首页> 外国专利> SIMILARITY BASED APPROACH FOR CLUSTERING AND ACCELERATING MULTIPLE INCIDENTS INVESTIGATION

SIMILARITY BASED APPROACH FOR CLUSTERING AND ACCELERATING MULTIPLE INCIDENTS INVESTIGATION

机译:基于相似度的聚类和加速多事件调查的方法

摘要

Systems, methods, and apparatuses are provided for clustering incidents in a computing environment. An incident notification relating to an event (e.g., a potential cyberthreat or any other alert) in the computing environment is received and a set of features may be generated based on the incident notification. The set of features may be provided as an input to a machine-learning engine to identify a similar incident notification in the computing environment. The similar incident notification may include a resolved incident notification or an unresolved incident notification. An action to resolve the incident notification may be received, and the received action may thereby be executed. In some implementations, in addition to resolving the received incident notification, the action may be executed to resolve a similar unresolved incident notification identified by the machine-learning engine.
机译:提供了用于在计算环境中对事件进行聚类的系统,方法和装置。接收与计算环境中的事件(例如,潜在的网络威胁或任何其他警报)有关的事件通知,并且可以基于事件通知来生成一组特征。可以将特征集作为输入提供给机器学习引擎,以识别计算环境中的类似事件通知。相似事件通知可以包括解决的事件通知或未解决的事件通知。可以接收解决事件通知的动作,并且由此可以执行接收到的动作。在一些实施方式中,除了解决所接收的事件通知之外,还可以执行动作以解决由机器学习引擎标识的相似的未解决的事件通知。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号