首页> 外国专利> Cognitive offense analysis using contextual data and knowledge graphs

Cognitive offense analysis using contextual data and knowledge graphs

机译:使用上下文数据和知识图进行认知犯罪分析

摘要

An automated method for processing security events in association with a cybersecurity knowledge graph. The method begins upon receipt of information from a security system representing an offense. An initial offense context graph is built based in part on context data about the offense. The graph also activity nodes connected to a root node; at least one activity node includes an observable. The root node and its one or more activity nodes represent a context for the offense. The knowledge graph, and potentially other data sources, are then explored to further refine the initial graph to generate a refined graph that is then provided to an analyst for further review and analysis. Knowledge graph exploration involves locating the observables and their connections in the knowledge graph, determining that they are associated with known malicious entities, and then building subgraphs that are then merged into the initial graph.
机译:与网络安全知识图关联处理安全事件的自动化方法。该方法从接收到来自代表犯罪的安全系统的信息开始。初始犯罪上下文图部分基于有关犯罪的上下文数据构建。该图还将活动节点连接到根节点。至少一个活动节点包括可观察的。根节点及其一个或多个活动节点代表攻击的上下文。然后,探索知识图以及可能的其他数据源,以进一步完善初始图,以生成完善的图,然后将其提供给分析人员以进行进一步的检查和分析。知识图探索包括在知识图中定位可观察对象及其连接,确定它们与已知的恶意实体相关联,然后构建子图,然后将这些子图合并到初始图中。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号