Abstract
This thesis investigates the improvement of mechanisms for early detection of cybersecurity incidents in Security Information and Event Management (SIEM) systems based on correlation rules and log analysis. In modern information infrastructures, large volumes of security logs are generated by servers, network devices, web applications, databases, authentication systems, and other information resources, which limits the effectiveness of manually analyzing individual log entries. Therefore, a mechanism is proposed for centrally collecting, normalizing, correlating by time and context, and comprehensively analyzing security events obtained from various sources based on correlation rules. Particular attention is paid to identifying logical relationships among events such as anomalies in user authentication, repeated failed login attempts, privilege changes, unusual network activity, and access to critical resources. The proposed mechanism is based on the following stages: log collection → normalization → event correlation → risk assessment → alert generation → incident investigation and escalation. Formulating correlation rules according to event criticality, frequency of occurrence, time interval, source and target objects, and security context makes it possible to reduce false alerts and prioritize the detection of high-risk events. Consequently, the study substantiates that the use of SIEM and log analysis tools enables cybersecurity incidents to be detected and responded to not merely as individual signals but as sequences of interconnected events, thereby improving the speed of incident response.
References
1. Scarfone K., Mell P. Guide to Intrusion Detection and Prevention Systems (IDPS). NIST Special Publication 800-94. — Gaithersburg: National Institute of Standards and Technology, 2007. DOI: 10.6028/NIST.SP.800-94.
2. Kent K., Souppaya M. Guide to Computer Security Log Management. NIST Special Publication 800-92. — Gaithersburg: National Institute of Standards and Technology, 2006. DOI: 10.6028/NIST.SP.800-92.
3. National Institute of Standards and Technology. Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile. NIST Special Publication 800-61 Rev. 3. — Gaithersburg: NIST, 2025.
4. National Institute of Standards and Technology. Cybersecurity Framework (CSF) 2.0. — Gaithersburg: NIST, 2024. DOI: 10.6028/NIST.CSWP.29.
5. MITRE. MITRE ATT&CK®: Enterprise Matrix. — MITRE Corporation. Kiberhujumchilarning taktika va texnikalarini tasniflash hamda SIEM korrelyatsiya qoidalarini hujum ssenariylari bilan bog‘lash uchun metodologik manba.
6. Cichonski P., Millar T., Grance T., Scarfone K. Computer Security Incident Handling Guide. NIST Special Publication 800-61 Rev. 2. — Gaithersburg: NIST, 2012. DOI: 10.6028/NIST.SP.800-61r2.
7. Chuvakin A., Schmidt K., Phillips C. Logging and Log Management: The Authoritative Guide to Understanding the Concepts Surrounding Logging and Log Management. — Waltham: Syngress, 2013.
8. Kent K., Chevalier S., Grance T., Dang H. Guide to Integrating Forensic Techniques into Incident Response. NIST Special Publication 800-86. — Gaithersburg: NIST, 2006. DOI: 10.6028/NIST.SP.800-86.
9. National Institute of Standards and Technology. Security and Privacy Controls for Information Systems and Organizations. NIST Special Publication 800-53 Rev. 5. — Gaithersburg: NIST, 2020. DOI: 10.6028/NIST.SP.800-53r5.
10. OASIS. STIX™ Version 2.1. OASIS Standard. — 2021. Tahdidlar haqidagi ma’lumotlarni standartlashtirilgan shaklda ifodalash va xavfsizlik hodisalari o‘rtasidagi bog‘liqliklarni tavsiflash uchun qo‘llaniladigan standart.