SCENARIO- AND RISK-WEIGHTED LOGGING DEFICIT METHODOLOGY FOR SIEM WITH A PROBABILISTIC INTENSITY BASELINE AND ASSESSMENT OF EVENT SUITABILITY FOR CORRELATION
Abstract
Relevance. The effectiveness of correlation in SIEM is determined not only by the completeness of incoming events, but also by their suitability for scenario-based analysis. Practical logging defects, including under-logging, violations of temporal consistency, loss of mandatory attributes, and record duplication, degrade detection quality and increase the likelihood of false positives. Objective. To develop a scenario- and risk-weighted methodology for the quantitative assessment of logging deficit as a measure of the suitability of an event stream for correlation. Tasks. To form a scenario-justified set of controlled event classes, assign risk weights to them, construct a probabilistic baseline intensity profile, introduce criteria of temporal validity and structural suitability of records, and obtain an integral indicator with diagnostic interpretation of the causes of logging quality degradation. Methods. The study employs scenario analysis of detection content, risk-weighted aggregation, baseline construction from historical data, monitoring of event temporal validity, and assessment of the completeness of minimally sufficient profiles of correlation-significant attributes. Results. The proposed method extends the basic logging deficit indicator by introducing a probabilistic baseline intensity profile, sensitivity to over-logging, loss of correlation-significant fields, and a diagnostic decomposition of logging quality degradation causes. Experimental validation showed that in the baseline mode, DL_new = 0.000 while DL_old = 0.297, confirming the absence of false positives produced by the new indicator on a normal event stream. In the duplication scenario, DL_old = 0.000 while DL_new = 0.073, demonstrating the ability of the new inidcator to detect over-logging that remains invisible to the basic indicator. When temporal consistency is violated, all indicators reach 1.000, which corresponds to the complete unsuitability of the event stream for correlation. Conclusions and significance. The scientific novelty lies in the formalization of logging deficit as a deficit of event-stream suitability for correlation, taking into account the scenario significance of event classes and introducing a diagnostic decomposition that makes it possible to identify the dominant diagnostic component of degradation. The practical significance lies in the ability to quantitatively justify priority measures for improving event sources, normalization procedures, and correlation rules in SIEM.
##article.references##
1. NIST SP 800-92. Rukovodstvo po upravleniyu zhurnalami sobytiy komp'yuternoy bezopasnosti. Natsional'nyy institut standartov i tekhnologiy SShA, 2006 [NIST SP 800-92. Guide to Computer Securi-ty Log Management. National Institute of Standards and Technology, 2006]. Available at: https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-92.pdf.
2. Gonsales-Granadil'o G., Gonsales-Sarsosa S., Dias R. Sistemy upravleniya informatsiey i sobytiyami bezopasnosti (SIEM): analiz, tendentsii i primenenie v kriticheskikh infrastrukturakh [Security Information and Event Management (SIEM): Analysis, Trends, and Usage in Critical Infrastructures], Sensors, 2021, Vol. 21, No. 14. Art. 4759. DOI: 10.3390/s21144759.
3. CIS Controls v8.1. Kontrol' 8: Upravlenie zhurnalami audita. TSentr internet-bezopasnosti, 2021 [CIS Controls v8.1. Control 8: Audit Log Management. Center for Internet Security, 2021]. Available at: https://cas.docs.cisecurity.org/en/latest/source/Controls8/.
4. Elastic Filebeat Documentation: Deduplikatsiya dannykh (dostavka tipa at-least-once). Elastic N.V., 2024 [Elastic Filebeat Documentation: Deduplicate data (at-least-once duplicates). Elastic N.V., 2024]. Available at: https://www.elastic.co/guide/en/beats/filebeat/8.19/filebeat-deduplication.html.
5. Elastic Filebeat Documentation: Rotatsiya zhurnalov privodit k potere ili dublirovaniyu sobytiy. Elastic N.V., 2024 [Elastic Filebeat Documentation: Log rotation results in lost or duplicate events. Elastic N.V., 2024]. Available at: https://www.elastic.co/guide/en/beats/filebeat/8.19/file-log-rotation.html.
6. Studiavan Kh., Sokhel F., Peyn K. Obzor metodov kriminalisticheskogo issledovaniya zhurnalov oper-atsionnykh sistem [A survey on forensic investigation of operating system logs], Digital Investigation, 2019, Vol. 29, pp. 1-20. DOI: 10.1016/j.diin.2019.02.005.
7. Koppolino L., D'Antonio S., Formikola V., Romano L. Sovershenstvovanie tekhnologii SIEM dlya zash-chity kriticheskikh infrastruktur [Enhancing SIEM technology to protect critical infrastructures], Critical Information Infrastructures Security (CRITIS 2011). LNCS. Vol. 6983. Springer, 2013,
pp. 10-21. DOI: 10.1007/978-3-642-41476-3_2.
