首页> 外国专利> Learning based security threat containment

Learning based security threat containment

机译:基于学习的安全威胁遏制

摘要

Systems, methods, and software described herein provide action recommendations to administrators of a computing environment based on effectiveness of previously implemented actions. In one example, an advisement system identifies a security incident for an asset in the computing environment, and obtains enrichment information for the incident. Based on the enrichment information a rule set and associated recommended security actions are identified for the incident. Once the recommended security actions are identified, a subset of the action recommendations are organized based on previous action implementations in the computing environment, and the subset is provided to an administrator for selection.
机译:这里描述的系统,方法和软件为基于先前实现的动作的有效性提供给计算环境的管理员的动作建议。在一个示例中,建议系统识别计算环境中资产的安全事件,并获得事件的丰富信息。基于浓缩信息,确定了该事件的规则集和相关的推荐安全操作。一旦识别推荐的安全操作,就基于计算环境中的先前的操作实现来组织动作建议的子集,并且子集被提供给管理员以进行选择。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号