首页> 外国专利> System and method to infer investigation steps for security alerts using crowd sourcing

System and method to infer investigation steps for security alerts using crowd sourcing

机译:使用人群采购推断安全警报调查步骤的系统和方法

摘要

Techniques are provided to dynamically generate response actions that may be used to investigate and respond to a security alert. Different prediction models are initially trained using a corpus of training data. This training data is obtained by identifying previous security alerts and then grouping together alert clusters. An analysis is performed to identify which steps were used to respond to the alerts in each group. These steps are fed into a prediction model to train the model. After multiple models are trained and after a new security alert is received, one model is selected to operate on the new alert, where the model is selected because it is identified as being most compatible with the new alert. When the selected model is applied to the new alert, the model generates a set of recommended steps that may be followed to investigate and/or respond to the new alert.
机译:提供技术以动态生成可用于调查和响应安全警报的响应操作。最初使用培训数据的语料库训练不同的预测模型。通过识别先前的安全警报,然后将警报集群分组来获得此培训数据。执行分析以确定用于响应每个组中的警报的步骤。这些步骤被馈入预测模型以培训模型。经过多种型号培训并在收到新的安全警报之后,选择一个模型以在新警报上运行,选择模型,因为它被标识为与新警报最兼容的模型。当所选模型应用于新警报时,模型会生成一组可能遵循的推荐步骤,以便调查和/或响应新警报。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号