首页> 外国专利> SIMILARITY BASED APPROACH FOR CLUSTERING AND ACCELERATING MULTIPLE INCIDENTS INVESTIGATION

SIMILARITY BASED APPROACH FOR CLUSTERING AND ACCELERATING MULTIPLE INCIDENTS INVESTIGATION

机译:基于相似性的聚类方法和加速多次事件调查的方法

摘要

Systems, methods, and apparatuses are provided for clustering incidents in a computing environment. An incident notification relating to an event (e.g., a potential cyberthreat or any other alert) in the computing environment is received and a set of features may be generated based on the incident notification. The set of features may be provided as an input to a machine-learning engine to identify a similar incident notification in the computing environment. The similar incident notification may include a resolved incident notification or an unresolved incident notification. An action to resolve the incident notification may be received, and the received action may thereby be executed. In some implementations, in addition to resolving the received incident notification, the action may be executed to resolve a similar unresolved incident notification identified by the machine-learning engine.
机译:为计算环境中的聚类事件提供了系统,方法和装置。与事件(例如,潜在网络Threat或任何其他警报有关的事件通知接收到计算环境中并且可以基于入射通知生成一组特征。可以将该组特征作为机器学习引擎的输入提供,以识别计算环境中的类似事件通知。类似的事件通知可以包括解析的事件通知或未解决的事件通知。可以接收要解决事件通知的动作,并且可以执行接收的动作。在一些实现中,除了解析所接收的事件通知之外,可以执行该动作以解决由机器学习引擎识别的类似的未解决的事件通知。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号