首页> 外国专利> SECURITY ALERT-INCIDENT GROUPING BASED ON INVESTIGATION HISTORY

SECURITY ALERT-INCIDENT GROUPING BASED ON INVESTIGATION HISTORY

机译:安全警报 - 基于调查历史的事件分组

摘要

Technology automatically groups security alerts into incidents using data about earlier groupings. A machine learning model is trained with select data about past alert-incident grouping actions. The trained model prioritizes new alerts and aids alert investigation by rapidly and accurately grouping alerts with incidents. The groupings are provided directly to an analyst or fed into a security information and event management tool. Training data may include entity identifiers, alert identifiers, incident identifiers, action indicators, action times, and optionally incident classifications. Investigative options presented to an analyst but not exercised may serve as training data. Incident updates produced by the trained model may add an alert to an incident, remove an alert, merge two incidents, divide an incident, or create an incident. Personalized incident updates may be based on a particular analyst's historic manual investigation actions. Grouped alerts may be standard, or be based on custom alert triggering rules.
机译:技术使用关于早期分组的数据自动将安全警报分组到事件中。机器学习模型接受了有关过去警报 - 事件分组操作的选择数据。训练有素的模型通过快速准确地分组事件的警报,优先考虑新警报和辅助警报调查。该分组直接提供给分析师或进入安全信息和事件管理工具。训练数据可以包括实体标识符,警报标识符,入射标识符,动作指示符,动作时间和可选事件分类。向分析师提供但不行使的调查选择可以作为培训数据。由培训的模型生成的事件更新可能会对事件添加警报,删除警报,合并两个事件,划分事件,或创建事件。个性化事件更新可以基于特定的分析师的历史性调查行动。分组的警报可能是标准的,或者基于自定义警报触发规则。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号