首页> 外国专利> Automated determination of relevance of a security alert to one or more other security alerts based on shared markers

Automated determination of relevance of a security alert to one or more other security alerts based on shared markers

机译:基于共享标记自动确定安全警报与一个或多个其他安全警报的相关性

摘要

A processing device in one embodiment comprises a processor coupled to a memory and is configured to obtain a plurality of security alerts in a computer network, to process the security alerts to extract a plurality of markers from each of the security alerts, to compute at least one relevance score relating a given one of the security alerts to another one of the security alerts based at least in part on distance measures computed between markers shared by the given security alert and the other security alert, and to adjust at least one operating characteristic of a network security system of the computer network based at least in part on the relevance score. The relevance score may be computed as a function of a number of markers shared by the given security alert and the other security alert.
机译:在一个实施例中的处理设备包括耦合到存储器的处理器,并且被配置为在计算机网络中获得多个安全警报,以处理安全警报以从每个安全警报中提取多个标记,以至少计算一个相关性得分至少部分地基于由给定安全警报和另一个安全警报共享的标记之间计算的距离度量,将给定的一个安全警报与另一个安全警报相关联,并调整至少部分地基于相关性得分的计算机网络的网络安全系统。可以根据由给定安全警报和另一个安全警报共享的多个标记来计算相关性分数。

著录项

  • 公开/公告号US10263998B1

    专利类型

  • 公开/公告日2019-04-16

    原文格式PDF

  • 申请/专利权人 EMC IP HOLDING COMPANY LLC;

    申请/专利号US201615378336

  • 发明设计人 NITIN BHATT;VADIM BRUK;

    申请日2016-12-14

  • 分类号H04L29/06;G06N7;

  • 国家 US

  • 入库时间 2022-08-21 12:15:08

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号