Alert priority setting device, alert priority setting method, and alert priority setting program
The alert priority setting device addresses the challenge of prioritizing alerts by calculating frequency scores through time-specific analysis, enabling automatic and effective prioritization of alerts without pre-defined rules.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- MITSUBISHI ELECTRIC CORP
- Filing Date
- 2024-11-22
- Publication Date
- 2026-06-03
AI Technical Summary
Existing alert prioritization methods fail to address alerts with high appearance frequencies and lack the ability to determine the degree of danger and type of attack, especially in machine learning-based anomaly detection systems.
An alert priority setting device that calculates an alert frequency score by dividing alert logs by time periods, counting frequencies, and using statistical analysis to determine outlier scores, which are then used to set priorities.
Enables appropriate prioritization of alerts based on frequency trends, automatically determining priorities without pre-defined rules, and effectively distinguishing between normal and anomalous activity.
Smart Images

Figure 2026090765000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a technique for determining the priority of alerts.
Background Art
[0002] Patent Document 1 discloses a method for assigning priorities to alerts. This method clusters combinations of different alerts (such as IDS) that appear in a fixed time unit, extracts clusters (combinations of alerts) with low appearance frequencies, and assigns priorities by utilizing the CVE information included in the alerts.
[0003] The method of Patent Document 1 has the following problems. Alerts or their combinations with high appearance frequencies may be ignored. In anomaly detection (especially machine learning-based anomaly detection), only information regarding whether an event is probabilistically rare can be obtained as a risk value, and the degree of danger of an attack and the type of attack are unknown. Therefore, priorities cannot be assigned based on them.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] An object of the present disclosure is to enable appropriate priorities for alerts to be determined.
Means for Solving the Problems
[0006] The alert priority setting device of the present disclosure An alert analysis unit divides the alert log for the target entity to obtain multiple time-specific alert logs corresponding to multiple time periods, counts the number of alerts included in the time-specific alert log for each time period as the alert frequency, calculates statistics of the alert frequency for past time periods as alert statistics, and uses the alert frequency for the target time period and the alert statistics for past time periods to calculate an alert frequency score, which is a score for the target alert log, which is the time-specific alert log for the target time period, for the target entity. A priority calculation unit that calculates the priority of the target alert log using the alert frequency score, It is equipped with. [Effects of the Invention]
[0007] According to this disclosure, it is possible to determine the appropriate priority for alerts. [Brief explanation of the drawing]
[0008] [Figure 1] Configuration diagram of the alert priority setting system 200 in Embodiment 1. [Figure 2] Configuration diagram of the alert priority setting device 100 in Embodiment 1. [Figure 3] Functional configuration diagram of the alert priority setting device 100 in Embodiment 1. [Figure 4] Configuration diagram of the alert analysis unit 120 in Embodiment 1. [Figure 5] A flowchart of the alert priority setting method in Embodiment 1. [Figure 6] Flowchart of step S110 in Embodiment 1. [Figure 7] Flowchart of step S120 in Embodiment 1. [Figure 8] Functional configuration diagram of the alert priority setting device 100 in Embodiment 2. [Figure 9] Configuration diagram of the alert analysis unit 120 in Embodiment 2. [Figure 10]Flowchart of the alert priority setting method in Embodiment 2. [Figure 11] Flowchart of step S200 in Embodiment 2. [Figure 12] Flowchart of step S250 in Embodiment 2. [Figure 13] Functional configuration diagram of the alert priority setting device 100 in Embodiment 3. [Figure 14] Configuration diagram of the alert analysis unit 120 in Embodiment 3. [Figure 15] Flowchart of the alert priority setting method in Embodiment 3. [Figure 16] Flowchart of step S300 in Embodiment 3. [Figure 17] Functional configuration diagram of the alert priority setting device 100 in Embodiment 4. [Figure 18] Configuration diagram of the alert analysis unit 120 in Embodiment 4. [Figure 19] Flowchart of the alert priority setting method in Embodiment 4. [Figure 20] Flowchart of step S400 in Embodiment 4. [Figure 21] Configuration diagram of the alert priority setting system 200 in Embodiment 5. [Figure 22] Functional configuration diagram of the alert priority setting device 100 in Embodiment 5. [Figure 23] Configuration diagram of the alert analysis unit 120 in Embodiment 5. [Figure 24] Flowchart of the alert priority setting method in Embodiment 5. [Figure 25] [[ID=I45]]Flowchart of step S500 in Embodiment 5. [Figure 26] Functional configuration diagram of the alert priority setting device 100 in Embodiment 6. [Figure 27] Configuration diagram of the alert analysis unit 120 in Embodiment 6. [Figure 28]A flowchart of the alert priority setting method in Embodiment 6. [Figure 29] Flowchart of step S600 in Embodiment 6. [Figure 30] Functional configuration diagram of the alert priority setting device 100 in Embodiment 7. [Figure 31] Flowchart of the difference identification unit 151 in Embodiment 7. [Figure 32] This figure shows an example of a bar graph of classification contribution in Embodiment 7. [Figure 33] A diagram showing an example of a pie chart of classification contribution in Embodiment 7. [Figure 34] This figure shows an example of a bar graph of classification contribution in Embodiment 7. [Figure 35] A figure showing an example of a scatter plot of classification contribution in Embodiment 7. [Figure 36] Functional configuration diagram of the alert priority setting device 100 in Embodiment 8. [Figure 37] Configuration diagram of the alert analysis unit 120 in Embodiment 8. [Figure 38] A flowchart of the alert priority setting method in Embodiment 8. [Figure 39] Flowchart of step S800 in Embodiment 8. [Figure 40] Flowchart of step S840 in Embodiment 8. [Figure 41] Functional configuration diagram of the alert priority setting device 100 in Embodiment 9. [Figure 42] Configuration diagram of the alert analysis unit 120 in Embodiment 9. [Figure 43] A flowchart of the alert priority setting method in Embodiment 9. [Figure 44] Flowchart of step S900 in Embodiment 9. [Figure 45] Flowchart of step S910 in Embodiment 9. [Figure 46] A diagram illustrating an overview of the embodiment. [Figure 47] A diagram illustrating an overview of the embodiment. [Figure 48] Conceptual diagram of TFIDF analysis in an embodiment. [Figure 49] Conceptual diagram of TFIDF analysis in an embodiment. [Figure 50] A diagram showing the relationship between TFIDF analysis and the score in the embodiment. [Modes for carrying out the invention]
[0009] In the embodiments and drawings, the same or corresponding elements are denoted by the same reference numeral. The descriptions of elements denoted by the same reference numeral as the described elements are omitted or simplified as appropriate. The arrows in the figures mainly indicate the flow of data or processing.
[0010] Embodiment 1. The alert priority setting device 100 will be explained with reference to Figures 1 to 7.
[0011] ***Explanation of the structure*** Based on Figure 1, the configuration of the alert priority setting system 200 will be explained. The alert priority setting system 200 includes a security sensor 210 and an alert priority setting device 100.
[0012] The security sensor 210 is an attack detection system. An attack detection system analyzes various pieces of information to detect attacks against various entities and generates alerts for each entity that has been targeted. The generation of an alert is also called a notification. Attack detection systems include rule-based systems such as SIEM and machine learning-based systems such as anomaly detection. An entity is, for example, a user or a device. Entities are identified by username, device name, IP address, etc. In addition to usernames and device names, other criteria such as source IP address, destination IP address, rules used, and alert urgency can be used to distinguish entities, and combinations of these criteria are also available. The username is the name of the person who logs into the terminal and uses it for work purposes. A device name is a name that uniquely identifies a device within a network. A device name is also called a hostname. The source IP address is the IP address of the device that sent the data during the communication. The destination IP address is the IP address of the terminal that received the data during the communication. The rules used refer to the rules that were used when an alert was triggered by the IDS, FW, or SIEM. The alert's urgency represents the severity level set for alerts in systems such as IDS or SIEM. IP is an abbreviation for Internet Protocol. IDS is an abbreviation for Intrusion Detection System. FW is an abbreviation for Firewall. SIEM is an abbreviation for Security Information and Event Management.
[0013] The embodiments describe the user as an entity.
[0014] Alert log 220 is an alert log obtained from security sensor 210. An alert log is a collection of alerts that have occurred. In other words, an alert log is one or more alerts that have occurred.
[0015] Related log 230 is a related log obtained from the security sensor 210. Related logs are a collection of information analyzed to determine whether or not an alert should be issued. In other words, related log 230 is an alert-related log for alert log 220. Alert-related logs are logs that are analyzed by SIEM or anomaly detection. These logs include proxy logs, AD logs, and event logs. When alert (A) is issued, alert-related logs for the time period surrounding the time when alert (A) was issued (the time period when the alert was issued) are analyzed. If the alarm activation time period is represented by [t_min[A], t_max[A]], the surrounding time period is represented by [t_min[A]-α, t_max[A]+β]. "α" and "β" are predetermined. For example, "α" and "β" are both 24 hours.
[0016] The alert priority setting device 100 sets a priority for alerts generated by the security sensor 210.
[0017] Based on Figure 2, the configuration of the alert priority setting device 100 will be explained. The alert priority setting device 100 is a computer equipped with hardware such as a processor 101, memory 102, auxiliary storage device 103, communication device 104, and input / output interface 105. These hardware components are connected to each other via signal lines.
[0018] The processor 101 is an IC that performs arithmetic operations and controls other hardware. For example, the processor 101 may be a CPU, DSP, GPU, or a combination of these. IC is an abbreviation for Integrated Circuit. CPU is an abbreviation for Central Processing Unit. DSP is an abbreviation for Digital Signal Processor. GPU is an abbreviation for Graphics Processing Unit.
[0019] Memory 102 is a volatile or non-volatile storage device. Memory 102 is also called main memory. For example, memory 102 is RAM. Data stored in memory 102 is saved to auxiliary storage device 103 as needed. RAM is an abbreviation for Random Access Memory.
[0020] The auxiliary storage device 103 is a non-volatile storage device. For example, the auxiliary storage device 103 is a ROM, HDD, flash memory, or a combination thereof. Data stored in the auxiliary storage device 103 is loaded into memory 102 as needed. ROM is an abbreviation for Read Only Memory. HDD is an abbreviation for Hard Disk Drive.
[0021] The communication device 104 is a receiver and transmitter. For example, the communication device 104 is a communication chip or NIC. Communication of the alert priority setting device 100 is performed using the communication device 104. NIC is an abbreviation for Network Interface Card.
[0022] The input / output interface 105 is a port to which input and output devices are connected. For example, the input / output interface 105 is a USB terminal, the input devices are a keyboard and mouse, and the output device is a display. Input and output of the alert priority setting device 100 are performed via the input / output interface 105. USB is an abbreviation for Universal Serial Bus.
[0023] The alert priority setting device 100 comprises elements such as an alert acquisition unit 110, an alert analysis unit 120, a priority calculation unit 130, and an alert output unit 140. These elements are implemented by software.
[0024] The auxiliary storage device 103 stores an alert priority setting program that enables the computer to function as an alert acquisition unit 110, an alert analysis unit 120, a priority calculation unit 130, and an alert output unit 140. The alert priority setting program is loaded into memory 102 and executed by the processor 101. The auxiliary storage device 103 also stores the operating system. At least a portion of the OS is loaded into memory 102 and executed by the processor 101. Processor 101 runs the alert priority setting program while simultaneously running the OS. OS is an abbreviation for Operating System.
[0025] The data for the alert priority setting program (input data, output data, etc.) is stored in the storage unit 190. Memory 102 functions as a storage unit 190. However, storage devices such as auxiliary storage device 103, registers in the processor 101, and cache memory in the processor 101 may function as a storage unit 190 instead of memory 102, or together with memory 102.
[0026] The alert priority setting program can be recorded (stored) in a computer-readable format on a non-volatile recording medium such as an optical disc or flash memory.
[0027] Figure 3 shows the functional configuration of the alert priority setting device 100. Alert log 221, related log 231, score 121, priority 131, and prioritized log 141 will be discussed later.
[0028] Based on Figure 4, the configuration of the alert analysis unit 120 will be explained. The alert analysis unit 120 includes an outlier analysis unit 310. The outlier analysis unit 310 includes an alert frequency calculation unit 311, an alert statistics calculation unit 312, and an outlier calculation unit 313. Frequency information 314, frequency information 315, and statistical information 316 will be described later.
[0029] ***Explanation of operation*** The operating procedure of the alert priority setting device 100 corresponds to the alert priority setting method. Furthermore, the operating procedure of the alert priority setting device 100 corresponds to the processing procedure of the alert priority setting program.
[0030] Based on Figure 5, we will explain how to set alert priorities. In step S110, the alert acquisition unit 110 acquires the alert log 221.
[0031] Step S110 will be explained in detail based on Figure 6. In step S111, the alert acquisition unit 110 acquires the alert log 220.
[0032] For example, the alert acquisition unit 110 receives alert logs 220 from the security sensor 210 and extracts alert logs 220 that occurred during the target period from the received alert logs 220. The target period is the period (for example, a specified time zone) that has been designated as the subject of the analysis.
[0033] In step S112, the alert acquisition unit 110 divides the acquired alert log 220 for each user (entity) to obtain multiple alert logs 221 corresponding to multiple users. Alert log 221 is the user-specific alert log 220.
[0034] In step S113, the alert acquisition unit 110 acquires the relevant log 230.
[0035] For example, the alert acquisition unit 110 receives relevant logs 230 from the alert priority setting system 200 and extracts relevant logs 230 for the surrounding period from the received relevant logs 230. The peripheral period is a defined period (for example, a specified time zone) that includes the target period. The alert log 220 generated by analyzing the related logs 230 of the peripheral period is the alert log 220 for the target period.
