 · Hazony · 2021 [cited by examiner]
US 20220131836A1 · Thomas · 2022 [cited by examiner]
CN 101697545 · 2010 [cited by applicant]
CN 105404586 · 2016 [cited by applicant]
CN 108243060 · 2018 [cited by applicant]
CN 109684832 · 2019 [cited by applicant]
JP 2000174808A · 2004 [cited by applicant]
Leonard Renners et al., Modeling and Learning Incident Prioritization, in The 9th IEEE International Conference on Intelligent Data Acquisition and Advanced Computing Systems (Sep. 2017) (Year: 2017). [cited by examiner]
Search Query Report from IP.com (performed Jul. 15, 2022) (Year: 2022). [cited by applicant]
Search Query Report from IP.com (performed Mar. 18, 2022) (Year: 2022). [cited by applicant]
International Search Report and Written Opinion of the International Searching Authority for International Application No. PCT/IB2020/053997, Jul. 28, 2020, 7 pages. [cited by applicant]
Renners et al., “Modeling and Learning Incident Prioritization”, The 9th IEEE International 1 Conference on Intelligent Data Acquisition and Advanced Computing Systems: Technology and Applications, Bucharest, Romania, S… [cited by applicant]
Mell et al., “The NIST Definition of Cloud Computing”, NIST, Special Publication 800-145, Sep. 2011, 7 pages. [cited by applicant]
Appendix P, “List of Kyndryl Patents or Patent Applications Treated as Related”, Oct. 25, 2022, 2 pages. [cited by applicant]
Office Action in Japanese Application No. 2021-560136; dated Apr. 12, 2024; 6 pages. [cited by applicant]
Renners, Leonard; “Modeling and learning incident prioritization”; IDAACS; dated Sep. 23, 2017; 6 pages. [cited by applicant]