Computer-Implemented Method, Computer Program, and System (Execution of Security Recommendations)
A system using an action model and collaborative filtering model provides context-specific security recommendations, addressing the irrelevance of traditional approaches and enhancing response effectiveness and customer satisfaction.
Patent Information
- Application Number
- JP2021198886
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-12-10
- Filing Date
- 2021-12-07
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2041-12-07
AI Technical Summary
Security analysts' recommendations for mitigating or preventing security incidents are often perceived as formulaic and irrelevant, leading to potential damage and decreased client satisfaction.
A system utilizing an action model and collaborative filtering model to generate a prioritized list of recommended actions based on past successes and organizational similarities, providing context-specific and actionable responses.
Enhances the relevance and effectiveness of security recommendations, reducing costs and time spent by analysts while increasing customer satisfaction through tailored responses.
Smart Images

Figure 0007714290000001 
Figure 0007714290000002 
Figure 0007714290000003
Abstract
Description
Technical Field
[0001] This disclosure relates to security, and more particularly, to the enforcement of security recommendations.
Background Art
[0002] Security analysts can monitor a client's computer communication network to identify potential security incidents, such as attempts by malicious users to hack into a particular client's network. In addition, security analysts can generally identify patterns of attempts made across a computer communication network. These patterns can indicate vulnerabilities in clients that could potentially be targets of an attack. Thus, these analysts can make recommendations to the client about what actions should be taken to mitigate or prevent any damage that might be caused by some action that a malicious user might take in some cases.
Summary of the Invention
Problems to be Solved by the Invention
[0003] It is useful for potential targets of security incidents to respond to these recommendations by taking action to prevent or mitigate or both the damage caused by an actual or potential security incident.
Means for Solving the Problems
[0004] Embodiments are disclosed for a method. The method includes determining a plurality of recommended actions based on a security incident using an action model trained to make recommendations. The method also includes determining a plurality of similar targets of the target of the security incident using a collaborative filtering model trained to assign a confidence value to the similarity between two targets. The method further includes assigning a plurality of weights to the recommended actions based on one or more actions taken by the similar targets and the confidence value, as well as the success or failure of the recommended actions. Additionally, the method includes generating a ranked list of the recommended actions sorted based on the assigned weights.
[0005] Furthermore, aspects of the present disclosure are directed to systems and computer program products having functions similar to the above-described functions of the computer-implemented method. The summary of the invention is not intended to represent every aspect, all implementations, or all embodiments of the present disclosure or combinations thereof.
Brief Description of the Drawings
[0006] The drawings included in this application are incorporated herein and form a part of this specification. They illustrate embodiments of the present disclosure and, together with this specification, serve to explain the principles of the present disclosure. The drawings are only examples of specific embodiments and do not limit the present disclosure.
[0007]
Figure 1
[0008]
Figure 2
[0009]
Figure 3
[0010]
Figure 4
[0011]
Figure 5
[0012]
Figure 6
[0013]
Figure 7
[0014] Although the present disclosure is suitable for various modified and alternative forms, specific details thereof are shown by way of example in the drawings and described in detail. However, it should be understood that the present disclosure is not intended to be limited to the specific embodiments described. On the contrary, it is intended to cover all modifications, equivalents, and alternatives included within the spirit and scope of the present disclosure.
Embodiments for Carrying Out the Invention
[0015] As described above, a security analyst can provide recommendations to a client regarding actions to be taken to mitigate or prevent any damage caused by any actions that a malicious user might take in a security incident, or might take in the future. Thus, a security analyst can spend a relatively large amount of time monitoring the customer's environment, generating client communications, and notifying the client of recommended actions.
[0016] For potential targets of a security incident, it is useful to respond to these recommendations by taking actions to prevent or mitigate damage, or both, from an actual or potential security incident. However, client communications may be perceived by the client as being overly formulaic and not particularly relevant, and thus the client may, in some cases, ignore them, and may, in some cases, fail to properly repair actual or potential damage, or both, from a security incident. Further, any resulting damage may increase the cost of client security or decrease client satisfaction.
[0017] Accordingly, embodiments of the present disclosure can provide more relevant and more meaningful recommendations for actual or potential targets of a security incident, or both. Such embodiments can provide a list of recommended actions that are prioritized according to how successful actions have been to date for similar targets and security incidents. In this way, such embodiments can provide context to recommendations that reflect similarities to past responses that have been successful for similar security incidents affecting similar targets.
