Reliable anomaly detection depends on more than collecting logs. An AI model must understand which assets generated the data, how those assets are related and what behaviour is expected from them. For this reason, IT asset modelling is an important technical activity within aSIEMmetry.
The project is developing a multi-agent approach that represents the different entities observed by a SIEM environment. These entities may include endpoints, servers, identities, applications, network services and other operational components.
Creating a consistent view of the environment
Security data often arrives from several products, each using different names, identifiers and formats. One source may refer to a device by hostname, another by IP address and another by an internal agent identifier. Without normalization, the same asset can appear as several unrelated entities.
The asset-modelling activity therefore requires consistent identification and correlation. The project must determine how events are associated with the correct assets and how relationships are maintained when infrastructure changes.
Representing relationships and dependencies
An asset does not operate in isolation. A user signs in to a workstation, the workstation accesses an application and the application communicates with several services. These relationships provide important context during anomaly detection.
By modelling dependencies, aSIEMmetry can evaluate whether a change is limited to one component or forms part of a wider behavioural pattern. This is particularly useful when an incident develops gradually across several systems.
Supporting the entropy calculation
The asset model provides the structure required by the security entropy component. Entropy cannot be interpreted meaningfully without understanding the expected role and context of the monitored entity. A high level of activity may be normal for one server but highly unusual for another.
The project is therefore working toward a model that can combine asset characteristics, behavioural history and current observations. This structured representation will support both machine analysis and the explanations provided to SOC analysts.
As development continues, the consortium will validate how accurately the model represents real operational environments and how efficiently it can adapt to change. Strong asset modelling is a necessary foundation for the project’s wider objective of proactive, contextual and explainable threat detection.