首页> 外国专利> Enhancing cybersecurity and operational monitoring with alert confidence assignments

Enhancing cybersecurity and operational monitoring with alert confidence assignments

机译:通过警报置信分配增强网络安全和操作监控

摘要

Tools and techniques are described to automate triage of security and operational alerts. Insight instances extracted from raw event data associated with an alert are aggregated, vectorized, and assigned confidence scores through classification based on machine learning. Confidence scoring enables heavily loaded administrators and controls to focus attention and resources where they are most likely to protect or improve the functionality of a monitored system. Feature vectors receive a broad base in the underlying instance values through aggregation, even when the number of instance values is unknown prior to receipt of the event data. Visibility into the confidence scoring process may be provided, to allow tuning or inform further training of a classifier model. Performance metrics are defined, and production level performance may be achieved.
机译:描述了工具和技术来自动化安全性和操作警报的自动化。从与警报相关联的原始事件数据提取的Insight实例通过基于机器学习的分类来聚合,矢量化和分配的置信度分数。信心评分使得大量加载的管理员和控件能够焦点关注和资源,在那里他们最有可能保护或改善受监控系统的功能。特征向量通过聚合在底层实例值中接收广泛的基础,即使在接收到事件数据之前未知数量。可以提供对置信度评分过程的可视性,以允许调谐或通知进一步训练分类器模型。定义性能指标,并且可以实现生产水平性能。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号