首页> 外国专利> MACHINE-LEARNING BASED APPROACH FOR DYNAMICALLY GENERATING INCIDENT-SPECIFIC PLAYBOOKS FOR A SECURITY ORCHESTRATION, AUTOMATION AND RESPONSE (SOAR) PLATFORM

MACHINE-LEARNING BASED APPROACH FOR DYNAMICALLY GENERATING INCIDENT-SPECIFIC PLAYBOOKS FOR A SECURITY ORCHESTRATION, AUTOMATION AND RESPONSE (SOAR) PLATFORM

机译:基于机器学习的方法,用于动态生成特定事件的剧本,用于安全编程,自动化和响应(SOAR)平台

摘要

Systems and methods for a machine-learning based approach for dynamically generating incident-specific playbooks for a security orchestration and automated response (SOAR) platform are provided. The SOAR platform captures information regarding execution of a sequence of actions performed by analysts responsive to a first incident of a first type. The captured information is fed into a machine-learning model. When a second incident, observed by the SOAR platform, is similar in nature to the first incident or the first type a recommended sequence of actions is generated based on the machine-learning model for use by an analyst in connection with responding to the second incident. In response to rejection of the recommended sequence by the analyst, revising the recommended sequence based on input provided by the analyst and storing the revised recommendation sequence in a form of a revised playbook for response to subsequent incidents that are similar to the second incident.
机译:提供了一种用于基于机器学习的方法和方法,用于动态生成特定于安全编程和自动响应(SOAR)平台的事件特定的剧本。 SOAR平台捕获关于响应于第一类型的第一个事件的分析师执行的一系列动作的执行信息。 捕获的信息被馈送到机器学习模型中。 当由SAR平台观察到的第二种事件与第一个事件或第一类型的基于机器学习模型类似于用于响应第二次事件时的分析师使用的机器学习模型类似 。 响应于分析师拒绝推荐序列,根据分析师提供的输入修订推荐序列,并以修订的比赛书的形式存储修订的推荐顺序,以应对与第二次事件类似的后续事件。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号