[0018] FIG. 1 is a block diagram of an exemplary system 100 for making recommendations according to some embodiments of the present disclosure. The system 100 includes a network 102, a security information and event management system (SIEMS) 104, an action model 106, a collaborative filtering model 108, and a recommendation manager 110. The network 102 may be a collection of computer communication networks that facilitate communication between components of the system 100, particularly between the SIEMS 104, the action model 106, the collaborative filtering model 108, and the recommendation manager 110, such as a local area network, a wide area network, or the like. In some embodiments, the network 102 may be the Internet.
[0019] The term SIEMS may refer to a software tool and / or service that combines the management of security information and the management of security events, i.e., security incidents. As such, the SIEMS 104 can analyze logs 112 generated by a computer system and / or a computer network or both to identify potential security incidents in real time.
[0020] Typically, a security analyst can identify threats to these systems by analyzing transactions, i.e., events that occur in a network computer system, which are recorded in the logs 112. However, due to the volume of the logs 112, it can be difficult for a security analyst to process the log data in its raw format in a timely manner to mitigate any potential damage. Therefore, the SIEMS 104 can process these logs 112 in a process called event normalization and categorization, whereby the SIEMS generates attacks that can be verified by a human security analyst. An attack is an event that the SIEMS identifies as a potential security incident.
[0021] The action model 106 can be a machine learning model trained to recommend a list of actions to be taken against a target or potential target to prevent or mitigate or both the damage from a security incident. In some embodiments of the present disclosure, the action model 106 includes ticket data 116. The ticket data 116 can be an index of security incidents for the recommended actions and additional context that the action model 106 constructs during training.
[0022] The collaborative filtering model 108 can be a machine learning model trained to weight the similarities between targets of security incidents. The similarity can be determined based on organizational factors of the targets, such as size, and in some cases, shared technical infrastructure components, etc. The similarity can be represented by a numerical expression between 0 and 1. 0 represents no similarity, and 1 represents complete similarity.
[0023] The recommendation manager 110 can be a system that provides security recommendations having steps that are meaningful and actionable (both mitigation and prevention), relevant to its environment, and that have worked in the past to remediate similar threats for similar targets. Depending on the level of confidence provided by the recommendation manager 110 for confirmation, the security recommendations can be automatically sent to the client or to the analyst. In this way, the recommendation manager 110 can reduce the cost and time that security analysts spend on investigating and constructing the recommended actions, and provide benefits to the client, which is the target or potential target of the security incident.
[0024] The recommendation manager 110 may include incident data 114 and target data 118. The incident data 114 may be collected from the logs 112 when the SIEMS 104 reports a security incident. The incident data 114 may include details such as when the security incident occurred, what the targeted organization is, which SIEMS rules were triggered by the security incident, which computer assets and / or network assets were involved and affected by the security incident, etc. In some embodiments of the present disclosure, the recommendation manager 110 can train the action model 106 using the incident data 114. Further, the recommendation manager 110 can loop back the training to the action model 106.
[0025] The target data 118 may represent information about the organizations that were the targets of past security incidents. The target data 118 may describe these targets both organizationally and technically. For example, the target data 118 may include characteristics such as size, industry, infrastructure, infrastructure components, and servers. These characteristics may be relevant to security incident response because how much security control an organization implements may vary based on these characteristics.
[0026] In this way, the recommendation manager 110 can repair a specific security incident by predicting the applicability of a group of cybersecurity actions by leveraging a machine learning regression model. In addition, the recommendation manager 110 can identify clients with similar attributes by leveraging a collaborative filtering model 108 incorporating a weighted alternating least squares (WALS) algorithm. These attributes can include, for example, size, industry, and infrastructure components. In addition, the recommendation manager 110 can evaluate the factors of repair actions for similar cyber incidents that were beneficial to other similar clients. In addition, the recommendation manager 10 can utilize a perspective in time analysis based on whether the actions taken for a specified cyber incident were validated as valid at that time. Furthermore, some actions may take longer to implement than other actions. Therefore, the recommendation manager 110 can prioritize short-term actions to be taken when an attack is critical and urgent based on that point in time when a security incident occurs. Furthermore, the recommendation manager 110 can consider the confidence score of the resulting actions taken in order of priority.
