首页> 外国专利> Incident triage scoring engine

Incident triage scoring engine

机译:事件分类评分引擎

摘要

Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for incident response are disclosed. In one aspect, a computer-implemented method includes receiving data identifying two or more groups of actions performed to remediate a computer security threat. The method includes determining first unique paths from a first action of each of the two or more groups of actions to a second action of each of the two or more groups of actions, and determining second unique paths from the second action of each of the two or more groups of actions to a third action of each of the two or more groups of actions. The method also includes combining common paths among the first unique paths and the second unique paths, identifying one of the common paths that appears most frequently, and determining a core path that includes a subset of the actions of the two or more groups of actions based on the one of the common paths that appears most frequently.
机译:公开了用于事件响应的方法,系统和装置,包括编码在计算机存储介质上的计算机程序。在一个方面,一种计算机实现的方法包括:接收标识用于纠正计算机安全威胁而执行的两组或更多组动作的数据。该方法包括确定从两个或更多个动作组中的每个动作的第一动作到两个或更多个动作组中的每个动作的第二动作的第一唯一路径;以及从两个或更多个动作组中的每个动作的第二动作确定第二唯一路径。一个或多个动作组,以将两个或多个动作组中的每个动作中的第三个动作。该方法还包括:在第一唯一路径和第二唯一路径之间组合公共路径;识别最频繁出现的公共路径中的一个;以及基于两个或多个动作组的动作的子集来确定核心路径。在最常出现的常见路径之一上。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号