Theory of correlation
Correlation has been a trendy term in the SIEM space for more than a decade now. The idea of mixing events from the same or different data sources to spot anomalies was a selling point.
Strictly speaking, correlation is a statistical mechanism that processes two or more events to analyze and compare them with each other. However, for a long time, the information security (InfoSec) community has been referring to correlation mainly with pattern-matching examples that process one single event at a time. Nowadays, several new detection techniques exist. The term correlation is used when the detection logic is processing one or more events. From now on, when we mention correlation, we are referring to any type of detection logic that can be created within a detection rule.
There is no common terminology when it comes to the types of detection logic/rules. Each one has its own definition, especially as security vendors use a naming convention to match their...