[0027] In this way, the recommendation manager 110 can help save the time and cost for security experts to attempt to customize a recommended list of actions to take in response to a security incident. Furthermore, the recommendation manager 110 can prevent a client from receiving a cookie-cutter type of response. This is because the recommendations from the recommendation manager 110 can use responses tailored for individual customers, thus increasing customer satisfaction and retention. Therefore, the recommendation manager 110 can provide the client with customized customer-related actions. In addition, the recommendation manager 110 can provide a correlation with a wide perspective of the industry that may fail to be identified by human analysis.
[0028] Figure 2 is a process flow diagram of an exemplary method 200 for making security recommendations according to some embodiments of the present disclosure. A recommendation manager, such as recommendation manager 110, may execute method 200.
[0029] In operation 202, the recommendation manager 110 may train the action model 106 to determine a list of actions recommended based on security incidents. Training the action model 106 may involve generating ticket data 116 by collecting investigation data on past security incidents, the actions taken by the target, and the outcomes of the actions taken. Such information may be collected in the ticket data 116. Thus, the trained action model 106 can determine a set of recommended actions to take based on the investigation details of future security incidents.
[0030] In operation 204, the recommendation manager 110 may train the collaborative filtering model 108 to identify similar targets that take similar actions. Training the collaborative filtering model 108 may involve grouping similar targets using collaborative filtering based on various target characteristics such as, for example, size, industry, infrastructure, infrastructure components, and servers, because companies may implement security controls differently based on these characteristics. Thus, the collaborative filtering model 108 can grade the similarity between a certain target and multiple targets in the training data based on the documented characteristics.
[0031] In operation 206, the recommendation manager 110 may generate a prioritized list of recommended actions to take with respect to a target in response to a security incident. In some embodiments of the present disclosure, the recommendation manager 110 may weight the similarity of other targets taking actions recommended by the action model 106 using the collaborative filtering model 108. In some embodiments of the present disclosure, the action model 106 may further weight the recommended actions based on whether the action was successful.
[0032] FIG. 3 is a process flow diagram of an exemplary method 300 for making security recommendations according to some embodiments of the present disclosure. A recommendation manager, such as the recommendation manager 110, may execute method 300.
[0033] In operation 302, the recommendation manager 110 may determine a list of actions based on a security incident and using an action model, such as the action model 106 described with respect to FIG. 1. The list of actions may include, for example, actions taken and outcomes. In some embodiments of the present disclosure, the recommendation manager 110 may input investigation data of a security incident through a trained regression model, such as the action model 106, even before a security analyst starts an operation. In this way, the security analyst may extend the operation of the recommendation manager 110.
[0034] In operation 304, the recommendation manager 110 may weight the list of actions based on the target using the collaborative filtering model 108. According to some embodiments of the present disclosure, the recommendation manager 110 may execute the target data 118 through the collaborative filtering model 108 to determine a confidence value regarding the similarity of other targets in past security incidents. In addition, the recommendation manager 110 may correlate the determined list of actions from the action model 106 with the actions taken by similar targets. Thus, if an action from the determined list is executed by a similar target, the recommendation manager 110 may apply a weighted value to the action that indicates the similarity of the target to past targets. Further, if the recommendation manager 110 determines that a particular action has been validated or a particular action has been successful, or both, the recommendation manager may weight the action with a higher value than if the action had failed.
[0035] In operation 306, the recommendation manager 110 may further weight the list of actions based on the timing of the security incident. In some scenarios, the timing may indicate whether the incidence rate of security incidents is increasing near holidays and commemorative days, etc. Thus, in some embodiments of the present disclosure, the recommendation manager 110 may further weight the list of actions based on the timing at which the action that triggered method 300 has been taken. Thus, if a past security incident in which an action was taken occurred at a different time than the current security incident, the recommendation manager 110 may reduce the weighting. Similarly, if the timing is within a predetermined time threshold, the recommendation manager 110 may increase the weighting.
[0036] In operation 308, the recommendation manager 110 may generate a prioritized list of recommended actions based on the weighted list of actions. The prioritized list may include weighted results and recommendations based on the possible outcomes. In other words, the prioritized list may be a weighted list of actions and outcomes. The priority of an action correlates with its cumulative weight. The cumulative weight may be based on past success, similarity to past targets, and timing, etc. Thus, the most prioritized is the action with a relatively highest cumulative weight, and ultimately the lowest prioritized is the action with a relatively lowest weight. In some embodiments of the present disclosure, the prioritized list may indicate the success rate of actions taken by similar clients.