[0036] In step S114, the alert acquisition unit 110 divides the acquired related log 230 for each user to obtain multiple related logs 231 corresponding to multiple users. Related log 231 is related log 231 for each user.
[0037] Returning to Figure 5, we will continue the explanation from step S120. In step S120, the alert analysis unit 120 calculates a score 121. A score of 121 is the score for the target alert log. A score of 121 is also called the alert frequency score. The target alert log is the alert log for the target user during the target time period. The target users are each of the users who are subject to the alert. The target time period is each individual time period that is to be analyzed. A time period is a fixed unit of time, for example, every 10 minutes.
[0038] Step S120 will be explained in detail based on Figure 7. In step S121, the alert frequency calculation unit 311 divides the user's alert log 221 by time period for each user to obtain multiple time-specific alert logs corresponding to multiple time periods. The time-based alert log is time-based alert log 221.
[0039] In step S122, the alert frequency calculation unit 311 counts the alert frequency for each time period for each user using the time-specific alert logs for each time period. The alert frequency is the number of alerts included in the alert log for each time period. Frequency information 314 is data showing the alert frequency for each time period for each user. Frequency information 315 is data showing the alert frequency for each user during the target time period.
[0040] In step S123, the alert statistics calculation unit 312 calculates alert statistics for past time periods for each user using the frequency information 314 for past time periods. Past time zones refer to time periods prior to the target time zone. Alert statistics are values that represent the statistics of alert frequency. For example, alert statistics include the mean, standard deviation, and quartile of alert frequency. Statistical information 316 is data showing alert statistics for past time periods for each user.
[0041] In step S124, the outlier calculation unit 313 calculates a score 121 for each user using frequency information 315 and statistical information 316.
[0042] Specifically, the outlier calculation unit 313 determines whether the alert frequency for the target time period corresponds to an outlier in the alert statistics for past time periods, and sets a score 121 according to the determination result. An outlier is an alert frequency that falls outside the range (statistical range) defined by the alert statistics.
[0043] A score of 121 is calculated as follows: Assume that the mean and standard deviation of alert frequency have been calculated as alert statistics. [u] represents the user. [t] represents a time period. A_cnt[u][t] represents the alert frequency for the target time period. A_mean[u] represents the average alert frequency over past time periods. A_std[u] represents the standard deviation of alert frequency over past time periods. A_score[u][t] represents a score of 121.
[0044] First, the outlier calculation unit 313 defines a statistical range. For example, the statistical range [A_mean[u]-3×A_std[u],A_mean[u]+3×A_std[u]] is defined. Next, the outlier calculation unit 313 determines whether A_cnt[u][t] is outside the statistical range. Then, if A_cnt[u][t] is outside the statistical range, the outlier calculation unit 313 sets a high value (for example, 1) as A_score[u][t]. Furthermore, if A_cnt[u][t] is within the statistical range, the outlier calculation unit 313 sets a low value (for example, 0) as A_score[u][t].
[0045] Multiple statistical ranges may be defined, and A_score[u][t] may be set according to the relationship between A_cnt[u][t] and the multiple statistical ranges. The outlier calculation unit 313 defines, for example, a first statistical range, a second statistical range, and a third statistical range. The first statistical range is the range represented by [A_mean[u]-1×A_std[u],A_mean[u]+1×A_std[u]]. The second statistical range is the range represented by [A_mean[u]-2×A_std[u],A_mean[u]+2×A_std[u]]. The third statistical range is the range represented by [A_mean[u]-3×A_std[u],A_mean[u]+3×A_std[u]]. If A_cnt[u][t] is within the first statistical range, the outlier calculation unit 313 sets A_score[u][t] to "0". If A_cnt[u][t] is not outside the first statistical range but is within the second statistical range, the outlier calculation unit 313 sets A_score[u][t] to "0.5". If A_cnt[u][t] is not in the second statistical range but is in the third statistical range, the outlier calculation unit 313 sets A_score[u][t] to "0.7". If A_cnt[u][t] is not within the third statistical range, the outlier calculation unit 313 sets A_score[u][t] to "1.0".
[0046] Returning to Figure 5, we will continue the explanation from step S130. In step S130, the priority calculation unit 130 calculates the priority 131 using the score 121. Priority 131 is the priority for the alert log.
[0047] For example, the priority calculation unit 130 sets the score 121 as the priority 131.
[0048] In step S140, the alert output unit 140 outputs a priority log 141. Prioritized log 141 is an alert log with priority 131 assigned to it.
[0049] For example, the alert output unit 140 displays the priority log 141 on the display.
[0050] ***Effects of Embodiment 1*** Embodiment 1 aims to automatically prioritize alerts from an attack detection system without pre-defining detailed rules.
[0051] Traditionally, there has been a challenge in automatically prioritizing alerts that do not contain explicit information related to priority, without having to prepare detailed rules for prioritization in advance. The alert priority setting device 100 prioritizes alerts based on the frequency trends of alert occurrences for each user. This allows for automatic priority setting of alerts without the need to prepare detailed rules in advance.
[0052] ***Supplement to Embodiment 1*** If there are different types of alerts, the alert frequency calculation unit 311 may perform a count for each type of alert.
[0053] The alert statistics calculation unit 312 operates to pre-calculate statistical information regarding alert logs and related logs from information over a certain period in the past. When monitoring is performed in real time, statistical information calculated by the alert statistics calculation unit 312 is referenced. Instead of calculating the mean or standard deviation of alert frequencies, machine learning can be used to learn a time series of normal alert frequencies. For example, algorithms such as One-Class SVM can be used. In this case, the alert statistics would store a normal model learned for each user, rather than the mean and standard deviation.
[0054] When machine learning is used, a normal model that has been trained and created for each entity is utilized. The outlier detection unit 313 calculates the degree of anomaly (degree of deviation from the normal model) for the frequency information of the target alert and determines whether it is an outlier based on whether it exceeds a predetermined threshold.
[0055] Embodiment 2. Regarding the method for calculating a score different from the score 121 of Embodiment 1, the main differences from Embodiment 1 will be explained based on Figures 8 to 12.
[0056] ***Explanation of the structure*** The configuration of the alert priority setting system 200 and the alert priority setting device 100 are the same as those in Embodiment 1. However, the configuration of the alert analysis unit 120 of the alert priority setting device 100 differs from the configuration in Embodiment 1.
[0057] Figure 8 shows the functional configuration of the alert priority setting device 100. Score 122 is the score in Embodiment 2.
[0058] Based on Figure 9, the configuration of the alert analysis unit 120 will be explained. The alert analysis unit 120 includes a relationship analysis unit 320. The relationship analysis unit 320 includes a word frequency calculation unit 321 and a relationship calculation unit 322. Word information 323 will be discussed later.
[0059] ***Explanation of operation*** Based on Figure 10, we will explain how to set alert priorities. Steps S110, S130, and S140 are as described in Embodiment 1.
[0060] In step S200, the alert analysis unit 120 calculates a score of 122. A score of 122 is the score for the target alert log. A score of 122 is also called the user word score.
[0061] Step S200 will be explained in detail based on Figure 11. In step S210, the word frequency calculation unit 321 divides the user's alert log 221 by time period for each user to obtain multiple time-specific alert logs corresponding to multiple time periods. Step S210 is the same as step S121 in Embodiment 1.
[0062] In step S220, the word frequency calculation unit 321 calculates alert word information for each time period for each user using the time-specific alert logs for each time period. At this time, the word frequency calculation unit 321 counts the word frequency for each word included in the time-based alert log. Word frequency is the number of times a word appears in the alert log for each time period. Alert word information is data that shows the word frequency for each word included in the alert log for each time period.
[0063] In step S230, the word frequency calculation unit 321 divides the user's related log 231 by time period for each user to obtain multiple time-specific related logs corresponding to multiple time periods. Step S230 is the same as step S121 in Embodiment 1.
[0064] The time period for related logs by time period is the time period that includes the time period covered by the alert log (the time period for which action is taken). If the target time period is represented as [t_min[A[u][t], t_max[A[u][t]]], the corresponding time period is represented, for example, as [t_min[A[u][t]]-α, t_max[A[u][t]]+β]. "α" and "β" are predetermined (for example, 24 hours).
[0065] In step S240, the word frequency calculation unit 321 calculates related word information for each time period for each user using the related logs for each time period. At this time, the word frequency calculation unit 321 counts the word frequency for each word included in the time-based related logs. Related word information is data showing the word frequency for each word included in the related logs for each time period.
[0066] Word information 323 is data that shows alert word information and related word information for each time period for each user.
[0067] In step S250, the relationship calculation unit 322 calculates a score 122 for each alert log 221 using the word information 323.
[0068] At this time, the relationship calculation unit 322 calculates the uniqueness between users as a score 122. User-to-user uniqueness is a value that indicates the degree of uniqueness of a target user's alert log relative to the alert logs of other users. Other users are each user who is not the target user.
[0069] Step S250 will be described in detail based on Figure 12. In step S251, the relationship calculation unit 322 calculates the user-to-user alert DF value.
[0070] At this time, the relationship calculation unit 322 counts the pairs of time zones and other users corresponding to the time zone alert logs containing the word indicated in the alert word information for the target time zone of the target user, using the alert word information for each corresponding time zone of other users. The counted value is the user-to-user alert DF value.
[0071] In step S252, the relationship calculation unit 322 calculates the user-to-user alert TF·IDF value.
[0072] The user-to-user alert TF·IDF value is calculated by performing the following formula: "w" represents each word shown in the alert word information. A_inter_TF·IDF[u][t][w] represents the inter-user alert TF·IDF value. WA_cnt[u][t][w] represents the word frequency of word w shown in the alert word information. A_inter_DF[u][t][w] represents the inter-user alert DF value.
[0073] A_inter_TF·IDF[u][t][w]= WA_cnt[u][t][w] / A_inter_DF[u][t][w]
[0074] If the word "w" appears frequently in the target user's alert log, the numerator will have a large value. If the word "w" is also included in other users' alert logs, the denominator will be a large value. Consequently, the more unique the word w is to the target user's alert log, the larger the value of A_inter_TF·IDF[u][t][w] will be. Conversely, the less unique the word w is to the target user's alert log, the smaller the value of A_inter_TF·IDF[u][t][w] will be.
[0075] In step S253, the relationship calculation unit 322 calculates the inter-user relationship DF value.
[0076] At this time, the relationship calculation unit 322, for each word shown in the related word information for the target user's target time period, uses the related word information for each corresponding time period of other users to count the pairs of time periods and other users that contain that word in the time period-specific related logs. The counted value is the user-related DF value.
[0077] In step S254, the relationship calculation unit 322 calculates the user-related TF·IDF value.
[0078] The inter-user related TF·IDF value is calculated by performing the following formula: "w" represents each word shown in the related word information. L_inter_TF·IDF[u][t][w] represents the inter-user related TF·IDF value. WL_cnt[u][t][w] represents the word frequency of word w shown in the related word information. L_inter_DF[u][t][w] represents the inter-user relationship DF value.
[0079] L_inter_TF·IDF[u][t][w]= WL_cnt[u][t][w] / L_inter_DF[u][t][w]
[0080] In step S255, the relationship calculation unit 322 calculates user uniqueness using the user-to-user alert TF·IDF value and the user-to-user relationship TF·IDF value.
[0081] User-to-user uniqueness can be calculated, for example, as follows: The relationship calculation unit 322 determines whether the first condition is met using the user-to-user alert TF / IDF value, and whether the second condition is met using the user-to-user relationship TF / IDF value. If either the first or second condition is met, the relationship calculation unit 322 sets the uniqueness between users to "1.0". If neither the first nor the second condition is met, the relationship calculation unit 322 sets the uniqueness between users to "0.0". The first condition is that in A_Inter_TF·IDF[u][t][w], there are at least two words w that exceed a specified threshold (θ1) and one that exceed a specified threshold (θ2). The second condition is that in L_Inter_TF·IDF[u][t][w], there are at least two words w that exceed a specified threshold (θ3) in a specified threshold (θ4). However, the method for calculating uniqueness among users is not limited to this method.
[0082] ***Effects of Embodiment 2*** Embodiment 2 aims to suppress alerts (false alerts) that occur simultaneously due to the normal updating of applications or operating systems that are systematically deployed within an organization.
[0083] The alert priority setting device 100 prioritizes alerts based on the relationships between users. This makes it possible to suppress the need to respond to multiple simultaneous alerts caused by normal application updates or other events implemented systematically within the organization.
[0084] ***Supplement to Embodiment 2*** After some time has passed, other users may trigger similar alerts. Therefore, when calculating DF values (A_inter_DF[u][t][w], L_inter_DF[u][t][w]) from the word information of other users' alerts, the relationship calculation unit 322 may wait for a certain period (Δ) and calculate the DF values for the period t to t+Δ.
[0085] Embodiment 3. Regarding the method for calculating a score different from the score 121 of Embodiment 1, the main differences from Embodiment 1 will be explained based on Figures 13 to 16.
[0086] ***Explanation of the structure*** The configuration of the alert priority setting system 200 and the alert priority setting device 100 are the same as those in Embodiment 1. However, the configuration of the alert analysis unit 120 of the alert priority setting device 100 differs from the configuration in Embodiment 1.
[0087] Figure 13 shows the functional configuration of the alert priority setting device 100. Score 123 is the score in Embodiment 3.
[0088] Based on Figure 14, the configuration of the alert analysis unit 120 will be explained. The alert analysis unit 120 includes an information utilization unit 330. The information utilization unit 330 includes a matching unit 331. Threat intelligence DB332 is a database where threat intelligence is registered.
