← CYBERNETICSINTERN.COMCYBERNETIC INTERN
Detection EngineeringFOUNDATION

Correlation needs a shared identifier

Joining two sources requires a field that means the same thing in both. Most estates find out during an incident that they do not have one.

Correlation sounds like a platform feature. It is mostly a data problem.

To connect a VPN session to a workstation logon, something has to appear in both records and mean the same thing in both. A username, perhaps. Except the VPN logs slipare, the identity provider logs slipare@company.com, the endpoint logs COMPANY\slipare, and the HR system logs an employee number.

Four labels, one person, and nothing in your platform knows they are related unless somebody sat down and told it.

Hostnames are worse, because they are not stable. One laptop has a short name, a fully qualified name, an asset tag, a serial number, and an address that rotates. The address is the field most rules reach for and the one that means the least, because last week it belonged to somebody else.

So the work that pays off is boring and happens long before you need it. Normalise identities to one canonical form at ingest. Keep a mapping from every host identifier you see back to a single asset record. Carry a session or request identifier through the systems capable of emitting one.

Pick two sources you would certainly need together during an intrusion. Name the field that joins them. If it takes you longer than ten seconds, you do not have one yet.

CHECK YOURSELF

During an investigation you need to connect activity in a cloud audit log to a specific laptop. The audit log records a public IP address. Why is that often not enough?

SHOW THE ANSWER

Many devices share one public address, and the mapping behind it changes over time

Why. Address translation puts a whole office or VPN pool behind a handful of public addresses, so the value identifies an egress point rather than a machine, and the internal lease sitting behind it moves. Answering the question needs whatever recorded that mapping at that moment, usually DHCP or the VPN concentrator, and those records carry their own much shorter retention. The other three describe things that are not generally true: cloud audit logs do record source addresses, the log is at rest and readable, and address formatting is one of the few genuinely consistent fields across sources.

← ALL DETECTION ENGINEERING