[0037] FIG. 4 is a data flow diagram of a process 400 for making recommendations according to some embodiments of the present disclosure. In process 400, a SIEMS such as SIEMS 104 may generate a security incident 402. The security incident 402 may indicate malicious activity against a client's network. Thus, the security incident 402 can generate incident data 404. The incident data 404 may be similar to the incident data 114 described with respect to FIG. 1. Referring to FIG. 4 again, in response to the security incident 402, the recommendation manager 110 may input the incident data 404 into a recommendation model 406. The recommendation model 406 may be similar to the action model 106. Additionally, the recommendation model 406 may include previous tickets 408. The previous tickets 408 may be similar to the ticket data 116. Thus, the recommendation model 406 can provide a list of recommended actions based on the incident data 404 of the security incident 402. The list of recommended actions may be input into a process called action cross-reference target 414, which will be described in more detail below.
[0038] In addition to providing incident data 404 to the recommendation model 406, the recommendation manager 110 may input the incident data 404 into a collaborative filtering model 410. The collaborative filtering model 410 may be similar to the collaborative filtering model 108. Additionally, the collaborative filtering model 410 may include previous targets 412. The previous targets 412 may be data about the targets of security incidents and may be similar to the target data 118. In response to the incident data 404, the collaborative filtering model 410 can generate a list of targets similar to the targets of the security incident 402 and corresponding numerical weight values indicating similarity on a scale from 0 to 100%. Additionally, the recommendation manager 110 may input the list of similar targets into a process called the action cross-reference target 414.
[0039] In the action cross-reference target 414, the recommendation manager 110 may identify the actions recommended by the recommendation model 406 that were executed by similar targets from the collaborative filtering model 410. Additionally, the recommendation manager 110 may assign the weight values of such targets to the corresponding actions. Further, the recommendation manager 110 can further weight the recommended actions based on whether past results were successful. Thus, the recommendation manager 110 can generate a prioritized list 420 of recommended actions sorted based on the weights assigned to each.
[0040] Thus, the action cross-reference target 414 can generate a weighted list of recommended actions for input into a process called the timing analysis 416. The timing analysis 416 may involve the recommendation manager 110 further weighting the recommended actions based on the timing of past actions and the timing of the current security incident 402.
[0041] FIG. 5 is a block diagram of an exemplary recommendation manager 500 according to some embodiments of the present disclosure. In various embodiments, the recommendation manager 500 is similar to the recommendation manager 110 and can perform the methods described in FIGS. 2 and 3 or the functions described in FIGS. 1 and 4 or both. In some embodiments, the recommendation manager 500 provides instructions for the foregoing methods or functions or both to a client machine such that the client machine executes the method or a part of the method based on the instructions provided by the recommendation manager 500. In some embodiments, the recommendation manager 500 includes software executed on hardware incorporated in a plurality of devices.
[0042] The recommendation manager 500 includes a memory 525, a storage 530, an interconnect (e.g., a bus) 520, one or more CPUs 505 (also referred to herein as processors 505), an I / O device interface 510, an I / O device 512, and a network interface 515.
[0043] Each CPU 505 fetches and executes program instructions stored in memory 525 or storage 530. The interconnect 520 is used to move data such as program instructions between the CPU 505, I / O devices, interface 510, storage 530, network interface 515, and memory 525. The interconnect 520 can be implemented using one or more buses. The CPU 505 can be, in various embodiments, a single CPU, multiple CPUs, or a single CPU having multiple processing cores. In some embodiments, the CPU 505 can be a digital signal processor (DSP). In some embodiments, the CPU 505 includes one or more 3D integrated circuits (3DICs) (e.g., 3D wafer level package (3DWLP), 3D interposer-based integration, 3D stacked IC (3D-SIC), monolithic 3DIC, 3D heterogeneous integration, 3D system in package (3DSiP) or package on package (PoP) or a CPU configuration by a combination thereof). Memory 525 is generally included to represent random access memory (e.g., static random access memory (SRAM), dynamic random access memory (DRAM), or flash). Storage 530 is generally included to represent non-volatile memory such as a hard disk drive, solid state device (SSD), removable memory card, optical storage, or flash memory device or a combination thereof. Additionally, storage 530 can include a storage area network (SAN) device, cloud, or other devices connected to the recommendation manager 500 via the I / O device interface 510 or to the network 550 via the network interface 515.