[0089] Threat intelligence is information that identifies known attacks. For example, threat information includes URLs, domains, IP addresses, and filenames. URL is an abbreviation for Uniform Resource Locator.
[0090] ***Explanation of operation*** Based on Figure 15, we will explain how to set alert priorities. Steps S110, S130, and S140 are as described in Embodiment 1.
[0091] In step S300, the alert analysis unit 120 calculates a score of 123. A score of 123 is the score for the target alert log. A score of 123 is also called the threat intelligence score.
[0092] Step S300 will be explained in detail based on Figure 16. In step S310, the matching unit 331 divides the user's alert log 221 by time period for each user and obtains multiple time-specific alert logs corresponding to multiple time periods. Step S310 is the same as step S121 in Embodiment 1.
[0093] In step S320, the matching unit 331 divides the user's related logs 231 by time period for each user and obtains multiple time-period related logs corresponding to multiple time periods. Step S320 is the same as step S230 in the second embodiment.
[0094] In step S330, the matching unit 331 calculates a score 123 for each user using the time-specific alert logs, time-specific related logs, and threat information for each time period.
[0095] A score of 123 is calculated as follows: First, the matching unit 331 checks whether threat information is included in the target alert log and the response-related logs. Then, the matching unit 331 calculates a score 123 based on the verification results. For example, if the target alert log and the response-related logs contain threat information, the matching unit 331 sets the score 123 to "1.0". Furthermore, if the target alert log and the related response logs do not contain threat information, the matching unit 331 sets the score 123 to "0.0".
[0096] ***Effects of Embodiment 3*** Embodiment 3 aims to enable early response to alerts that are clearly identifiable as known attacks.
[0097] The alert priority setting device 100 prioritizes alerts by utilizing external intelligence, such as threat information. This enables immediate response to alerts related to known attacks.
[0098] ***Supplement to Embodiment 3*** If the threat information already includes risk values, the matching unit 331 assigns a score of 123 to that information. If multiple threat intelligences are included, the matching unit 331 merges the corresponding scores. For example, the matching unit 331 calculates the maximum or average of the multiple scores.
[0099] Embodiment 4. Regarding the method for calculating a score different from the score 121 of Embodiment 1, the main differences from Embodiment 1 will be explained based on Figures 17 to 20.
[0100] ***Explanation of the structure*** The configuration of the alert priority setting system 200 and the alert priority setting device 100 are the same as those in Embodiment 1. However, the configuration of the alert analysis unit 120 of the alert priority setting device 100 differs from the configuration in Embodiment 1.
[0101] Figure 17 shows the functional configuration of the alert priority setting device 100. Score 124 is the score in Embodiment 4.
[0102] Based on Figure 18, the configuration of the alert analysis unit 120 will be explained. The alert analysis unit 120 includes an aggregation unit 340. The aggregation unit 340 includes a merge unit 341. The aggregation rule DB342 is the database where aggregation rules are registered.
[0103] Aggregation rules specify the conditions for aggregating alert logs and related logs. For example, if the alert log is a collection of alerts related to web access logs, the aggregation rule would have the following conditions: • They share the same destination domain or destination IP address. • They share the same source IP address. • The accessed URL contains the same file extension. • The same referrer is attached. This alert was blocked on the proxy side. This is an alert that was flagged as suspicious by the proxy's reputation system.
[0104] ***Explanation of operation*** Based on Figure 19, we will explain how to set alert priorities. Steps S110, S130, and S140 are as described in Embodiment 1.
[0105] In step S400, the alert analysis unit 120 calculates a score of 124. A score of 124 is the score for the target alert log. This score is also called the aggregate score.
[0106] Step S400 will be explained in detail based on Figure 20. In step S410, the merge unit 341 divides the user's alert log 221 by time period for each user to obtain multiple time-specific alert logs corresponding to multiple time periods. Step S410 is the same as step S121 in Embodiment 1.
[0107] In step S420, the merge unit 341 divides the user's related logs 231 by time period for each user to obtain multiple time-period related logs corresponding to multiple time periods. Step S420 is the same as step S230 in Embodiment 2.
[0108] In step S430, the merge unit 341 aggregates the time-specific alert logs and time-specific related logs for each time period using aggregation rules. Aggregation may be performed for all users or for each user. This will yield multiple log sets. A log set consists of a collection of aggregated time-based alert logs and a collection of aggregated time-based related logs.
[0109] In step S440, the merge unit 341 calculates a score 124 based on the aggregation results. If aggregation is performed for each user, the score 124 is calculated for each user.
[0110] At this time, the merge unit 341 calculates a score 124 using the number of time-specific alert logs belonging to the log set to which the time-specific alert logs for the target time period belong.
[0111] A score of 124 can be calculated, for example, by performing the following calculation: "score" represents a score of 124. "G1" represents the log set to which the time-specific alert logs for the target user belong. "Gi" represents each log set. For example, if we aggregate logs based on the condition that they "have the same destination domain," then "G1" represents the set of logs accessing destination domain A, "G2" represents the set of logs accessing destination domain B, and "G3" represents the set of logs accessing destination domain C (G4-GN are similar). |G1| is the number of time-based alert logs belonging to log set G1. |Gi| is the number of time-based alert logs belonging to the log set Gi. Σ|Gi| is the total number of time-based alert logs belonging to each log set Gi.
[0112] score = |G1| / Σ|Gi|
[0113] If there are multiple log sets to which the time-specific alert logs for the target user belong (for example, G1 and G2), a score of 124 will be displayed for each log set to which the time-specific alert logs for the target user belong.
[0114] ***Effects of Embodiment 4*** Embodiment 4 aims to enable a simultaneous response to multiple similar alerts when they occur.
[0115] The alert priority setting device 100 merges similar alerts and assigns a priority to the merged alerts according to their size. This makes it possible to respond to multiple similar alerts preferentially and efficiently.
[0116] Embodiment 5. Regarding the method for calculating a score different from the score 121 of Embodiment 1, the main differences from Embodiment 1 will be explained based on Figures 21 to 25.
[0117] ***Explanation of the structure*** Based on Figure 21, the configuration of the alert priority setting system 200 will be explained. The alert priority setting system 200 is further equipped with a security sensor 240. Security sensor 240 is a separate attack detection system from security sensor 210. Alert log 250 is an alert log obtained from security sensor 240. Related log 260 is a related log obtained from security sensor 240. In other words, related log 260 is an alert-related log for alert log 250.
[0118] The configuration of the alert priority setting device 100 is the same as the configuration in Embodiment 1. However, the configuration of the alert analysis unit 120 differs from that in Embodiment 1.
[0119] Figure 22 shows the functional configuration of the alert priority setting device 100. Score 125 is the score in Embodiment 5.
[0120] Based on Figure 23, the configuration of the alert analysis unit 120 will be explained. The alert analysis unit 120 is equipped with an information utilization unit 350. The information utilization unit 350 includes a word frequency calculation unit 351 and a matching unit 352. Other Sensor Alert DB359 is the database in which Other Sensor Alert Log 358 is registered. Other sensor alert log 358 is a user-specific alert log 250. Similar to alert log 221, other sensor alert log 358 is obtained by splitting alert log 250 by user.
[0121] ***Explanation of operation*** Based on Figure 24, we will explain how to set alert priorities. Steps S110, S130, and S140 are as described in Embodiment 1.
[0122] In step S500, the alert analysis unit 120 calculates a score of 125. A score of 125 is the score for the target alert log. A score of 125 is also called the sensor word score.
[0123] Step S500 will be explained in detail based on Figure 25. In step S510, the word frequency calculation unit 351 calculates alert word information for each time period for each user. Step S510 is the same as steps S210 and S220 in Embodiment 2.
[0124] In step S520, the word frequency calculation unit 351 calculates related word information for each time period for each user. Step S520 is the same as steps S230 and S240 in Embodiment 2.
[0125] Word information 353 is data that shows alert word information and related word information for each time period for each user.
[0126] In step S530, the word frequency calculation unit 351 calculates the word information from other sensors for each time period for each user. Other sensor word information is alert word information calculated using alert logs for each time period obtained by dividing the other sensor alert log 358. Step S530 is the same as steps S210 and S220 in Embodiment 2.
[0127] Word information 354 is data showing word information from other sensors for each time period for each user.
[0128] In step S540, the matching unit 352 calculates a score of 125 using word information 353 and word information 354.
[0129] A score of 125 is calculated as follows: First, the matching unit 352 extracts high-frequency words from the word information 353. High-frequency words are words whose frequency is greater than the extraction threshold. The extraction threshold is set in advance. Furthermore, the matching unit 352 extracts frequently occurring words from the word information 354. The matching unit 352 then sets a score of 125 based on the high-frequency words (target words) extracted from the word information 353 and the high-frequency words (comparison words) extracted from the word information 354. For example, if the number of target words that match any of the comparison words (match count) is greater than the setting threshold, the word frequency calculation unit 351 sets the score 125 to "1.0". The setting threshold is set in advance. Furthermore, if the number of matches is below the setting threshold, the word frequency calculation unit 351 sets the score 125 to "0.0". However, the method for calculating a score of 125 is not limited to this method.
[0130] ***Effects of Embodiment 5*** Embodiment 5 aims to enable immediate response to alerts occurring at the same time as other security sensors have issued alerts.
[0131] The alert priority setting device 100 matches the timing of alerts issued by other security sensors with the timing of the alert being analyzed. This makes it possible to identify alerts related to more reliable signs of an incident.
[0132] Embodiment 6. Regarding the method for calculating a score different from the score 121 of Embodiment 1, the main differences from Embodiment 1 will be explained based on Figures 26 to 29.
[0133] ***Explanation of the structure*** The configuration of the alert priority setting system 200 and the alert priority setting device 100 are the same as those in Embodiment 1. However, the configuration of the alert analysis unit 120 of the alert priority setting device 100 differs from the configuration in Embodiment 1.
[0134] Figure 26 shows the functional configuration of the alert priority setting device 100. Score 126 is the score in Embodiment 6.
[0135] Based on Figure 27, the configuration of the alert analysis unit 120 will be explained. The alert analysis unit 120 includes an event analysis unit 360. The event analysis unit 360 includes a search unit 361. Attack indicator rules DB362 is a database where attack indicator rules are registered.
[0136] Attack indicator rules specify the conditions for logs that indicate signs of an attack. For example, attack indicator rules specify conditions related to the following behaviors that may be associated with an attack: • Program download • Execution of the program • Service registration • Startup registration • Posting (sending) data
[0137] ***Explanation of operation*** Based on Figure 28, we will explain how to set alert priorities. Steps S110, S130, and S140 are as described in Embodiment 1.
[0138] In step S600, the alert analysis unit 120 calculates a score of 126. A score of 126 is the score for the target alert log. A score of 126 is also called the attack indicator score.
[0139] Step S600 will be explained in detail based on Figure 29. In step S610, the search unit 361 divides the user's alert log 221 by time period for each user and obtains multiple time-specific alert logs corresponding to multiple time periods. Step S610 is the same as step S121 in Embodiment 1.
[0140] In step S620, the search unit 361 divides the user's related logs 231 by time period for each user and obtains multiple time-period related logs corresponding to multiple time periods. Step S620 is the same as step S230 in the second embodiment.
[0141] In step S630, the search unit 361 searches for information indicating signs of an attack for each user, using attack indicator rules, from the time-based alert logs and time-based related logs for each time period.
[0142] In step S640, the search unit 361 calculates a score 126 based on the search results.
[0143] A score of 126 can be calculated, for example, as follows: The search unit 361 compares the number of matching information X with thresholds θ1 and θ2. Thresholds θ1 and θ2 are set in advance. Threshold θ1 is greater than threshold θ2. If the number X is greater than the threshold θ1, the search unit 361 sets the score 126 to "1.0". If the number X is greater than threshold θ2 and less than or equal to threshold θ1, the search unit 361 sets the score 126 to "0.5". If the number X is less than or equal to the threshold θ2, the search unit 361 sets the score 126 to "0.0".
[0144] ***Effects of Embodiment 6*** Embodiment 6 aims to enable alerts that show signs of an attack before or after the event to be treated as highly reliable alerts.
[0145] The alert priority setting device 100 checks whether the alert logs before and after the alert being analyzed, as well as related logs, contain information related to signs of an attack. This makes it possible to identify alerts related to signs of an incident with a higher degree of certainty.
[0146] Embodiment 7. The differences in the visualization method between the target alert log and past alert logs, and the main differences from Embodiment 1, will be explained based on Figures 30 to 35.
[0147] ***Explanation of the structure*** The configuration of the alert priority setting system 200 is the same as the configuration in Embodiment 1. However, the configuration of the alert priority setting device 100 differs from the configuration in Embodiment 1.
[0148] Based on Figure 30, the configuration of the alert priority setting device 100 will be explained. The alert priority setting device 100 further includes elements such as a difference identification unit 151 and a visualization unit 152. The alert priority setting device 100 further utilizes a computer as a difference identification unit 151 and a visualization unit 152. False positive DB271 is a database that registers alert logs for attacks that were previously falsely detected, along with related logs corresponding to those alert logs. The Known Attack DB272 is a database that registers alert logs for attacks that were correctly detected in the past, along with related logs corresponding to those alert logs. Visualization result 153 will be discussed later.
[0149] ***Explanation of operation*** The operation of the difference identification unit 151 will be explained based on Figure 31. In step S711, the difference identification unit 151 selects an analysis log and extracts feature information from the analysis log.
[0150] Analysis logs consist of alert logs and related logs that are subject to visualization. For example, the difference identification unit 151 selects an alert log with a priority higher than a threshold and the related logs corresponding to that alert log as analysis logs.
