首页> 外国专利> PROFILING CYBER THREATS DETECTED IN A TARGET ENVIRONMENT AND AUTOMATICALLY GENERATING ONE OR MORE RULE BASES FOR AN EXPERT SYSTEM USABLE TO PROFILE CYBER THREATS DETECTED IN A TARGET ENVIRONMENT

PROFILING CYBER THREATS DETECTED IN A TARGET ENVIRONMENT AND AUTOMATICALLY GENERATING ONE OR MORE RULE BASES FOR AN EXPERT SYSTEM USABLE TO PROFILE CYBER THREATS DETECTED IN A TARGET ENVIRONMENT

机译:对目标环境中检测到的网络威胁进行配置分析,并自动生成一个或多个规则库,用于可用于配置目标环境中检测到的网络威胁的专家系统

摘要

A method of automatically generating one or more rule bases for an expert system usable to profile cyber threats detected in a target environment, comprising the steps of: for each alert of a training set of alerts triggered by a potential cyber threat detected by an SIEM: retrieving captured packet data related to the alert; and extracting training threat data pertaining to a set of attributes from captured packet data triggering the alert; generating a predictive model of the level of risk posed by an alert based on attribute values for that alert by analysing the captured training threat data pertaining to the set of attributes; and generating a set of fuzzy rules based on the predictive model, said rules being usable at run time in a fuzzy logic engine to evaluate data pertaining to one or more of the extracted attributes of a detected cyber threat to determine values for one or more output variables indicative of a level of an aspect of risk attributable to the detected cyber threat.
机译:一种自动为专家系统自动生成一个或多个规则库的方法,该专家系统可用于分析在目标环境中检测到的网络威胁,包括以下步骤:对于由SIEM检测到的潜在网络威胁触发的警报训练集的每个警报:检索与警报有关的捕获的分组数据;从捕获到的触发警报的分组数据中提取与一组属性有关的训练威胁数据;通过分析捕获的与该属性集有关的训练威胁数据,基于该警报的属性值生成该警报所构成的风险级别的预测模型;并基于预测模型生成一组模糊规则,所述规则可在运行时在模糊逻辑引擎中用于评估与检测到的网络威胁的一个或多个提取属性有关的数据,以确定一个或多个输出的值指示可归因于检测到的网络威胁的风险方面的级别的变量。

著录项

  • 公开/公告号EP3340570A1

    专利类型

  • 公开/公告日2018-06-27

    原文格式PDF

  • 申请/专利权人 CYBERLYTIC LIMITED;

    申请/专利号EP20180157284

  • 申请日2014-12-05

  • 分类号H04L29/06;G06F21/55;G06F21/57;G06N5/04;G06N7/02;

  • 国家 EP

  • 入库时间 2022-08-21 13:15:34

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号