首页> 外国专利> Systems and techniques for guiding a response to a cybersecurity incident

Systems and techniques for guiding a response to a cybersecurity incident

机译:指导对网络安全事件做出响应的系统和技术

摘要

A cybersecurity engine can guide a forensic investigation of a security incident by estimating the utility of investigating events associated with the security incident, selecting a subset of such events based on the estimated utilities, and presenting data associated with the selected events to the investigator. A method for guiding a response to a security incident may include estimating, for each of a plurality of security events associated with the security incident, a utility of investigating the security event. The method may further include selecting a subset of the security events based, at least in part, on the estimated utilities of investigating the security events. The method may further include guiding the response to the security incident by presenting, to a user, data corresponding to the selected security events.
机译:网络安全引擎可以通过估计调查与安全事件关联的事件的效用,基于估计的效用选择此类事件的子集以及将与所选事件关联的数据呈现给调查人员,来指导对安全事件进行法医调查。用于指导对安全事件的响应的方法可以包括针对与该安全事件相关联的多个安全事件中的每一个估计调查该安全事件的效用。该方法可以进一步包括至少部分地基于调查安全事件的估计效用来选择安全事件的子集。该方法可以进一步包括通过向用户呈现与所选择的安全事件相对应的数据来引导对安全事件的响应。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号