A core activity within the aSIEMmetry project is the development of the security entropy multi-agent model. This model is designed to help Security Operations Centres identify meaningful behavioural changes across the assets and entities monitored through their existing SIEM infrastructure.
Traditional detection mechanisms often examine events using static rules, signatures or predefined thresholds. These controls remain important, but they may struggle when an attacker uses legitimate credentials, approved tools or low-volume actions that do not immediately match a known pattern.
Modelling more than individual alerts
The security entropy approach focuses on the state and behaviour of monitored assets over time. Instead of treating each alert as an isolated item, the model can evaluate relationships between devices, users, applications, identities and network activity.
Multiple specialized agents can analyse different aspects of the environment and contribute their observations to a wider assessment. This design supports more contextual detection because a small deviation on one asset may become significant when it appears together with unusual behaviour elsewhere.
Establishing useful behavioural baselines
A major development challenge is defining what normal behaviour means in a dynamic infrastructure. Assets change roles, users access new services and applications generate different volumes of activity over time. The model must therefore adapt without treating every legitimate change as a security incident.
The project is working toward baselines that are sufficiently flexible for operational environments while still being sensitive to meaningful anomalies. This requires reliable data preparation, consistent asset identification and careful evaluation of how different signals influence the entropy score.
Supporting rather than replacing analysts
The purpose of the model is not simply to produce another stream of alerts. Its value comes from helping analysts prioritize deviations that deserve investigation and understand why a particular asset or activity was considered unusual.
As development progresses, the consortium will continue evaluating model accuracy, explainability and integration with SOC processes. The security entropy model is one of the main foundations of aSIEMmetry’s objective: enabling earlier detection of emerging threats while reducing the operational burden created by fragmented and high-volume security data.