MECHANISM FOR EARLY DETECTION OF CYBERSECURITY INCIDENTS BASED ON CORRELATION RULES AND LOG ANALYSIS IN SIEM SYSTEMS
PDF

Keywords

SIEM, log analysis, correlation rules, cybersecurity incident, early incident detection, security monitoring, log data, anomaly, risk assessment, alert, incident detection, information security.

How to Cite

Ashurov Laziz. (2026). MECHANISM FOR EARLY DETECTION OF CYBERSECURITY INCIDENTS BASED ON CORRELATION RULES AND LOG ANALYSIS IN SIEM SYSTEMS. Sog‘liqni Saqlashda Yangi Yondashuvlar, 1(6), 54-67. https://doi.org/10.5281/zenodo.22748904

Abstract

This thesis investigates the improvement of mechanisms for the early detection of cybersecurity incidents in Security Information and Event Management (SIEM) systems based on correlation rules and log analysis. In modern information infrastructures, large volumes of security logs are generated by servers, network devices, web applications, databases, authentication systems, and other information resources, which limits the effectiveness of manually analyzing individual log entries. Therefore, a mechanism is proposed for the centralized collection, normalization, temporal and contextual correlation, and comprehensive analysis of security events obtained from various sources based on correlation rules. Particular attention is paid to identifying logical relationships among events such as anomalies in user authentication, repeated failed login attempts, privilege changes, unusual network activity, and access to critical resources. The proposed mechanism is based on the following stages: log collection → normalization → event correlation → risk assessment → alert generation → incident investigation and escalation. Formulating correlation rules according to event criticality, frequency of occurrence, time intervals, source and target objects, and security context makes it possible to reduce false-positive alerts and prioritize the detection of high-risk events. As a result, the use of SIEM and log analysis tools is shown to enable cybersecurity incidents to be identified not merely as individual signals, but as sequences of interconnected events, thereby improving the speed of incident response.

PDF

References

1. Scarfone K., Mell P. Guide to Intrusion Detection and Prevention Systems (IDPS). NIST Special Publication 800-94. — Gaithersburg: National Institute of Standards and Technology, 2007. DOI: 10.6028/NIST.SP.800-94.

2. Kent K., Souppaya M. Guide to Computer Security Log Management. NIST Special Publication 800-92. — Gaithersburg: National Institute of Standards and Technology, 2006. DOI: 10.6028/NIST.SP.800-92.

3. National Institute of Standards and Technology. Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile. NIST Special Publication 800-61 Rev. 3. — Gaithersburg: NIST, 2025.

4. National Institute of Standards and Technology. Cybersecurity Framework (CSF) 2.0. — Gaithersburg: NIST, 2024. DOI: 10.6028/NIST.CSWP.29.

5. MITRE. MITRE ATT&CK®: Enterprise Matrix. — MITRE Corporation. Kiberhujumchilarning taktika va texnikalarini tasniflash hamda SIEM korrelyatsiya qoidalarini hujum ssenariylari bilan bog‘lash uchun metodologik manba.

6. Cichonski P., Millar T., Grance T., Scarfone K. Computer Security Incident Handling Guide. NIST Special Publication 800-61 Rev. 2. — Gaithersburg: NIST, 2012. DOI: 10.6028/NIST.SP.800-61r2.

7. Chuvakin A., Schmidt K., Phillips C. Logging and Log Management: The Authoritative Guide to Understanding the Concepts Surrounding Logging and Log Management. — Waltham: Syngress, 2013.

8. Kent K., Chevalier S., Grance T., Dang H. Guide to Integrating Forensic Techniques into Incident Response. NIST Special Publication 800-86. — Gaithersburg: NIST, 2006. DOI: 10.6028/NIST.SP.800-86.

9. National Institute of Standards and Technology. Security and Privacy Controls for Information Systems and Organizations. NIST Special Publication 800-53 Rev. 5. — Gaithersburg: NIST, 2020. DOI: 10.6028/NIST.SP.800-53r5.

10. OASIS. STIX™ Version 2.1. OASIS Standard. — 2021. Tahdidlar haqidagi ma’lumotlarni standartlashtirilgan shaklda ifodalash va xavfsizlik hodisalari o‘rtasidagi bog‘liqliklarni tavsiflash uchun qo‘llaniladigan standart.