Risk information output device, information output system, risk information output method, and recording medium
US-2024414180-A1 · Dec 12, 2024 · US
US2017093902A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2017093902-A1 |
| Application number | US-201514871643-A |
| Country | US |
| Kind code | A1 |
| Filing date | Sep 30, 2015 |
| Priority date | Sep 30, 2015 |
| Publication date | Mar 30, 2017 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Techniques are disclosed for detecting security incidents based on low confidence security events. A security management server aggregates a collection of security events received from logs from one or more devices. The security management server evaluates the collection of security events based on a confidence score assigned to each distinct type of security event. Each confidence score indicates a likelihood that a security incident has occurred. The security management server determines, based on the confidence scores, at least one threshold for determining when to report an occurrence of a security incident from the collection of security events. Upon determining that at least one security event of the collection has crossed the at least one threshold, the security management server reports the occurrence of the security incident to an analyst.
Opening claim text (preview).
What is claimed is: 1 . A method, comprising: aggregating a collection of security events received from logs from one or more devices; evaluating the collection of security events based on a confidence score assigned to each distinct type of security event, wherein the confidence for each distinct type of security event indicates a likelihood that a security incident has occurred; determining, based on the confidence scores, at least one threshold for determining when to report an occurrence of a security incident from the collection of security events; and upon determining that at least one security event of the collection has crossed the at least one threshold, reporting the occurrence of the security incident to an analyst. 2 . The method of claim 1 , wherein, upon determining that the at least one security event of the collection has crossed the at least one threshold, the method further comprising: identifying the at least one security event associated with the security incident; generating a set of evidence comprising a list of at least one another security event associated with the at least one security event to justify the reporting of the security incident to the analyst, wherein the another security event has been observed to co-occur with any of the at least one security event within a predefined time period; and reporting the at least one security event and the set of evidence to the analyst. 3 . The method of claim 2 , further comprising: determining information regarding one or more criteria used to generate the set of evidence, wherein the one or more criteria comprises at least one of the confidence scores or one or more metrics used to determine the thresholds; reporting the information of the one or more criteria to the analyst; and providing a mechanism that allows the analyst to expose the set of evidence for one or more of the confidence scores. 4 . The method of claim 2 , further comprising: upon receiving feedback from an analyst, modifying at least one of the thresholds or the set of evidence, based on a type of the analyst feedback, wherein the type of analyst feedback indicates at least one of no response from the analyst, an indication that the security incident is a false-positive, or at least one change in the set of evidence. 5 . The method of claim 4 , further comprising determining that no response from the analyst indicates that the security incident is marked false-positive, and wherein modifying at least one of the thresholds or the set of evidence comprises adjusting the set of threshold values. 6 . The method of claim 4 , wherein upon determining the type of analyst feedback indicates at least one change in the set of evidence: determining the at least one change is based on the one or more criteria used to generate the set of evidence, and wherein modifying at least one of the thresholds or the set of evidence comprises automatically re-computing the confidence scores based on the updated set of evidence. 7 . The method of claim 3 , wherein the mechanism allows the analyst to select at least one of the another security event to indicate the another security event does not belong in the set of evidence. 8 . The method of claim 7 , wherein upon receiving an indication that one of the another security events does not belong in the set of evidence, the method further comprising: analyzing an estimated effect of removing the indicated another security event on the reporting of security incidents to the analyst; and determining, based on the analysis, whether to remove the indicated another security event from the set of evidence. 9 . The method of claim 8 , further comprising removing the indicated another security event from the set of evidence if the analysis indicates at least one of a decrease in a number of false-positive security incidents reported to the analyst or an increase in a number of reported security incidents that are resolved by the analyst. 10 . The method of claim 8 , further comprising not removing the indicated another security event from the set of evidence if the analysis indicates at least one of an increase in a number of false positive security incidents reported to the analyst or a decrease in a number of reported security incidents that are resolved by the analyst. 11 . The method of claim 2 , wherein the list is sorted by decreasing frequency of the at least one another security event, wherein the list further describes each of the at least one another security event by name and describes a percentage of time the at least one another security event co-occurred with any of the security events within the time period relative to a total number of occurrences of the security event with any another security event. 12 . The method of claim 2 , wherein the another security event indicates at least one of an infection, vulnerability, or attack. 13 . A computer-readable storage medium storing instructions, which, when executed on a processor, perform an operation, the operation comprising: aggregating a collection of security events received from logs from one or more devices; evaluating the collection of security events based on a confidence score assigned to each distinct type of security event, wherein the confidence for each distinct type of security event indicates a likelihood that a security incident has occurred; determining, based on the confidence scores, at least one threshold for determining when to report an occurrence of a security incident from the collection of security events; and upon determining that at least one security event of the collection has crossed the at least one threshold, reporting the occurrence of the security incident to an analyst. 14 . The computer-readable storage medium of claim 13 , wherein, upon determining that the at least one security event of the collection has crossed the at least one threshold, the operation further comprising: identifying the at least one security event associated with the security incident; generating a set of evidence comprising a list of at least one another security event associated with the at least one security event to justify the reporting of the security incident to the analyst, wherein the another security event has been observed to co-occur with any of the at least one security event within a predefined time period; and reporting the at least one security event and the set of evidence to the analyst. 15 . The computer-readable storage medium of claim 14 , further comprising: determining information regarding one or more criteria used to generate the set of evidence, wherein the one or more criteria comprises at least one of the confidence scores or one or more metrics used to determine the thresholds; reporting the information of the one or more criteria to the analyst; and providing a mechanism that allows the analyst to expose the set of evidence for one or more of the confidence scores. 16 . The computer-readable storage medium of claim 15 , wherein the mechanism allows the analyst to select at least one of the another security event to indicate the another security event does not belong in the set of evidence. 17 . The computer-readable storage medium of claim 16 , wherein upon receiving an indication that one of the another security events does not belong in the set of evidence, the method further comprising: analyzing an estimated effect of removing the indicated another security event on the reporting of security incidents to the analyst; and determining, based on the analysis, w
Event detection, e.g. attack signature detection · CPC title
Traffic logging, e.g. anomaly detection · CPC title
involving long-term monitoring or reporting · CPC title
Vulnerability analysis · CPC title
using filtering, e.g. reduction of information by using priority, element types, position or time · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.