[0044] In some embodiments, the memory 525 stores the instructions 560. However, in various embodiments, the instructions 560 may be stored partially in the memory 525 and partially in the storage 530, or entirely in the memory 525, or entirely in the storage 530, or accessed on the network 550 via the network interface 515.
[0045] The instructions 560 can be processor-executable instructions for performing any part or all of the methods described in FIGS. 2 and 3 or the functions described in FIGS. 1 and 4 or both.
[0046] In various embodiments, the I / O device 512 includes an interface capable of presenting information and receiving input. For example, the I / O device 512 can present information to a listener that interacts with the recommendation manager 500 and receive input from the listener.
[0047] The recommendation manager 500 is connected to the network 550 via the network interface 515. The network 550 can include a physical network, a wireless network, a cellular network, or different networks.
[0048] In some embodiments, the recommendation manager 500 can be a multi-user mainframe computer system, a single-user system, or a server computer or similar device that has little or no direct user interface but receives requests from other computer systems (clients). Further, in some embodiments, the recommendation manager 500 can be implemented as a desktop computer, a portable computer, a laptop or notebook computer, a tablet computer, a pocket computer, a telephone, a smartphone, a network switch or router, or any other suitable type of electronic device.
[0049] Note that FIG. 5 is intended to show representative major components of an exemplary recommendation manager 500. However, in some embodiments, individual components may have a higher or lower complexity than that represented in FIG. 5, there may be components other than or in addition to those shown in FIG. 5, and the number, type, and configuration of such components may vary.
[0050] Although this disclosure includes a detailed description regarding cloud computing, the implementation of the teachings described herein is not limited to a cloud computing environment. Rather, embodiments of this disclosure can be implemented in conjunction with any other type of computing environment now known or later developed.
[0051] Cloud computing is a service delivery model that enables convenient on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that can be rapidly provisioned and released with minimal management effort or interaction with a service provider. This cloud model can include at least five characteristics, at least three service models, and at least four deployment models.
[0052] The characteristics are as follows.
[0053] On-demand self-service: A cloud consumer can unilaterally provision computing capabilities, such as server time and network storage, as needed, automatically, without requiring human interaction with a service provider.
[0054] Broad network access: The functionality is available over a network and accessed through a standard mechanism that facilitates use by heterogeneous mix of thin client platforms or thick client platforms (e.g., mobile phones, laptops, and PDAs).
[0055] Resource pooling: The provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, and different physical and virtual resources are dynamically assigned and re-assigned according to demand. Generally, consumers have no control or knowledge over the exact location of the resources provided, but have a sense of location independence in that they can specify a location at a higher level of abstraction (e.g., country, state, or data center).
[0056] Rapid elasticity: The functionality can be provisioned quickly and elastically, in some cases automatically, so as to scale out rapidly and released quickly so as to scale in. To the consumer, the functionality available for provisioning often appears limitless and any amount can be purchased at any point in time.
[0057] Measured service: The cloud system automatically controls and optimizes resource use by leveraging a metering function at an appropriate level of abstraction for the type of service (e.g., storage, processing, bandwidth, and active user accounts). Transparency is provided to both the provider and consumer of the utilized service by enabling the use of resources to be monitored, controlled, and reported.
[0058] The service model is as follows.
[0059] Software as a Service (SaaS): The functionality provided to the consumer is to use the provider's application that runs on a cloud infrastructure. This application is accessible from various client devices through a client interface such as a web browser (e.g., web-based email). With limited exceptions for user-specific application configuration settings, the consumer does not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, storage, or even individual application functionality.
[0060] Platform as a Service (PaaS): The functionality provided to the consumer is to deploy on a cloud infrastructure an application created or obtained by the consumer, using programming languages and tools supported by the provider. The consumer does not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, or storage, but has control over the deployed application and, in some cases, the application hosting environment configuration.
[0061] Infrastructure as a Service (IaaS): The functionality provided to the consumer is to provision processing, storage, network, and other basic computing resources that the consumer can deploy and run software, which may include operating systems and applications. The consumer does not manage or control the underlying cloud infrastructure, but has control over the operating systems, storage, deployed applications, and, in some cases, limited control over selected network components (e.g., host firewalls).
[0062] The deployment models are as follows.
