首页> 外国专利> Systems and techniques for guiding a response to a cybersecurity incident

Systems and techniques for guiding a response to a cybersecurity incident

机译:用于指导对网络安全事件响应的系统和技术

摘要

A cybersecurity engine can guide a forensic investigation of a security incident by estimating the utility of investigating events associated with the security incident, selecting a subset of such events based on the estimated utilities, and presenting data associated with the selected events to the investigator. A method for guiding a response to a security incident may include estimating, for each of a plurality of security events associated with the security incident, a utility of investigating the security event. The method may further include selecting a subset of the security events based, at least in part, on the estimated utilities of investigating the security events. The method may further include guiding the response to the security incident by presenting, to a user, data corresponding to the selected security events.
机译:网络安全引擎可以通过估计与安全事件相关的事件的实用性来指导对安全事件的法医研究,基于估计的实用程序选择这些事件的子集,并将与所选事件相关联的数据呈现给调查器。用于指导对安全事件的响应的方法可以包括估计与安全事件相关联的多个安全事件中的每一个,该公用事型研究安全事件。该方法还可以包括至少部分地基于研究安全事件的估计实用程序的基于安全事件的子集。该方法还可以包括通过向用户呈现对应于所选择的安全事件的数据来指导对安全事件的响应。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号