[0151] For example, if the alert log concerns web access logs, the characteristic information would include URL, username, IP address, and file name. This characteristic information is predetermined for each log type. Characteristic information is used to identify similar action logs to the target log. Action logs will be discussed later.
[0152] In step S712, the difference identification unit 151 extracts characteristic information from each action log registered in the action alert DB.
[0153] The response alert database is a database containing alert logs that have been handled in the past, along with related logs corresponding to those alert logs. False positive DB271 and known attack DB272 correspond to the response alert DBs.
[0154] The extracted characteristic information is associated with the response log and registered in the response alert database. If characteristic information is registered, it will be retrieved from the response alert database.
[0155] In step S713, the difference identification unit 151 compares the characteristic information of each analysis log with the characteristic information of each corresponding log and extracts corresponding logs (similar logs) whose characteristic information is similar to that of the analysis log.
[0156] For example, the difference identification unit 151 uses the K Nearest Neighbor method to extract corresponding logs as similar logs that are close to the feature information of the feature information of the analysis log.
[0157] In step S714, the difference identification unit 151 performs training for the classifier using the feature information of the analysis log and the feature information of the similar log for each pair of analysis log and similar log.
[0158] The classifier is trained to classify the features of the analysis log from the features of similar logs. It is a pre-trained model for classifying the features of the two types of alert logs. An example of a classifier is a random forest. The classifier calculates the feature importance for each type of feature information. Note that because random forests involve randomness in the classifier training, the calculation of the classification contribution changes with each training run. Therefore, it is also possible to run the classifier training multiple times and use the average of the classification contributions calculated each time.
[0159] Then, the difference identification unit 151 uses the learned classifier to calculate the classification contribution for each type of feature information.
[0160] In step S715, the difference identification unit 151 calculates the difference between the feature information of the analysis log and the feature information of the similar log for feature information with a high classification contribution.
[0161] Feature information corresponding to a classification contribution higher than the threshold is considered to have a high classification contribution.
[0162] The difference in feature information is the difference in the actual values (or values converted to numerical values) included in the feature information. Since it is difficult to numerically compare strings such as IP addresses and usernames, these strings are converted into frequency information. The frequency of each string is collected by analyzing alert logs and related logs over a certain period in the past, and the probability of occurrence is calculated. For example, let's assume that there are 50 instances of the IP address (AAAA), 30 instances of the IP address (BBBB), and 20 instances of the IP address (CCCC). In this case, (AAAA) would be quantified as 50 / 100, (BBBB) as 30 / 100, and (CCCC) as 20 / 100.
[0163] Feature information with a high classification contribution can be interpreted as the feature information that had a significant impact in distinguishing between analysis logs and similar logs, and is the feature information with a large difference.
[0164] The operation of the visualization unit 152 will be explained. The visualization unit 152 visualizes the differences between the characteristic information of the analysis log and the characteristic information of similar logs on the dashboard.
[0165] For example, the visualization unit 152 generates a graph that shows the difference between the characteristic information of the analysis log and the characteristic information of similar logs, and displays the generated graph. For example, the visualization unit 152 displays graphs as shown in Figures 38 to 41.
[0166] Figure 32 shows an example of a bar graph of classification contribution. The vertical axis represents classification contribution, and the horizontal axis represents the type of feature information. This bar graph shows the classification contribution for each type of feature information, sorted in descending order of classification contribution.
[0167] Figure 33 shows an example of a pie chart of classification contribution. This pie chart shows the magnitude of the classification contribution for each type of feature information, sorted in descending order of classification contribution. In a pie chart, a larger area indicates a higher contribution to classification.
[0168] Figure 34 shows an example of a bar graph of classification contribution. This bar graph shows the characteristic information of the analysis log and the characteristic information of the similar logs respectively. The bar on the far left shows the value of the characteristic information of the analysis log. Each of the remaining bars shows the value of the characteristic information of the similar logs. In FIG. 34, the number of similar logs is five.
[0169] FIG. 35 shows an example of a scatter diagram of classification contribution degrees. This scatter diagram shows the relationship between two types of characteristic information of the analysis log and the similar logs in a two-dimensional plane. The black squares are the plotted values of the two types of characteristic information of the analysis log. The shaded squares are the plotted values of the two types of characteristic information of the similar logs respectively. In FIG. 35, the number of similar logs is five. The two types of characteristic information are selected in descending order of classification contribution degree.
[0170] However, the visualization method is not limited to these methods.
[0171] ***Effects of Embodiment 7*** Even if an alert with a high priority is known, there is no way to know whether the alert is a false detection or an attack. Embodiment 7 visualizes and presents the characteristic differences between false detection data and known attacks by comparing the target alert with past information similar to it. Thereby, it becomes possible to clearly present information for analyzing whether a high-priority alert is a false detection or an attack.
[0172] Embodiment 7 calculates the difference in characteristics when comparing a high-priority alert with alerts previously recognized as false detections and alerts previously recognized as attacks in the past, and visualizes and presents the difference. Thereby, it becomes possible to facilitate the analysis of alerts.
[0173] [[ID=Step S710 is performed for each type of response information for previously resolved alerts. The types of response information include, for example, "alerts determined to be false positives" and "alerts determined to be attacks" as a result of the analysis. For each of the "alerts determined to be false positives" and "alerts determined to be attacks," the differences between them and the characteristic information of the alert being analyzed are extracted and visualized.
[0174] When inputting feature information into a machine learning algorithm, special techniques are needed to process the feature information (categorical data) consisting of strings such as URLs and filenames. It is necessary to first count unique string information for each feature of the categorical data from prepared historical normal data, calculate the probability of occurrence based on that frequency information, and quantify it. This makes processing by the machine learning algorithm possible.
[0175] Embodiment 7 may be implemented in combination with embodiments other than Embodiment 1. In other words, the alert analysis unit 120 may calculate the score of another embodiment instead of the score 121 of Embodiment 1.
[0176] Embodiment 8. The method for calculating a score different from the score 121 of Embodiment 1 will be explained, mainly based on the differences from Embodiment 1, using Figures 36 to 40.
[0177] ***Explanation of the structure*** The configuration of the alert priority setting system 200 and the alert priority setting device 100 are the same as those in Embodiment 1. However, the configuration of the alert analysis unit 120 of the alert priority setting device 100 differs from the configuration in Embodiment 1.
[0178] Figure 36 shows the functional configuration of the alert priority setting device 100. Score 128 is the score in Embodiment 8.
[0179] Based on Figure 37, the configuration of the alert analysis unit 120 will be explained. The alert analysis unit 120 includes a relationship analysis unit 380. The relationship analysis unit 380 comprises a word frequency calculation unit 321, a relationship calculation unit 322, a word statistical analysis unit 381, a relationship calculation unit 382, and a score calculation unit 383. The word frequency calculation unit 321 and the relationship calculation unit 322 are the same elements as those described in Embodiment 2. Statistical information 384 will be discussed later.
[0180] ***Explanation of operation*** Based on Figure 38, we will explain how to set alert priorities. Steps S110, S130, and S140 are as described in Embodiment 1.
[0181] In step S800, the alert analysis unit 120 calculates a score of 128. A score of 128 is the score for the target alert log. A score of 128 is also called the user relationship score.
[0182] Step S800 will be explained in detail based on Figure 39. In step S810, the word frequency calculation unit 321 calculates alert word information and related word information for each time period for each user. Step S810 is the same as steps S210 to S240 in Embodiment 2.
[0183] In step S820, the relationship calculation unit 322 calculates the uniqueness between users for each user. Step S820 is the same as step S250 in the second embodiment.
[0184] In step S830, the word statistics analysis unit 381 calculates alert word statistics and related word statistics for each user using the word information 323. Statistical information 384 consists of alert word statistics and related word statistics.
[0185] At this time, the word statistical analysis unit 381 counts the number of time zones of the alert logs containing the word for each word shown in the alert word information. The alert word statistical information indicates the number of time zones of the alert logs containing the word for each word shown in the alert word information.
[0186] Also, the word statistical analysis unit 381 counts the number of time zones of the related logs containing the word for each word shown in the related word information. The related word statistical information indicates the number of time zones of the related logs containing the word for each word shown in the related word information.
[0187] In step S840, the relationship calculation unit 382 calculates the within-user uniqueness for each user using the word information 323 and the statistical information 384.
[0188] Based on FIG. 40, the details of step S840 will be described. In step S841, the relationship calculation unit 382 calculates the within-user alert TF·IDF value.
[0189] The within-user alert TF·IDF value is calculated by calculating the following formula. "u" represents the target user. "t" represents the target time zone. "w" represents each word shown in the alert word information. A_inner_TF·IDF[u][t][w] represents the within-user alert TF·IDF value. WA_cnt[u][t][w] represents the word frequency. A_inner_DF[u][w] is the within-user alert DF value, which is the statistical information of the past time zones of the target user, and the statistical information is analyzed and stored in advance as follows. For each word shown in the alert word information of the target time zone of the target user, using the alert word information of a plurality of time zones in a certain period in the past of the same user, the number of time zones corresponding to the alert logs by time zone containing the word is counted. For a word w shown in the alert word information for the target user u within the target time period, the number of time periods in the past time-based alert logs for the same user that contain that word is A_inner_DF[u][w].
[0190] A_inner_TF·IDF[u][t][w]= WA_cnt[u][t][w] / A_inner_DF[u][w]
[0191] If the word "w" appears frequently in the target user's alert log, the numerator will have a large value. If the word "w" is also included in the target user's past alert logs, the denominator will be a large value. Consequently, the more unique the word w is to the target user's current alert log, the larger the value of A_inner_TF·IDF[u][t][w] will be. Conversely, the less unique the word w is to the target user's current alert log, the smaller the value of A_inner_TF·IDF[u][t][w] will be.
[0192] In step S842, the relationship calculation unit 382 calculates the user-related TF·IDF value.
[0193] The user-related TF·IDF value is calculated by performing the following formula: "w" represents each word shown in the related word information. L_inner_TF·IDF[u][t][w] represents the user-related TF·IDF value. WL_cnt[u][t][w] represents word frequency. L_inner_DF[u][w] is an internal user-related DF value, which is statistical information about the target user over past time periods. The statistical information is analyzed and stored in advance as follows. For each word shown in the related word information for the target user's time period, the number of time periods corresponding to the related logs containing that word is counted, using related word information for multiple time periods over a certain past period for the same user. For a word w shown in the related word information for the target user u within the target time period, the number of time periods in the past related logs for the same user that contain that word is L_inner_DF[u][w].
[0194] L_inner_TF·IDF[u][t][w]= WL_cnt[u][t][w] / L_inner_DF[u][w]
[0195] In step S843, the relationship calculation unit 382 calculates the uniqueness within the user using the user-internal alert TF·IDF value and the user-internal relationship TF·IDF value.
[0196] Uniqueness within a user can be calculated, for example, as follows: The relationship calculation unit 382 determines whether the first condition is met using the user's internal alert TF / IDF value, and determines whether the second condition is met using the user's internal relationship TF / IDF value. If either the first or second condition is met, the relationship calculation unit 382 sets the user-specific uniqueness to "1.0". If neither the first nor the second condition is met, the relationship calculation unit 382 sets the user-specific uniqueness to "0.0". The first condition is that in A_Inner_TF·IDF[u][t][w], there are at least two words w that exceed a specified threshold (θ1) and one that exceed a specified threshold (θ2). The second condition is that in L_Inner_TF·IDF[u][t][w], there are at least two words w that exceed a specified threshold (θ3) and a specified threshold (θ4). However, the method for calculating user uniqueness is not limited to this method.
[0197] Returning to Figure 39, step S850 will be explained. In step S850, the score calculation unit 383 calculates a score 128 using inter-user uniqueness and intra-user uniqueness.
[0198] A score of 128 can be calculated, for example, as follows: (1) If both the uniqueness between users and the uniqueness within a user are "1.0", the score calculation unit 383 sets the score 128 to "1.0". The alert in question is a new alert that the user has never received before. No similar alerts exist for other users during the relevant time period. (2) If the uniqueness between users is "1.0" and the uniqueness within a user is "0", the score calculation unit 383 sets the score 128 to "0.5". The alert in question is one that the user has received in the past. No similar alerts exist for other users during the same time period. This alert can be considered a false positive, indicating that the user is exhibiting unusual behavior, such as performing specialized tasks. (3) If the uniqueness between users is "0" and the uniqueness within a user is "1.0", the score calculation unit 383 sets the score 128 to "0.5". The alert in question is a new alert for that user. Similar alerts exist for other users during the same time period. Furthermore, the alert in question could be considered a false positive, for example, due to a change in the user's attributes, such as a change in workplace. (4) If both inter-user uniqueness and intra-user uniqueness are "0", the score calculation unit 383 sets the score 128 to "0". The alert in question is one that the user has received before. Similar alerts also appear for other users during the same time period. Furthermore, the alert in question is a fairly common alert overall (a false positive). However, the method for calculating and interpreting a score of 128 is not limited to this method.
[0199] ***Effects of Embodiment 8*** In Embodiment 2, alerts may be given higher priority for the behavior of users who regularly perform specialized tasks. In Embodiment 8, alerts are prioritized based on the relationships between alerts within the user. This makes it possible to reduce the priority of false alerts for users who habitually exhibit unusual behavior.
[0200] ***Supplement to Embodiment 8*** The word statistics analysis unit 381 is executed to pre-calculate statistical information regarding alert logs and related logs from information over a certain period in the past. When monitoring in real time, statistical information calculated by the alert analysis unit 120 is referenced.
[0201] Embodiment 9. Regarding the calculation of a score different from the score 121 of Embodiment 1, the main differences from Embodiment 1 will be explained based on Figures 41 to 45.
