Correlation Rule
A correlation rule links events from various sources and triggers an Alert when a defined pattern is matched.
A correlation rule links several events into a single pattern before it triggers an Alert. It detects attacks composed of individual steps that appear harmless on their own.
How it works
The rule observes events from one or more sources over a specific time period. It connects them using common attributes like the same account, IP address, or device. An Alert is created if the defined conditions are met. Typical patterns include sequences, clusters, or the combination of events from different systems.
A practical example: an account has twenty failed logins within ten minutes. This is followed by a successful login. Shortly after, a forwarding rule is created in the mailbox. Each event on its own would hardly be suspicious. The correlation rule identifies the sequence as a probable account takeover.
What to look out for
- Sources must have common attributes. Different usernames in various systems prevent correlation.
- Time windows must be appropriate. A window that is too short misses slow attacks; one that is too long creates false positives.
- Test each rule with realistic data. This should include benign edge cases.
- Describe in the rule what the Alert means and what the next steps are.
Limitations
Correlation rules only detect patterns that have been previously described. New attack methods will evade them. This is why behavioural analysis and threat hunting complement these rules. Additionally, complex rules require significant computing power in the SIEM.
Typical mistakes
Correlation rules are often adopted from templates without being adapted to the specific environment. They then trigger on normal processes, such as during maintenance windows. A second mistake is creating rules that rely on sources no longer connected. They remain silent, and no one notices.
Relation to Detection as Code
Correlation rules are often complex and prone to error. Testing with sample data and performing reviews are therefore particularly important.
How we implement it
We manage our correlation rules as code: versioned, tested and tuned to your environment. If a log source fails, you receive a notification.