首页> 外国专利> ENHANCING CYBERSECURITY AND OPERATIONAL MONITORING WITH ALERT CONFIDENCE ASSIGNMENTS

ENHANCING CYBERSECURITY AND OPERATIONAL MONITORING WITH ALERT CONFIDENCE ASSIGNMENTS

机译:通过机密保密分配增强网络安全和操作监控

摘要

Tools and techniques are described to automate triage of security and operational alerts. Insight instances extracted from raw event data associated with an alert are aggregated, vectorized, and assigned confidence scores through classification based on machine learning. Confidence scoring enables heavily loaded administrators and controls to focus attention and resources where they are most likely to protect or improve the functionality of a monitored system. Feature vectors receive a broad base in the underlying instance values through aggregation, even when the number of instance values is unknown prior to receipt of the event data. Visibility into the confidence scoring process may be provided, to allow tuning or inform further training of a classifier model. Performance metrics are defined, and production level performance may be achieved.
机译:描述了用于自动分类安全和操作警报的工具和技术。从与警报关联的原始事件数据中提取的Insight实例通过基于机器学习的分类进行汇总,矢量化和分配置信度得分。通过置信度评分,繁重的管理员和控件可以将注意力和资源集中在最有可能保护或改善受监视系统功能的位置。即使在接收事件数据之前不知道实例值的数量的情况下,特征向量也会通过聚合在基础实例值中获得广泛的基础。可以提供置信度评分过程的可见性,以允许调整或通知分类器模型的进一步训练。定义了绩效指标,可以实现生产水平的绩效。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号