[0202] ***Explanation of the structure*** The configuration of the alert priority setting system 200 and the alert priority setting device 100 are the same as those in Embodiment 1. However, the configuration of the alert analysis unit 120 of the alert priority setting device 100 differs from the configuration in Embodiment 1.
[0203] Figure 41 shows the functional configuration of the alert priority setting device 100. Score 129 is the score in Embodiment 9.
[0204] Based on Figure 42, the configuration of the alert analysis unit 120 will be explained. The alert analysis unit 120 includes a relationship analysis unit 390. The relationship analysis unit 390 includes a word frequency calculation unit 321, a relationship calculation unit 322, a word statistical analysis unit 381, a relationship calculation unit 382, a relationship calculation unit 391, and a score calculation unit 392. The word frequency calculation unit 321 and the relationship calculation unit 322 are the same elements as those described in Embodiment 2. The word statistics analysis unit 381 and the relationship calculation unit 382 are the same elements as those described in Embodiment 8.
[0205] ***Explanation of operation*** Based on Figure 43, we will explain how to set alert priorities. Steps S110, S130, and S140 are as described in Embodiment 1.
[0206] In step S900, the alert analysis unit 120 calculates a score of 129. A score of 129 is the score for the target alert log. A score of 129 is also called the historical relationship score.
[0207] Step S900 will be explained in detail based on Figure 44. Steps S810 to S840 are as described in Embodiment 8.
[0208] In step S910, the relationship calculation unit 391 calculates the past uniqueness for each user using word information 323 and statistical information 384.
[0209] Step S910 will be described in detail based on Figure 45. In step S911, the relationship calculation unit 391 calculates the past user-to-user alert TF·IDF value.
[0210] The past user-to-user alert TF·IDF values are calculated as follows: First, the relationship calculation unit 391 calculates the past alert DF value as follows: For each word shown in the alert word information for the target user's target time period, the system uses alert word information for multiple time periods from other users over a certain past period to count the number of pairs of time periods and other users that contain that word in the time period alert log. The counted value is the past alert DF value.
[0211] Then, the relationship calculation unit 391 calculates past user-to-user alert TF·IDF values using the calculated past alert DF values. The past user-to-user alert TF·IDF value is calculated by performing the following formula: A_inter_prev_TF·IDF[u][t][w] represents the past inter-user alert TF·IDF value. A_inter_DF_PREV[u][w] represents past alert DF values.
[0212] A_inter_prev_TF·IDF[u][t][w]= WA_cnt[u][t][w] / A_inter_DF_PREV[u][w]
[0213] If the word "w" appears frequently in the target user's alert log, the numerator will have a large value. If the word "w" is also included in other users' past alert logs, the denominator will be a large value. Consequently, the more unique the word w is in the target user's alert log compared to other users' past alert logs, the larger the value of A_inter_prev_TF·IDF[u][t][w] will be. Conversely, the less unique the word w is in the target user's alert log compared to other users' past alert logs, the smaller the value of A_inter_prev_TF·IDF[u][t][w] will be.
[0214] In step S912, the relationship calculation unit 391 calculates past user-related TF·IDF values.
[0215] The historical inter-user related TF / IDF values are calculated as follows: First, the relationship calculation unit 391 calculates the past user relationship DF value as follows: For each word shown in the related word information for the target user's time period, the system uses related word information for multiple time periods from other users over a certain past period to count the pairs of time periods and other users that contain that word in the time-period related logs. The counted value is the past inter-user related DF value.
[0216] Then, the relationship calculation unit 391 calculates the past user relationship TF·IDF value using the calculated past user relationship DF value. The historical inter-user relationship TF·IDF value is calculated by applying the following formula. L_inter_prev_TF·IDF[u][t][w] represents past inter-user TF·IDF values. L_inter_DF_PREV[u][w] represents past inter-user relationship DF values.
[0217] L_inter_prev_TF·IDF[u][t][w]= WL_cnt[u][t][w] / L_inter_DF_PREV[u][w]
[0218] In step S913, the relationship calculation unit 391 calculates past uniqueness using past inter-user alert TF·IDF values and past inter-user relationship TF·IDF values.
[0219] Historical uniqueness can be calculated, for example, as follows: The relationship calculation unit 391 determines whether the first condition is met using past inter-user alert TF / IDF values, and determines whether the second condition is met using past inter-user relationship TF / IDF values. If either the first or second condition is met, the relationship calculation unit 391 sets the past uniqueness to "1.0". If neither the first nor the second condition is met, the relationship calculation unit 391 sets the past uniqueness to "0.0". The first condition is that in A_Inner_prev_TF·IDF[u][t][w], there are at least two words w that exceed a specified threshold (θ1) (θ2). The second condition is that in L_Inner_prev_TF·IDF[u][t][w], there are at least two words w that exceed a specified threshold (θ3) (θ4). However, the method for calculating historical uniqueness is not limited to this method.
[0220] Returning to Figure 44, step S920 will be explained. In step S920, the score calculation unit 392 calculates a score 129 using inter-user uniqueness, intra-user uniqueness, and past uniqueness.
[0221] A score of 129 can be calculated, for example, as follows: (1) If the uniqueness between users, the uniqueness within a user, and the uniqueness in the past are all "1.0", the score calculation unit 392 sets the score 129 to "1.0". (2) If the uniqueness between users and the uniqueness within a user are "1.0" and the past uniqueness is "0", the relationship calculation unit 391 sets the score 129 to a value in the range of "0.75 to 1.0". It is possible that an attack that occurred against other users in the past has now occurred only against the target user. (3) If the uniqueness between users and the uniqueness in the past are "1.0" and the uniqueness within a user is "0", the relationship calculation unit 391 sets the score 129 to "0.5". This indicates that a normal operation may have occurred for a user who has been performing special tasks in the past. (4) If the inter-user uniqueness is "1.0" and the intra-user uniqueness and past uniqueness are "0", the relationship calculation unit 391 sets the score 129 to "0.5". This may indicate that a person who previously performed a special task as part of a team but has recently started performing the same task alone is performing the task correctly. (5) If the uniqueness between users is "0" and the uniqueness within a user and the uniqueness in the past are "1.0", the score calculation unit 392 sets the score 129 to a value in the range of "0.5 to 0.75". There is a suspicion that a large-scale infection has occurred by a type of malware that has not occurred before. (6) If the uniqueness between users and the past uniqueness are "0" and the uniqueness within a user is "1.0", the score calculation unit 392 sets the score 129 to "0.5". This may indicate that an OS or application update has occurred for the new user. (7) If the uniqueness between users and the uniqueness within a user are "0" and the uniqueness in the past is "1.0", the score calculation unit 392 sets the score of 129 to "0.2". It is possible that the entire organization has recently started doing a task that the user used to do in the past. (8) If user-to-user uniqueness, user-to-user uniqueness, and past uniqueness are all "0", the score calculation unit 392 sets the score 129 to "0". The alert in question is not a new alert. However, the method for calculating a score of 129 is not limited to this method. Nor is the interpretation of a score of 129 limited.
[0222] ***Effects of Embodiment 9*** In Embodiment 2 or Embodiment 8, alerts related to incidents caused by malware spreading simultaneously may be given a lower priority. Such alerts are suppressed along with alerts that occur simultaneously due to, for example, updates to legitimate applications deployed systematically within the organization. In Embodiment 9, the relationship with past alerts from other users is added as a consideration. This makes it possible to isolate alerts related to malware incidents that are spreading simultaneously in multiple locations.
[0223] Embodiment 10. Embodiments 1 to 9 can be implemented in combination with each other. The alert analysis unit 120 may include two or more elements from among the following: outlier analysis unit 310, relationship analysis unit 320, information utilization unit 330, aggregation unit 340, information utilization unit 350, event analysis unit 360, relationship analysis unit 380, and relationship analysis unit 390. In this case, two or more scores (121-126, 128, 129) will be calculated.
[0224] If more than one score is calculated, the scores will be merged. For example, merging can calculate the sum, product, maximum value, minimum value, average, or weighted average of two or more scores as the resulting score. Then, priority is calculated using the score after merging.
[0225] For example, the merged score A_P[u][t], calculated as a weighted average of the two scores, is expressed as follows: A_P[u][t] = C0×Score1[u][t]+ (1-C0)×score2[u][t] C0 is a real number in the range [0,1] and is predetermined. Score1[u][t] is the score (A_P1[u1][t1]) obtained from the outlier analysis unit 310. Score2[u][t] is a score obtained from any of the other elements (320-360, 380, 390) of the alert analysis unit 120.
[0226] ***Supplementary Information on the Embodiment*** The alert priority setting device 100 analyzes the characteristics of alerts and logs related to those alerts to prioritize them. This allows for the automation of alert prioritization without the need to prepare detailed rules in advance.
[0227] An overview of the embodiment will be described based on Figure 46. The problem is the high number of alerts in the SOC. This is due to the limitations of log analysis techniques (such as anomaly detection) and the enormous number of logs to be examined. Even if the accuracy of anomaly detection is good (false positive rate: 0.1%), if the number of logs to be examined is large (e.g., 1 million), the number of false positives (1,000) will be enormous. Furthermore, if the amount of logs that can be used for training anomaly detection exceeds the capacity, it becomes necessary to limit the amount of data, such as shortening the training period or random sampling, which reduces the accuracy of anomaly detection. The embodiment adjusts the priority of alerts using heuristics from several perspectives. The embodiment then visualizes and presents what makes high-priority alerts different from past false positive alerts.
[0228] An overview of the embodiment will be described based on Figure 47. The challenges include the large number of alarms from attack detection systems (rule-based and anomaly-based), the limitations in improving the accuracy of attack detection systems, and the need to select which alarms to address. The embodiment adjusts alert priorities heuristically from several perspectives (two are exemplified in the overview below). The embodiment then visualizes and presents what makes high-priority alerts different from past false positive alerts. The first consideration is the statistically low frequency (outlier) of alerts for each user. When a number of alerts occurs that is considered statistically outliers, the priority is increased. Taking User 2 in Figure 47 as an example, priority increases when the number of alerts for User 2 exceeds the upper threshold (μ2 + 3σ2). "μ2" is the average number of alerts for User 2, and "σ2" is the standard deviation of the number of alerts for User 2. The second point to consider is whether the information included in the alert (let's say the destination domain) is also included in other users' alerts. If many of the same information is included in other users' alerts, the priority will be lowered due to common events (e.g., updates). If the same information is not included in other users' alerts, the priority will be increased due to unusual events (e.g., C2 communication).
[0229] Explain the problems you want to solve with existing technologies. In this embodiment, we want to prioritize alerts from systems that provide a score indicating whether an event is probabilistically rare, such as an anomaly detection system. Anomaly detection alerts do not directly correlate high or low scores to high or low risk levels. Because the model is created for the entire user base, it only represents the degree of rarity within the overall user data. Furthermore, no base risk value is provided. Also, there is no linking to CVEs like in IDS alerts. The embodiment aims to automatically set priorities without having to create detailed rules for assigning priorities. Creating rules is time-consuming. Furthermore, since rules are environment-dependent, they need to be changed when the environment changes. In this embodiment, we aim to prioritize alerts from two perspectives: the trend in the frequency of alert occurrences for each individual and the relationship between alerts and within alerts for each individual.
[0230] This document explains the anomaly detection alerts, hypotheses, and approaches. Hypothesis 1: The threshold for the number of alerts that warrant action varies from user to user. The reasons are as follows: Some users are more prone to triggering alerts than others. Therefore, the total amount of logs differs for each user. Furthermore, the difficulty of modeling each user's behavior varies. The approach is as follows: Calculate the trend in the number of alerts for each user. We consider a user to be at risk when the trend in the number of alerts reaches an outlier value. Users who have been consistently generating many alerts since immediately after training are considered at low risk even if some alerts occur. Users who rarely generate alerts are considered at high risk even if only a few alerts occur. Outliers: If the distribution of alert occurrence frequency follows a normal distribution, outliers are those exceeding (mean) ± 3 × (standard deviation). If the distribution is not normal, other statistical outlier detection methods (such as outliers using the interquartile range) can be used. Hypothesis 2: Similar alerts occurring simultaneously are often caused by systems that many users have installed (such as updates). The reasons are as follows: Due to the nature of targeted attacks, attackers do not want to attract attention, so they do not infect many users at once. If the false alert originated from a company-wide system, it's highly likely that many users would receive alerts simultaneously. The approach is as follows: The TF-IDF value* is calculated from the information contained in the alert and associated logs from the following perspectives. *TF-IDF is a technique used in the field of natural language processing to find words specific to a given document. In this embodiment, the features contained in the alert (+ associated logs) are treated as words in the document, and the TF-IDF is calculated. Regarding inter-user interactions, alerts from a given user and those from other users are compared for alerts occurring around the same time. The system then determines whether an alert is unique to the target user. Within a user, current and past alerts are compared to the user's alerts. Then, it is determined whether a new alert has occurred within the target user.
[0231] Figures 48 to 50 illustrate the concept of TFIDF analysis. Figure 48 shows the process for determining whether an alert is unique to the target user. "TF" represents the frequency of each word. "DF" represents the number of alerts containing each word. Figure 49 shows the process for determining whether an alert has newly occurred among the target users. Figure 50 shows the relationship between Word_Count1 (see Figure 48), Word_Count2 (see Figure 49), thresholds (θ1, θ2), and Score2.
[0232] I will now explain how to determine the final priorities. Scores calculated from multiple perspectives (Score1, Score2) are merged. Merging methods include using the average, weighted average, maximum value, and minimum value. Score 1 is a score indicating whether the frequency of alerts is an outlier. Using an outlier detection method, it can be determined whether the frequency of an alert is an outlier, for example, as follows: Whether the alert frequency exceeds the range of (mean) ± 3 × (standard deviation). Does the frequency of the alerts fall within the interquartile range of outliers? If the alert frequency is an outlier, the score is 1.0. If the alert frequency is not an outlier, the score is 0. Score 2 is the TF·IDF score (0-1.0) (see Figure 50). Examples of alerts that will be given priority are as follows: Alerts are given priority when both Score1 and Score2 are 1.0. Alerts are given priority when Score1 + Score2 > θ3. Alerts are given priority when Score1 × Score2 > θ4. Furthermore, there can be various ways to determine the final priority.
[0233] The embodiment visualizes what differs from past false positive alerts. The embodiment performs the following processing. Extract past false positive alerts similar to the target alert (K-neighbors). The system trains a classifier to categorize past false positive alerts that are similar to the target alert. The feature importance (feature information that contributed to the classification) of the trained classifier is calculated. The embodiment displays a monitoring screen with added explanatory features. On the monitoring screen, classification contributions are displayed as bar graphs and pie charts. Feature values for alert events and neighboring events are displayed as bar graphs for each feature, ordered by their classification contribution, and two types of features are plotted in two dimensions.
[0234] Each embodiment is an example of a preferred form and is not intended to limit the technical scope of this disclosure. Each embodiment may be implemented in part or in combination with other embodiments. Procedures described using flowcharts, etc., may be modified as appropriate.
[0235] Each element of the alert priority setting device 100 may be implemented using software, hardware, firmware, or a combination thereof. The word "part" in each element of the alert priority setting device 100 may be read as "processing," "process," "circuit," or "circuit."
[0236] The various aspects of this disclosure are described below as appendices. (Note 1) An alert analysis unit divides the alert log for the target entity to obtain multiple time-specific alert logs corresponding to multiple time periods, counts the number of alerts included in the time-specific alert log for each time period as the alert frequency, calculates statistics of the alert frequency for past time periods as alert statistics, and uses the alert frequency for the target time period and the alert statistics for past time periods to calculate an alert frequency score, which is a score for the target alert log, which is the time-specific alert log for the target time period for the target entity; and a priority calculation unit uses the alert frequency score to calculate the priority of the target alert log. An alert priority setting device equipped with the following features.
[0237] (Note 2) The alert analysis unit calculates information on words included in each time-slot alert log for each entity as time-slot alert word information, and uses the time-slot alert word information for the target time slot of the target entity and the time-slot alert word information for the target time slot of other entities to calculate an entity word score, which is a score for the target alert log. The priority calculation unit merges the calculated scores and uses the merged scores to calculate the priority of the target alert log. The alert priority setting device described in Appendix 1.
[0238] (Note 3) The alert analysis unit checks whether the threat information is included in the target alert log and the related logs, which are related logs analyzed to determine whether the occurrence of the target alert log is necessary, using threat information that identifies known attacks, and calculates a threat information score, which is a score for the target alert log, based on the check result. The priority calculation unit merges the calculated scores and uses the merged scores to calculate the priority of the target alert log. The alert priority setting device described in Appendix 1 or Appendix 2.
[0239] (Note 4) The alert analysis unit aggregates the multiple time-based alert logs using aggregation rules that indicate the conditions for aggregating the alert logs, and calculates an alert aggregation score, which is a score for the target alert log, based on the aggregation results. The priority calculation unit merges the calculated scores and uses the merged scores to calculate the priority of the target alert log. An alert priority setting device as described in any one of the appendices 1 through 3.
[0240] (Note 5) The alert analysis unit calculates information about the words contained in the target alert log from the target security sensor as target alert word information, divides the alert logs for the target entity from other security sensors to obtain multiple time-specific alert logs corresponding to multiple time periods, calculates information about the words contained in the time-specific alert logs for the target time period from the other security sensors as reference alert word information, and uses the target alert word information and the reference alert word information to calculate a sensor word score, which is a score for the target alert log. The priority calculation unit merges the calculated scores and uses the merged scores to calculate the priority of the target alert log. An alert priority setting device as described in any one of the appendices 1 through 4.
[0241] (Note 6) The alert analysis unit determines whether there are any logs indicating an attack in the corresponding related logs, which are related logs analyzed to determine whether the occurrence of the target alert log is necessary, using attack indicator rules that indicate the conditions for logs indicating signs of an attack, and calculates an attack indicator score, which is a score for the target alert log, based on the determination result. The priority calculation unit merges the calculated scores and uses the merged scores to calculate the priority of the target alert log. An alert priority setting device as described in any one of the appendices 1 through 5.
[0242] (Note 7) The alert analysis unit calculates information on words included in each time-slot alert log for each entity as time-slot alert word information, calculates inter-entity uniqueness using the time-slot alert word information for the target time slot of the target entity and the time-slot alert word information for the target time slot of other entities, calculates alert word statistics using the time-slot alert word information for each time slot of the target entity, calculates intra-entity uniqueness using the time-slot alert word information for the target time slot of the target entity and the alert word statistics of the target entity, and calculates an entity relationship score, which is a score for the target alert log, using the inter-entity uniqueness and intra-entity uniqueness. The priority calculation unit merges the calculated scores and uses the merged scores to calculate the priority of the target alert log. An alert priority setting device as described in any one of the appendices 1 through 6.
[0243] (Note 8) The alert analysis unit calculates information on words included in each time-slot alert log for each entity as time-slot alert word information, calculates inter-entity uniqueness using the time-slot alert word information for the target time slot of the target entity and the time-slot alert word information for the target time slot of other entities, calculates alert word statistics information for each entity using the time-slot alert word information for each time slot, calculates intra-entity uniqueness using the time-slot alert word information for the target time slot of the target entity and the alert word statistics information of the target entity, calculates past uniqueness using the alert word statistics information of the target entity and the alert word statistics information of other entities, and calculates an entity relationship score, which is a score for the target alert log, using the inter-entity uniqueness, intra-entity uniqueness and past uniqueness. The priority calculation unit merges the calculated scores and uses the merged scores to calculate the priority of the target alert log. An alert priority setting device as described in any one of the appendices 1 through 7.
[0244] (Note 9) A difference identification unit that calculates the difference between the characteristic information of the target alert log and the characteristic information of past alert logs, A visualization unit that generates a graph representing the calculated difference and displays the generated graph, An alert priority setting device described in any one of the appendices 1 to 8, comprising the features specified above.
[0245] (Note 10) An alert analysis unit divides the alert log for each entity to obtain multiple time-based alert logs corresponding to multiple time periods, calculates the information of words contained in each time-based alert log for each entity as time-based alert word information, and uses the time-based alert word information for the target entity's target time period and the time-based alert word information for the target time period of other entities to calculate an entity word score, which is a score for the target alert log, which is the time-based alert log for the target time period of the target entity. A priority calculation unit that calculates the priority of the target alert log using the entity word score, An alert priority setting device equipped with the following features.
[0246] (Note 11) An alert analysis unit divides the alert log for the target entity to obtain multiple time-based alert logs corresponding to multiple time periods, uses threat information to identify known attacks to check whether the threat information is included in the target alert log, which is the time-based alert log for the target time period for the target entity, and the corresponding related logs, which are related logs analyzed to determine whether the occurrence of the target alert log is necessary, and calculates a threat information score, which is a score for the target alert log, based on the check result. A priority calculation unit that calculates the priority of the target alert log using the threat information score, An alert priority setting device equipped with the following features.
[0247] (Note 12) An alert analysis unit divides the alert log for a target entity to obtain multiple time-specific alert logs corresponding to multiple time periods, aggregates the multiple time-specific alert logs using aggregation rules that indicate the conditions for aggregating the alert logs, and calculates an alert aggregation score, which is a score for the target alert log that is the time-specific alert log for the target time period for the target entity, based on the aggregation result. A priority calculation unit that calculates the priority of the target alert log using the alert aggregation score, An alert priority setting device equipped with the following features.
[0248] (Note 13) An alert analysis unit divides the alert log for the target entity from the target security sensor to obtain multiple time-specific alert logs corresponding to multiple time periods, calculates the information of words contained in the target alert log, which is the time-specific alert log for the target time period from the target security sensor, as target alert word information, divides the alert log for the target entity from other security sensors to obtain multiple time-specific alert logs corresponding to multiple time periods, calculates the information of words contained in the time-specific alert log for the target time period from the other security sensors, and calculates a sensor word score, which is a score for the target alert log, using the target alert word information and the reference alert word information. A priority calculation unit that calculates the priority of the target alert log using the sensor word score, An alert priority setting device equipped with the following features.
[0249] (Note 14) An alert analysis unit divides the alert log for the target entity to obtain multiple time-specific alert logs corresponding to multiple time periods, uses attack indicator rules that indicate the conditions for logs showing signs of an attack to determine whether the target alert log, which is a time-specific alert log for the target time period for the target entity, is necessary to generate, and determines whether there are logs showing signs of an attack in the corresponding related logs, which are related logs analyzed in order to determine whether there are logs showing signs of an attack, and calculates an attack indicator score, which is a score for the target alert log, based on the determination result. A priority calculation unit that calculates the priority of the target alert log using the attack indication score, An alert priority setting device equipped with the following features.
[0250] (Note 15) An alert analysis unit divides the alert log for each entity to obtain multiple time-based alert logs corresponding to multiple time periods, calculates the information of words contained in each time-based alert log for each entity as time-based alert word information, calculates inter-entity uniqueness using the time-based alert word information for the target entity's target time period and the time-based alert word information for the target time period of other entities, calculates alert word statistics using the time-based alert word information for each time period of the target entity, calculates intra-entity uniqueness using the time-based alert word information for the target entity's target time period and the alert word statistics of the target entity, and calculates an entity relationship score, which is a score for the target alert log, which is the time-based alert log for the target time period of the target entity, using the inter-entity uniqueness and intra-entity uniqueness. A priority calculation unit that calculates the priority of the target alert log using the entity relationship score, An alert priority setting device equipped with the following features.
[0251] (Note 16) An alert analysis unit divides the alert log for each entity to obtain multiple time-based alert logs corresponding to multiple time periods, calculates the information of words contained in each time-based alert log for each entity as time-based alert word information, calculates inter-entity uniqueness using the time-based alert word information for the target entity's target time period and the time-based alert word information for the target time period of other entities, calculates alert word statistics information using the time-based alert word information for each time period for each entity, calculates intra-entity uniqueness using the time-based alert word information for the target entity's target time period and the alert word statistics information of the target entity, calculates past uniqueness using the alert word statistics information of the target entity and the alert word statistics information of other entities, and calculates an entity relationship score, which is a score for the target alert log, which is the time-based alert log for the target time period of the target entity, using the inter-entity uniqueness, intra-entity uniqueness and past uniqueness. A priority calculation unit that calculates the priority of the target alert log using the entity relationship score, An alert priority setting device equipped with the following features.
[0252] (Note 17) A difference identification unit that calculates the difference between the characteristic information of the target alert log and the characteristic information of past alert logs, A visualization unit that generates a graph representing the calculated difference and displays the generated graph, An alert priority setting device as described in any one of appendices 10 to 16, comprising the features described herein.
[0253] (Note 18) The alert log for the target entity is divided to obtain multiple time-specific alert logs corresponding to multiple time periods, the number of alerts included in the time-specific alert log for each time period is counted as the alert frequency, statistics of the alert frequency for past time periods are calculated as alert statistics, and the alert frequency for the target time period and the alert statistics for past time periods are used to calculate the alert frequency score, which is the score for the target alert log, which is the time-specific alert log for the target time period for the target entity. The priority of the target alert log is calculated using the alert frequency score. How to set alert priority.
[0254] (Note 19) For each entity, the alert log for that entity is divided to obtain multiple time-based alert logs corresponding to multiple time periods, and for each entity, the information of the words contained in each time-based alert log is calculated as time-based alert word information, and using the time-based alert word information for the target entity's target time period and the time-based alert word information for the target time period of other entities, an entity word score is calculated, which is the score for the target alert log, which is the time-based alert log for the target time period of the target entity. The priority of the target alert log is calculated using the entity word score. How to set alert priority.
[0255] (Note 20) The alert log for the target entity is divided to obtain multiple time-based alert logs corresponding to multiple time periods, and threat information that identifies known attacks is used to check whether the threat information is included in the target alert log, which is the time-based alert log for the target time period for the target entity, and the related logs, which are related logs analyzed to determine whether the occurrence of the target alert log is necessary, and a threat information score, which is a score for the target alert log, is calculated based on the check result. The priority of the target alert log is calculated using the aforementioned threat intelligence score. How to set alert priority.
[0256] (Note 21) The alert log for the target entity is divided to obtain multiple time-based alert logs corresponding to multiple time periods, the multiple time-based alert logs are aggregated using aggregation rules that indicate the conditions for aggregating the alert logs, and based on the aggregation results, an alert aggregation score is calculated, which is the score for the target alert log, which is the time-based alert log for the target time period for the target entity. The priority of the target alert log is calculated using the alert aggregation score. How to set alert priority.
[0257] (Note 22) The alert logs for the target entity from the target security sensor are divided to obtain multiple time-specific alert logs corresponding to multiple time periods, and the information of words contained in the target alert log, which is the time-specific alert log for the target time period from the target security sensor, is calculated as target alert word information. The alert logs for the target entity from other security sensors are divided to obtain multiple time-specific alert logs corresponding to multiple time periods, and the information of words contained in the time-specific alert log for the target time period from the other security sensors is calculated as reference alert word information. The sensor word score, which is the score for the target alert log, is calculated using the target alert word information and the reference alert word information. The priority of the target alert log is calculated using the aforementioned sensor word score. How to set alert priority.
[0258] (Note 23) The alert log for the target entity is divided to obtain multiple time-specific alert logs corresponding to multiple time periods, and using attack indicator rules that indicate the conditions for logs showing signs of an attack, it is determined whether there are logs showing signs of an attack in the corresponding related logs, which are related logs analyzed to determine whether the target alert log, which is the time-specific alert log for the target time period for the target entity, is necessary to generate, and based on the determination result, an attack indicator score, which is a score for the target alert log, is calculated. The priority of the target alert log is calculated using the aforementioned attack indicator score. How to set alert priority.
[0259] (Note 24) For each entity, the alert log for the entity is divided to obtain multiple time-based alert logs corresponding to multiple time periods; for each entity, the information of the words contained in each time-based alert log is calculated as time-based alert word information; inter-entity uniqueness is calculated using the time-based alert word information for the target entity's target time period and the time-based alert word information for the target time period of other entities; alert word statistics are calculated using the time-based alert word information for each time period of the target entity; intra-entity uniqueness is calculated using the time-based alert word information for the target entity's target time period and the alert word statistics of the target entity; and an entity relationship score is calculated, which is a score for the target alert log, which is the time-based alert log for the target time period of the target entity, using the inter-entity uniqueness and intra-entity uniqueness. The priority of the target alert log is calculated using the entity relationship score. How to set alert priority.
[0260] (Note 25) For each entity, the alert log for the entity is divided to obtain multiple time-based alert logs corresponding to multiple time periods; for each entity, the information of the words contained in each time-based alert log is calculated as time-based alert word information; inter-entity uniqueness is calculated using the time-based alert word information for the target entity's target time period and the time-based alert word information for the target time period of other entities; alert word statistics are calculated for each entity using the time-based alert word information for each time period; intra-entity uniqueness is calculated using the time-based alert word information for the target entity's target time period and the alert word statistics of the target entity; past uniqueness is calculated using the alert word statistics of the target entity and the alert word statistics of other entities; and an entity relationship score is calculated, which is a score for the target alert log, which is the time-based alert log for the target time period of the target entity, using the inter-entity uniqueness, intra-entity uniqueness, and past uniqueness. The priority of the target alert log is calculated using the entity relationship score. How to set alert priority.
[0261] (Note 26) An alert analysis process that divides the alert log for the target entity to obtain multiple time-specific alert logs corresponding to multiple time periods, counts the number of alerts included in the time-specific alert log for each time period as the alert frequency, calculates statistics of the alert frequency for past time periods as alert statistics, and uses the alert frequency for the target time period and the alert statistics for past time periods to calculate an alert frequency score, which is a score for the target alert log, which is the time-specific alert log for the target time period, for the target entity. A priority calculation process that calculates the priority of the target alert log using the alert frequency score, An alert priority setting program to cause a computer to execute an alert.
[0262] (Note 27) An alert analysis process that divides the alert log for each entity to obtain multiple time-based alert logs corresponding to multiple time periods, calculates the information of words contained in each time-based alert log for each entity as time-based alert word information, and uses the time-based alert word information for the target entity's target time period and the time-based alert word information for the target entity's target time period to calculate an entity word score, which is a score for the target alert log, which is the time-based alert log for the target time period for the target entity. A priority calculation process that calculates the priority of the target alert log using the entity word score, An alert priority setting program to cause a computer to execute an alert.
[0263] (Note 28) An alert analysis process involves splitting the alert log for the target entity to obtain multiple time-based alert logs corresponding to multiple time periods, using threat information to identify known attacks to check whether the threat information is included in the target alert log, which is the time-based alert log for the target time period for the target entity, and the corresponding related logs, which are related logs analyzed to determine whether the occurrence of the target alert log is necessary, and calculating a threat information score, which is a score for the target alert log, based on the check results. A priority calculation process that calculates the priority of the target alert log using the threat information score, An alert priority setting program to cause a computer to execute an alert.
[0264] (Note 29) An alert analysis process that divides the alert log for the target entity to obtain multiple time-specific alert logs corresponding to multiple time periods, aggregates the multiple time-specific alert logs using aggregation rules that indicate the conditions for aggregating the alert logs, and calculates an alert aggregation score, which is a score for the target alert log that is the time-specific alert log for the target time period for the target entity, based on the aggregation result. A priority calculation process that calculates the priority of the target alert log using the alert aggregation score, An alert priority setting program to cause a computer to execute an alert.
[0265] (Note 30) An alert analysis process that divides the alert log for the target entity from the target security sensor to obtain multiple time-specific alert logs corresponding to multiple time periods, calculates the information of words contained in the target alert log, which is the time-specific alert log for the target time period from the target security sensor, as target alert word information, divides the alert log for the target entity from other security sensors to obtain multiple time-specific alert logs corresponding to multiple time periods, calculates the information of words contained in the time-specific alert log for the target time period from the other security sensors, and calculates a sensor word score, which is a score for the target alert log, using the target alert word information and the reference alert word information. A priority calculation process that calculates the priority of the target alert log using the sensor word score, An alert priority setting program to cause a computer to execute an alert.
[0266] (Note 31) An alert analysis process involves splitting the alert log for the target entity to obtain multiple time-specific alert logs corresponding to multiple time periods, using attack indicator rules that indicate the conditions for logs showing signs of an attack to determine whether the target alert log, which is a time-specific alert log for the target time period for the target entity, is necessary, determining whether there are logs showing signs of an attack in the corresponding related logs, which are analyzed related logs, and calculating an attack indicator score, which is a score for the target alert log, based on the determination result. A priority calculation process that calculates the priority of the target alert log using the attack indication score, An alert priority setting program to cause a computer to execute an alert.
[0267] (Note 32) An alert analysis process that divides the alert log for each entity to obtain multiple time-based alert logs corresponding to multiple time periods, calculates the information of words contained in each time-based alert log for each entity as time-based alert word information, calculates inter-entity uniqueness using the time-based alert word information for the target entity's target time period and the time-based alert word information for the target time period of other entities, calculates alert word statistics using the time-based alert word information for each time period of the target entity, calculates intra-entity uniqueness using the time-based alert word information for the target entity's target time period and the alert word statistics of the target entity, and calculates an entity relationship score, which is a score for the target alert log, which is the time-based alert log for the target time period of the target entity, using the inter-entity uniqueness and intra-entity uniqueness. A priority calculation process that calculates the priority of the target alert log using the entity relationship score, An alert priority setting program to cause a computer to execute an alert.
[0268] (Note 33) An alert analysis process that divides the alert log for each entity to obtain multiple time-based alert logs corresponding to multiple time periods, calculates the information of words contained in each time-based alert log for each entity as time-based alert word information, calculates inter-entity uniqueness using the time-based alert word information for the target entity's target time period and the time-based alert word information for the target time period of other entities, calculates alert word statistics using the time-based alert word information for each time period for each entity, calculates intra-entity uniqueness using the time-based alert word information for the target entity's target time period and the alert word statistics of the target entity, calculates past uniqueness using the alert word statistics of the target entity and the alert word statistics of other entities, and calculates an entity relationship score, which is a score for the target alert log, which is the time-based alert log for the target time period of the target entity, using the inter-entity uniqueness, intra-entity uniqueness and past uniqueness. A priority calculation process that calculates the priority of the target alert log using the entity relationship score, An alert priority setting program to cause a computer to execute an alert. [Explanation of Symbols]
[0269] 100 Alert priority setting device, 101 Processor, 102 Memory, 103 Auxiliary storage device, 104 Communication device, 105 Input / Output interface, 110 Alert acquisition unit, 120 Alert analysis unit, 121-126 Score, 128 Score, 129 Score, 130 Priority calculation unit, 131 Priority, 140 Alert output unit, 141 Priority-assigned log, 151 Difference identification unit, 152 Visualization unit, 153 Visualization results, 190 Storage unit, 200 Alert priority setting system, 210 Security sensor, 220 Alert log, 221 Alert log, 230 Related log, 231 Related log, 240 Security sensor, 250 Alert log, 260 Related log, 271 False detection DB, 272 Known attack DB, 310 Outlier analysis unit, 311 Alert frequency calculation unit, 312 Alert statistics calculation unit, 313 Outlier calculation unit, 314 Frequency information, 315 Frequency information, 316 Statistical information, 320 Relationship analysis unit, 321 Word frequency calculation unit, 322 Relationship calculation unit, 323 Word information, 330 Information utilization unit, 331 Matching unit, 332 Threat information DB, 340 Aggregation unit, 341 Merge unit, 342 Aggregation rule DB, 350 Information utilization unit, 351 Word frequency calculation unit, 352 Matching unit, 353 Word information, 354 Word information, 358 Other sensor alert log, 359 Other sensor alert DB, 360 Event analysis unit, 361 Search unit, 362 Attack indicator rule DB, 380 Relationship analysis unit, 381 Word statistics analysis unit, 382 Relationship calculation unit, 383 Score calculation unit, 384 Statistical information, 390 Relationship Analysis Unit, 391 Relationship Calculation Unit, 392 Score Calculation Unit.
Claims
1. An alert analysis unit divides the alert log for the target entity to obtain multiple time-specific alert logs corresponding to multiple time periods, counts the number of alerts included in the time-specific alert log for each time period as the alert frequency, calculates statistics of the alert frequency for past time periods as alert statistics, and uses the alert frequency for the target time period and the alert statistics for past time periods to calculate an alert frequency score, which is a score for the target alert log, which is the time-specific alert log for the target time period, for the target entity. A priority calculation unit that calculates the priority of the target alert log using the alert frequency score, An alert priority setting device equipped with the following features.
2. The alert analysis unit calculates information on words included in each time-slot alert log for each entity as time-slot alert word information, and uses the time-slot alert word information for the target time slot of the target entity and the time-slot alert word information for the target time slot of other entities to calculate an entity word score, which is a score for the target alert log. The priority calculation unit merges the calculated scores and uses the merged scores to calculate the priority of the target alert log. The alert priority setting device according to claim 1.
3. The alert analysis unit checks whether the threat information is included in the target alert log and the related logs, which are related logs analyzed to determine whether the occurrence of the target alert log is necessary, using threat information that identifies known attacks, and calculates a threat information score, which is a score for the target alert log, based on the check result. The priority calculation unit merges the calculated scores and uses the merged scores to calculate the priority of the target alert log. The alert priority setting device according to claim 1.
4. The alert analysis unit aggregates the multiple time-based alert logs using aggregation rules that indicate the conditions for aggregating the alert logs, and calculates an alert aggregation score, which is a score for the target alert log, based on the aggregation results. The priority calculation unit merges the calculated scores and uses the merged scores to calculate the priority of the target alert log. The alert priority setting device according to claim 1.
5. The alert analysis unit calculates information about the words contained in the target alert log from the target security sensor as target alert word information, divides the alert logs for the target entity from other security sensors to obtain multiple time-specific alert logs corresponding to multiple time periods, calculates information about the words contained in the time-specific alert logs for the target time period from the other security sensors as reference alert word information, and uses the target alert word information and the reference alert word information to calculate a sensor word score, which is a score for the target alert log. The priority calculation unit merges the calculated scores and uses the merged scores to calculate the priority of the target alert log. The alert priority setting device according to claim 1.
6. The alert analysis unit determines whether there are any logs indicating an attack in the corresponding related logs, which are related logs analyzed to determine whether the occurrence of the target alert log is necessary, using attack indicator rules that indicate the conditions for logs indicating signs of an attack, and calculates an attack indicator score, which is a score for the target alert log, based on the determination result. The priority calculation unit merges the calculated scores and uses the merged scores to calculate the priority of the target alert log. The alert priority setting device according to claim 1.
7. The alert analysis unit calculates information on words included in each time-slot alert log for each entity as time-slot alert word information, calculates inter-entity uniqueness using the time-slot alert word information for the target time slot of the target entity and the time-slot alert word information for the target time slot of other entities, calculates alert word statistics using the time-slot alert word information for each time slot of the target entity, calculates intra-entity uniqueness using the time-slot alert word information for the target time slot of the target entity and the alert word statistics of the target entity, and calculates an entity relationship score, which is a score for the target alert log, using the inter-entity uniqueness and intra-entity uniqueness. The priority calculation unit merges the calculated scores and uses the merged scores to calculate the priority of the target alert log. The alert priority setting device according to claim 1.
8. The alert analysis unit calculates information on words included in each time-slot alert log for each entity as time-slot alert word information, calculates inter-entity uniqueness using the time-slot alert word information for the target time slot of the target entity and the time-slot alert word information for the target time slot of other entities, calculates alert word statistics information for each entity using the time-slot alert word information for each time slot, calculates intra-entity uniqueness using the time-slot alert word information for the target time slot of the target entity and the alert word statistics information of the target entity, calculates past uniqueness using the alert word statistics information of the target entity and the alert word statistics information of other entities, and calculates an entity relationship score, which is a score for the target alert log, using the inter-entity uniqueness, intra-entity uniqueness and past uniqueness. The priority calculation unit merges the calculated scores and uses the merged scores to calculate the priority of the target alert log. The alert priority setting device according to claim 1.
9. A difference identification unit that calculates the difference between the characteristic information of the target alert log and the characteristic information of past alert logs, A visualization unit that generates a graph representing the calculated difference and displays the generated graph, An alert priority setting device according to any one of claims 1 to 8, comprising:
10. An alert analysis unit divides the alert log for each entity to obtain multiple time-based alert logs corresponding to multiple time periods, calculates the information of words contained in each time-based alert log for each entity as time-based alert word information, and uses the time-based alert word information for the target entity's target time period and the time-based alert word information for the target time period of other entities to calculate an entity word score, which is a score for the target alert log, which is the time-based alert log for the target time period of the target entity. A priority calculation unit that calculates the priority of the target alert log using the entity word score, An alert priority setting device equipped with the following features.
