首页> 外国专利> Corroborating threat assertions by consolidating security and threat intelligence with kinetics data

Corroborating threat assertions by consolidating security and threat intelligence with kinetics data

机译:通过将动力学数据与安全性和威胁情报相结合来确认威胁断言

摘要

A cognitive security analytics platform is enhanced by providing a computationally- and storage-efficient data mining technique to improve the confidence and support for one or more hypotheses presented to a security analyst. The approach herein enables the security analyst to more readily validate a hypothesis and thereby corroborate threat assertions to identify the true causes of a security offense or alert. The data mining technique is entirely automated but involves an efficient search strategy that significantly reduces the number of data queries to be made against a data store of historical data. To this end, the algorithm makes use of maliciousness information attached to each hypothesis, and it uses a confidence schema to sequentially test indicators of a given hypothesis to generate a rank-ordered (by confidence) list of hypotheses to be presented for analysis and response by the security analyst.
机译:通过提供一种计算效率和存储效率高的数据挖掘技术来增强认知安全分析平台,以提高对提供给安全分析师的一个或多个假设的置信度和支持。本文中的方法使安全分析人员可以更容易地验证假设,从而确认威胁主张,以识别安全违法或警报的真正原因。数据挖掘技术是完全自动化的,但涉及一种有效的搜索策略,该策略可显着减少要对历史数据的数据存储进行的数据查询的数量。为此,该算法利用每个假设附带的恶意信息,并使用置信度模式依次测试给定假设的指标,以生成假设的等级排序列表(通过置信度),以进行分析和响应由安全分析师。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号