8. Kotenko I.V., Gayfulina D.A., Zelichenok I.I. Sistematicheskiy obzor metodov korrelyatsii sobytiy be-zopasnosti [Systematic literature review of security event correlation methods], IEEE Access, 2022, Vol. 10, pp. 43387-43420. DOI: 10.1109/ACCESS.2022.3168976.
9. Chua E., Kalutarazh Kh., Tasdemir K., Abrakham A., Meypl K. Sistematicheskiy obzor instrumentov log-korrelyatsii dlya obnaruzheniya i prognozirovaniya kiberatak v krupnykh setyakh [A systematic literature review of log-correlation tools for cyberattack detection and prediction in large networks], Journal of In-formation Security and Applications, 2025, Vol. 92. Art. 104096. DOI: 10.1016/j.jisa.2025.104096.
10. Ivanov A.V., Kiselev M.A. Metodika otsenki kachestva logirovaniya sobytiy informatsionnoy bezopasnosti v iteratsionno-upravlencheskom tsikle s primeneniem metriki defitsita logirovaniya [Methodology for as-sessing the quality of information security event logging in an iterative management cycle using the log-ging deficit metric], Doklady TUSURa [Proceedings of TUSUR University], 2026, Vol. 29, No. 1, pp. 114-123. DOI: 10.21293/1818-0442-2026-29-1-114-123.
11. Gerkhards R. Protokol Syslog. RFC 5424 [The Syslog Protocol. RFC 5424], IETF, 2009. Available at: https://datatracker.ietf.org/doc/html/rfc5424.
12. Fisher D., Goel K., Endryus R. i dr. Povyshenie kachestva zhurnalov sobytiy: obnaruzhenie i kolich-estvennaya otsenka defektov vremennykh metok [Enhancing event log quality: detecting and quantifying timestamp imperfections], Business Process Management (BPM 2020). LNCS. Vol. 12168. Springer, 2020, pp. 309-326. DOI: 10.1007/978-3-030-58666-9_18.
13. Van R.Y., Strong D.M. Za predelami tochnosti: chto kachestvo dannykh oznachaet dlya potrebiteley [Be-yond accuracy: what data quality means to data consumers], Journal of Management Information Systems, 1996, Vol. 12, No. 4, pp. 5-33. DOI: 10.1080/07421222.1996.11518099.
14. NIST/SEMATECH. Elektronnyy spravochnik po statisticheskim metodam. Merki razbrosa: mezhkvartil'nyy razmakh [NIST/SEMATECH e-Handbook of statistical methods. Measures of scale: in-terquartile range]. Available at: https://itl.nist.gov/div898/handbook/eda/section3/eda352.htm.
15. NIST/SEMATECH. Elektronnyy spravochnik po statisticheskim metodam. Vyborochnye kvantili [NIST/SEMATECH e-Handbook of statistical methods. Sample quantiles]. Available at: https://itl.nist.gov/div898/software/dataplot/refman2/auxillar/quantile.htm.
16. Levshun D.S., Kotenko I.V. Obzor metodov iskusstvennogo intellekta dlya korrelyatsii sobytiy bezopas-nosti: modeli, vyzovy i vozmozhnosti [A survey on artificial intelligence techniques for security event cor-relation: models, challenges, and opportunities], Artificial Intelligence Review, 2023, Vol. 56, pp. 8547-8590. DOI: 10.1007/s10462-022-10381-4.
17. Kotenko I.V., Fedorchenko A.V., Doynikova E.V. Analitika dannykh dlya upravleniya bezopasnost'yu slozhnykh geterogennykh sistem: zadachi korrelyatsii sobytiy i otsenki zashchishchennosti [Data analytics for security management of complex heterogeneous systems: event correlation and security assessment tasks], Advances in Cyber Security Analytics and Decision Systems. Springer, Cham, 2020, pp. 79-116. DOI: 10.1007/978-3-030-19353-9_5.
18. Brayant B.D., Saedian Kh. Uluchshenie agregatsii metadannykh alertov SIEM s ispol'zovaniem novoy klassifikatsionnoy modeli na osnove kill-chain [Improving SIEM alert metadata aggregation with a novel kill-chain based classification model], Computers & Security, 2020, Vol. 94, Art. 101783. DOI: 10.1016/j.cose.2020.101783.
19. Shiraz M. i dr. Effektivnyy monitoring bezopasnosti s ispol'zovaniem optimizirovannoy arkhitektury SIEM [Effective security monitoring using efficient SIEM architecture], Human-centric Computing and Information Sciences, 2023, Vol. 13, Art. 17. DOI: 10.22967/HCIS.2023.13.017.
20. Erlinger L., Voss V. Obzor instrumentov izmereniya i monitoringa kachestva dannykh [A survey of data quality measurement and monitoring tools], Frontiers in Big Data, 2022, Vol. 5, Art. 850611. DOI: 10.3389/fdata.2022.850611.