11. An alert analysis unit divides the alert log for the target entity to obtain multiple time-based alert logs corresponding to multiple time periods, uses threat information to identify known attacks to check whether the threat information is included in the target alert log, which is the time-based alert log for the target time period for the target entity, and the corresponding related logs, which are related logs analyzed to determine whether the occurrence of the target alert log is necessary, and calculates a threat information score, which is a score for the target alert log, based on the check result. A priority calculation unit that calculates the priority of the target alert log using the threat information score, An alert priority setting device equipped with the following features.
12. An alert analysis unit divides the alert log for a target entity to obtain multiple time-specific alert logs corresponding to multiple time periods, aggregates the multiple time-specific alert logs using aggregation rules that indicate the conditions for aggregating the alert logs, and calculates an alert aggregation score, which is a score for the target alert log that is the time-specific alert log for the target time period for the target entity, based on the aggregation result. A priority calculation unit that calculates the priority of the target alert log using the alert aggregation score, An alert priority setting device equipped with the following features.
13. An alert analysis unit divides the alert log for the target entity from the target security sensor to obtain multiple time-specific alert logs corresponding to multiple time periods, calculates the information of words contained in the target alert log, which is the time-specific alert log for the target time period from the target security sensor, as target alert word information, divides the alert log for the target entity from other security sensors to obtain multiple time-specific alert logs corresponding to multiple time periods, calculates the information of words contained in the time-specific alert log for the target time period from the other security sensors, and calculates a sensor word score, which is a score for the target alert log, using the target alert word information and the reference alert word information. A priority calculation unit that calculates the priority of the target alert log using the sensor word score, An alert priority setting device equipped with the following features.
14. An alert analysis unit divides the alert log for the target entity to obtain multiple time-specific alert logs corresponding to multiple time periods, uses attack indicator rules that indicate the conditions for logs showing signs of an attack to determine whether the target alert log, which is a time-specific alert log for the target time period for the target entity, is necessary to generate, and determines whether there are logs showing signs of an attack in the corresponding related logs, which are related logs analyzed in order to determine whether there are logs showing signs of an attack, and calculates an attack indicator score, which is a score for the target alert log, based on the determination result. A priority calculation unit that calculates the priority of the target alert log using the attack indication score, An alert priority setting device equipped with the following features.
15. An alert analysis unit divides the alert log for each entity to obtain multiple time-based alert logs corresponding to multiple time periods, calculates the information of words contained in each time-based alert log for each entity as time-based alert word information, calculates inter-entity uniqueness using the time-based alert word information for the target entity's target time period and the time-based alert word information for the target time period of other entities, calculates alert word statistics using the time-based alert word information for each time period of the target entity, calculates intra-entity uniqueness using the time-based alert word information for the target entity's target time period and the alert word statistics of the target entity, and calculates an entity relationship score, which is a score for the target alert log, which is the time-based alert log for the target time period of the target entity, using the inter-entity uniqueness and intra-entity uniqueness. A priority calculation unit that calculates the priority of the target alert log using the entity relationship score, An alert priority setting device equipped with the following features.
16. An alert analysis unit divides the alert log for each entity to obtain multiple time-based alert logs corresponding to multiple time periods, calculates the information of words contained in each time-based alert log for each entity as time-based alert word information, calculates inter-entity uniqueness using the time-based alert word information for the target entity's target time period and the time-based alert word information for the target time period of other entities, calculates alert word statistics information using the time-based alert word information for each time period for each entity, calculates intra-entity uniqueness using the time-based alert word information for the target entity's target time period and the alert word statistics information of the target entity, calculates past uniqueness using the alert word statistics information of the target entity and the alert word statistics information of other entities, and calculates an entity relationship score, which is a score for the target alert log, which is the time-based alert log for the target time period of the target entity, using the inter-entity uniqueness, intra-entity uniqueness and past uniqueness. A priority calculation unit that calculates the priority of the target alert log using the entity relationship score, An alert priority setting device equipped with the following features.
17. A difference identification unit that calculates the difference between the characteristic information of the target alert log and the characteristic information of past alert logs, A visualization unit that generates a graph representing the calculated difference and displays the generated graph, An alert priority setting device according to any one of claims 10 to 16, comprising:
18. The alert log for the target entity is divided to obtain multiple time-specific alert logs corresponding to multiple time periods, the number of alerts included in the time-specific alert log for each time period is counted as the alert frequency, statistics of the alert frequency for past time periods are calculated as alert statistics, and the alert frequency for the target time period and the alert statistics for past time periods are used to calculate the alert frequency score, which is the score for the target alert log, which is the time-specific alert log for the target time period for the target entity. The priority of the target alert log is calculated using the alert frequency score. How to set alert priority.
19. For each entity, the alert log for that entity is divided to obtain multiple time-based alert logs corresponding to multiple time periods, and for each entity, the information of the words contained in each time-based alert log is calculated as time-based alert word information, and using the time-based alert word information for the target entity's target time period and the time-based alert word information for the target time period of other entities, an entity word score is calculated, which is the score for the target alert log, which is the time-based alert log for the target time period of the target entity. The priority of the target alert log is calculated using the entity word score. How to set alert priority.
20. The alert log for the target entity is divided to obtain multiple time-based alert logs corresponding to multiple time periods, and threat information that identifies known attacks is used to check whether the threat information is included in the target alert log, which is the time-based alert log for the target time period for the target entity, and the related logs, which are related logs analyzed to determine whether the occurrence of the target alert log is necessary, and a threat information score, which is a score for the target alert log, is calculated based on the check result. The priority of the target alert log is calculated using the aforementioned threat intelligence score. How to set alert priority.
21. The alert log for the target entity is divided to obtain multiple time-based alert logs corresponding to multiple time periods, the multiple time-based alert logs are aggregated using aggregation rules that indicate the conditions for aggregating the alert logs, and based on the aggregation results, an alert aggregation score is calculated, which is the score for the target alert log, which is the time-based alert log for the target time period for the target entity. The priority of the target alert log is calculated using the alert aggregation score. How to set alert priority.
22. The alert logs for the target entity from the target security sensor are divided to obtain multiple time-specific alert logs corresponding to multiple time periods, and the information of words contained in the target alert log, which is the time-specific alert log for the target time period from the target security sensor, is calculated as target alert word information. The alert logs for the target entity from other security sensors are divided to obtain multiple time-specific alert logs corresponding to multiple time periods, and the information of words contained in the time-specific alert log for the target time period from the other security sensors is calculated as reference alert word information. The sensor word score, which is the score for the target alert log, is calculated using the target alert word information and the reference alert word information. The priority of the target alert log is calculated using the aforementioned sensor word score. How to set alert priority.
23. The alert log for the target entity is divided to obtain multiple time-specific alert logs corresponding to multiple time periods, and using attack indicator rules that indicate the conditions for logs showing signs of an attack, it is determined whether there are logs showing signs of an attack in the corresponding related logs, which are related logs analyzed to determine whether the target alert log, which is the time-specific alert log for the target time period for the target entity, is necessary to generate, and based on the determination result, an attack indicator score, which is a score for the target alert log, is calculated. The priority of the target alert log is calculated using the aforementioned attack indicator score. How to set alert priority.
24. For each entity, the alert log for the entity is divided to obtain multiple time-based alert logs corresponding to multiple time periods; for each entity, the information of the words contained in each time-based alert log is calculated as time-based alert word information; inter-entity uniqueness is calculated using the time-based alert word information for the target entity's target time period and the time-based alert word information for the target time period of other entities; alert word statistics are calculated using the time-based alert word information for each time period of the target entity; intra-entity uniqueness is calculated using the time-based alert word information for the target entity's target time period and the alert word statistics of the target entity; and an entity relationship score is calculated, which is a score for the target alert log, which is the time-based alert log for the target time period of the target entity, using the inter-entity uniqueness and intra-entity uniqueness. The priority of the target alert log is calculated using the entity relationship score. How to set alert priority.
25. For each entity, the alert log for the entity is divided to obtain multiple time-based alert logs corresponding to multiple time periods; for each entity, the information of the words contained in each time-based alert log is calculated as time-based alert word information; inter-entity uniqueness is calculated using the time-based alert word information for the target entity's target time period and the time-based alert word information for the target time period of other entities; alert word statistics are calculated for each entity using the time-based alert word information for each time period; intra-entity uniqueness is calculated using the time-based alert word information for the target entity's target time period and the alert word statistics of the target entity; past uniqueness is calculated using the alert word statistics of the target entity and the alert word statistics of other entities; and an entity relationship score is calculated, which is a score for the target alert log, which is the time-based alert log for the target time period of the target entity, using the inter-entity uniqueness, intra-entity uniqueness, and past uniqueness. The priority of the target alert log is calculated using the entity relationship score. How to set alert priority.
26. An alert analysis process that divides the alert log for the target entity to obtain multiple time-specific alert logs corresponding to multiple time periods, counts the number of alerts included in the time-specific alert log for each time period as the alert frequency, calculates statistics of the alert frequency for past time periods as alert statistics, and uses the alert frequency for the target time period and the alert statistics for past time periods to calculate an alert frequency score, which is a score for the target alert log, which is the time-specific alert log for the target time period, for the target entity. A priority calculation process that calculates the priority of the target alert log using the alert frequency score, An alert priority setting program to cause a computer to execute an alert.
27. An alert analysis process that divides the alert log for each entity to obtain multiple time-based alert logs corresponding to multiple time periods, calculates the information of words contained in each time-based alert log for each entity as time-based alert word information, and uses the time-based alert word information for the target entity's target time period and the time-based alert word information for the target entity's target time period to calculate an entity word score, which is a score for the target alert log, which is the time-based alert log for the target time period for the target entity. A priority calculation process that calculates the priority of the target alert log using the entity word score, An alert priority setting program to cause a computer to execute an alert.
28. An alert analysis process involves splitting the alert log for the target entity to obtain multiple time-based alert logs corresponding to multiple time periods, using threat information to identify known attacks to check whether the threat information is included in the target alert log, which is the time-based alert log for the target time period for the target entity, and the corresponding related logs, which are related logs analyzed to determine whether the occurrence of the target alert log is necessary, and calculating a threat information score, which is a score for the target alert log, based on the check results. A priority calculation process that calculates the priority of the target alert log using the threat information score, An alert priority setting program to cause a computer to execute an alert.
29. An alert analysis process that divides the alert log for the target entity to obtain multiple time-specific alert logs corresponding to multiple time periods, aggregates the multiple time-specific alert logs using aggregation rules that indicate the conditions for aggregating the alert logs, and calculates an alert aggregation score, which is a score for the target alert log that is the time-specific alert log for the target time period for the target entity, based on the aggregation result. A priority calculation process that calculates the priority of the target alert log using the alert aggregation score, An alert priority setting program to cause a computer to execute an alert.
30. An alert analysis process that divides the alert log for the target entity from the target security sensor to obtain multiple time-specific alert logs corresponding to multiple time periods, calculates the information of words contained in the target alert log, which is the time-specific alert log for the target time period from the target security sensor, as target alert word information, divides the alert log for the target entity from other security sensors to obtain multiple time-specific alert logs corresponding to multiple time periods, calculates the information of words contained in the time-specific alert log for the target time period from the other security sensors, and calculates a sensor word score, which is a score for the target alert log, using the target alert word information and the reference alert word information. A priority calculation process that calculates the priority of the target alert log using the sensor word score, An alert priority setting program to cause a computer to execute an alert.
31. An alert analysis process involves splitting the alert log for the target entity to obtain multiple time-specific alert logs corresponding to multiple time periods, using attack indicator rules that indicate the conditions for logs showing signs of an attack to determine whether the target alert log, which is a time-specific alert log for the target time period for the target entity, is necessary, determining whether there are logs showing signs of an attack in the corresponding related logs, which are analyzed related logs, and calculating an attack indicator score, which is a score for the target alert log, based on the determination result. A priority calculation process that calculates the priority of the target alert log using the attack indication score, An alert priority setting program to cause a computer to execute an alert.
32. An alert analysis process that divides the alert log for each entity to obtain multiple time-based alert logs corresponding to multiple time periods, calculates the information of words contained in each time-based alert log for each entity as time-based alert word information, calculates inter-entity uniqueness using the time-based alert word information for the target entity's target time period and the time-based alert word information for the target time period of other entities, calculates alert word statistics using the time-based alert word information for each time period of the target entity, calculates intra-entity uniqueness using the time-based alert word information for the target entity's target time period and the alert word statistics of the target entity, and calculates an entity relationship score, which is a score for the target alert log, which is the time-based alert log for the target time period of the target entity, using the inter-entity uniqueness and intra-entity uniqueness. A priority calculation process that calculates the priority of the target alert log using the entity relationship score, An alert priority setting program to cause a computer to execute an alert.
33. An alert analysis process that divides the alert log for each entity to obtain multiple time-based alert logs corresponding to multiple time periods, calculates the information of words contained in each time-based alert log for each entity as time-based alert word information, calculates inter-entity uniqueness using the time-based alert word information for the target entity's target time period and the time-based alert word information for the target time period of other entities, calculates alert word statistics using the time-based alert word information for each time period for each entity, calculates intra-entity uniqueness using the time-based alert word information for the target entity's target time period and the alert word statistics of the target entity, calculates past uniqueness using the alert word statistics of the target entity and the alert word statistics of other entities, and calculates an entity relationship score, which is a score for the target alert log, which is the time-based alert log for the target time period of the target entity, using the inter-entity uniqueness, intra-entity uniqueness and past uniqueness. A priority calculation process that calculates the priority of the target alert log using the entity relationship score, An alert priority setting program to cause a computer to execute an alert.