首页> 外国专利> Incident Response Plan based on Indicators of Compromise

Incident Response Plan based on Indicators of Compromise

机译:基于妥协指标的事件响应计划

摘要

A system and method for responding to incidents in an enterprise network is disclosed. The system tracks incidents by creating, in an incident Manager, incident objects for each incident. Each incident object includes details for the incidents, also known as incident characteristics. The system also creates one or more indicators of compromise (IOCs) associated with the incident characteristics for each incident. When processing a new incident or an update to an incident, the system compares IOCs associated with the incident object for the incident being processed to stored IOCs for other incidents to determine if other incidents are related to the incident being processed. In embodiments, the system can then generate tasks for responding to new incidents based on incident characteristics of and IOCs associated with the new incidents, and can regenerate tasks for responding to incidents based on updates to incident characteristics of and IOCs associated with the incidents.
机译:公开了一种用于响应企业网络中的事件的系统和方法。系统通过在事件管理器中为每个事件创建事件对象来跟踪事件。每个事件对象都包含事件的详细信息,也称为事件特征。该系统还为每个事件创建一个或多个与事件特征相关的危害指标(IOC)。在处理新事件或事件的更新时,系统会将与正在处理的事件的事件对象关联的IOC与已存储的其他事件的IOC进行比较,以确定其他事件是否与正在处理的事件相关。在实施例中,系统然后可以基于与新事件相关联的IOC的事件特征来生成用于响应新事件的任务,并且可以基于与事件相关联的事件特征和IOC的更新来重新生成用于响应事件的任务。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号