Correlation involves relating several events.

Let's take a simple example.

A SIEM receives:

Event 1

47 failed authentication attempts on one account.

Then :

Event 2

Authentication successful from an unusual IP address.

Then :

Event 3

Creating a new administrator account.

Then :

Event 4

Access to multiple critical servers.

Then :

Event 5

Executing PowerShell.

Individually, these events may not trigger a critical alert.

When correlated, they can constitute a much more significant attack scenario.

The SIEM can then generate an alert of the following type:

“Suspected compromise of a privileged account.”

This capability constitutes a fundamental difference between:

collect logs

And

to actually use logs to detect threats.

Categories: