首页> 外国专利> CYBERSECURITY INCIDENT RESPONSE AND SECURITY OPERATION SYSTEM EMPLOYING PLAYBOOK GENERATION AND PARENT MATCHING THROUGH CUSTOM MACHINE LEARNING

CYBERSECURITY INCIDENT RESPONSE AND SECURITY OPERATION SYSTEM EMPLOYING PLAYBOOK GENERATION AND PARENT MATCHING THROUGH CUSTOM MACHINE LEARNING

机译:网络安全事件响应和安全运行系统通过自定义机器学习采用Playbook生成和父匹配

摘要

A cybersecurity incident is registered at a security incident response platform. At a playbook generation system, details are received of the cybersecurity incident from the security incident response platform. At least some of the details correspond to a set of features of the cybersecurity incident. A set or subset of nearest neighbors of the cybersecurity incident is localized in a feature space. The nearest neighbors of the cybersecurity incident are other cybersecurity incidents having a distance from the cybersecurity incident within the feature space that is defined by differences in features of the nearest neighbors with respect to the set of features of the cybersecurity incident. A playbook is created for responding to the cybersecurity incident having prescriptive procedures based on occurrences of prescriptive procedures previously employed in response to the nearest neighbor cybersecurity incidents. The differences in features of the nearest neighbors with respect to the set of features of the cybersecurity incident are calculated, for at least one feature, using a present-or-equal metric, and for at least one other feature, using a symmetric difference metric. The playbook generation system is also a parent recommendation system, which identifies a parent for the cybersecurity incident, based on distances of the nearest neighbors of the cybersecurity incident in the feature space. The parent recommendation system adjusts, based on the recommended parent or the parent other than the recommended parent being selected, weights of features upon which distances in the feature space are based.
机译:网络安全事件在安全事件响应平台上注册。在Playbobrbober生成系统中,收到了从安全事件响应平台的网络安全的细节。至少一些细节对应于网络安全事件的一组特征。网络安全事件的最近邻居的集合或子集在特征空间中本地化。网络安全事件的最近邻居是其他网络安全事件,其具有距离所在特征空间内的网络安全的距离,这些事件由最近邻居的特征的特征差异相对于网络安全事件的一组特征而定义。创建了一个Playbook,用于响应具有规定程序的网络安全事件,该事件基于以前用于响应最近的邻国安全事件的规定程序的出现。使用当前或等级度量的至少一个特征来计算最近邻居关于网络安全事件的一组特征的特征的差异,使用当前或等于的度量,以及至少一个其他特征,使用对称差异度量。 Playbook生成系统也是父推荐系统,其基于在特征空间中的网络安全的最近邻居的距离的距离基于最近的邻居的距离来识别网络安全事件的父母。父推荐系统基于所选择的推荐父级以外的推荐父级或父级调整,特征空间中的距离基于的功能权重。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号