Invention Grant
- Patent Title: Automatic transformation of security event detection rules
-
Application No.: US15692429Application Date: 2017-08-31
-
Publication No.: US10586051B2Publication Date: 2020-03-10
- Inventor: Yoichi Hatsutori , Takuya Mishina , Naoto Sato , Fumiko Satoh
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Edward P. Li
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/57 ; G06F21/10 ; H04L29/06 ; G06F21/55

Abstract:
A computer-implemented method, a computer program product, and a computer system for transformation of security information and event management (SIEM) rules and deploying the SIEM rules in a network of event processors. A computer system or server converts the SIEM rules to formal representations. The computer system or server generates rule abstraction of the formal representations, by using an abstraction function. The computer system or server constructs a finite automaton based on the rule abstraction. The computer system or server eliminates irrelevant transitions in the finite automaton to generate an optimized finite automaton. The computer system or server generates optimized formal rules, based on the optimized finite automaton. The computer system or server converts the optimized formal rules to optimized SIEM rules. The computer or server deploys the optimized SIEM rules in the network of the event processors.
Public/Granted literature
- US20190065755A1 AUTOMATIC TRANSFORMATION OF SECURITY EVENT DETECTION RULES Public/Granted day:2019-02-28
Information query