首页> 外国专利> INFORMATION SECURITY RISK MANAGEMENT

INFORMATION SECURITY RISK MANAGEMENT

机译:信息安全风险管理

摘要

A method, system and computer program product for facilitating risk mitigation of information security threats. Data obtained from at least one tracked data source is analyzed for identifying at least one event related to a threat, to be stored in a database comprising date and time of each event identified, enabling generation of threat timeline comprising temporally ordered sequence of each event related to respective threat identified. Features selected using correlation between features from threat timelines in the database and labeling assigned using records of threat usage incidents are extracted from events in threat timeline for the threat which the at least one event related thereto being identified and based thereon a dynamic score indicating an estimated level of risk posed by the threat is calculated using at least one machine learning model for predicting threat usage during a time window defined, enabling risk mitigation based on outputted indication thereof.
机译:一种用于促进信息安全威胁的风险缓解的方法,系统和计算机程序产品。分析了从至少一个跟踪数据源获得的数据,用于识别与威胁相关的至少一个事件,以存储在包括所识别的每个事件的日期和时间的数据库中,从而能够生成包括每个相关事件的时间上有序的序列的威胁时间线的生成确定各自的威胁。使用来自威胁时间表之间的特征与使用威胁使用事件的记录分配的标签之间的相关特征从威胁时间线中的事件中提取,用于识别其与其相关的至少一个事件的威胁,并且基于其动态分数指示估计的动态分数威胁所带来的风险水平是使用至少一台机器学习模型计算用于预测定义时间窗口的威胁使用的机器学习模型,从而实现基于其输出指示的风险缓解。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号