[0063] Private Cloud: The cloud infrastructure is operated for the sole use of an organization. The private cloud may be managed by the organization or a third party and may exist on-premises or off-premises.
[0064] Community Cloud: The cloud infrastructure is shared by several organizations and supports a specific community that shares concerns (e.g., mission, security requirements, policies, and compliance considerations). The private cloud may be managed by these organizations or a third party and may exist on-premises or off-premises.
[0065] Public Cloud: The cloud infrastructure is made available to the general public or a large industry group and is owned by an organization that sells cloud services.
[0066] Hybrid Cloud: The cloud infrastructure remains a distinct entity but is a composite of two or more clouds (private, community, or public) that are bound together by standard or proprietary technologies (e.g., cloud bursting for load balancing between clouds) that enable data and application portability.
[0067] Cloud computing environments are service-oriented, with an emphasis on statelessness, loose coupling, modularity, and semantic interoperability. At the heart of cloud computing is an infrastructure that includes a network of interconnected nodes.
[0068] FIG. 6 is a cloud computing environment 610 according to some embodiments of the present disclosure. As shown, the cloud computing environment 610 includes one or more cloud computing nodes 600. The cloud computing nodes 600 can execute the methods described in FIGS. 2 and 3, the functions described in FIGS. 1 and 4, or both. In addition, the cloud computing nodes 600 can communicate with local computing devices used by cloud consumers, such as, for example, a personal digital assistant (PDA) or a mobile phone 600A, a desktop computer 600B, a laptop computer 600C, or an automotive computer system 600N, or a combination thereof. Further, the cloud computing nodes 600 can communicate with each other. Also, the cloud computing nodes 600 can be physically or virtually grouped (not shown) in one or more networks, such as the private cloud, community cloud, public cloud, or hybrid cloud described above, or a combination thereof. Thereby, the cloud computing environment 610 can provide infrastructure, platform, software, or a combination thereof, as a service such that a cloud consumer does not need to maintain resources on a local computing device. The types of computing devices 600A-N shown in FIG. 6 are only intended to be exemplary, and it should be understood that the computing nodes 600 and the cloud computing environment 610 can communicate with any type of computerized device via any type of network or network addressable connection, or both (e.g., using a web browser).
[0069] FIG. 7 is a set of function abstraction model layers provided by a cloud computing environment 610 (FIG. 6) according to some embodiments of the present disclosure. It should be understood in advance that the components, layers, and functions shown in FIG. 7 are for illustrative purposes only, and embodiments of the present disclosure are not limited thereto. As shown below, the following layers and corresponding functions are provided.
[0070] The hardware and software layer 700 includes hardware components and software components. Examples of hardware components include mainframe 702, RISC (Reduced Instruction Set Computer) architecture-based server 704, server 706, blade server 708, storage device 710, and network and network components 712. In some embodiments, the software components include network application server software 714 and database software 716.
[0071] The virtualization layer 720 provides an abstraction layer from which the following examples of virtual entities can be provided: virtual server 722, virtual storage 724, virtual network 726 including a virtual private network, virtual applications and operating systems 728, and virtual client 730.
[0072] In one example, the management layer 740 may provide the functions described below. Resource provisioning 742 provides for the dynamic procurement of computing resources and other resources utilized to execute tasks within a cloud computing environment. Metering and pricing 744 provides for cost tracking when resources are utilized within a cloud computing environment and for billing or charging for consumption of these resources. In one example, these resources may include application software licenses. Security provides for protection of data and other resources in addition to verification of identification information about cloud consumers and tasks. The user portal 746 provides access to the cloud computing environment for consumers and system administrators. Service level management 748 provides for the allocation and management of cloud computing resources such that the required service levels are met. Service level management 748 may allocate appropriate processing capabilities and memory for processing static sensor data. Service level agreement (SLA) planning and fulfillment 750 provides for the pre - preparation and procurement of cloud computing resources where future requirements are anticipated to conform to the SLA.
[0073] The workload layer 760 provides examples of functions that a cloud computing environment may utilize. Examples of workloads and functions that may be provided from this layer include mapping and navigation 762, software development and lifecycle management 764, virtual classroom education delivery 766, data analytics processing 768, transaction processing 770, as well as recommendation manager 772.
[0074] The present disclosure may be a system, method, or computer program product, or any combination thereof, at any possible technical detail integration level. The computer program product may include one (or more) computer - readable storage media having computer - readable program instructions for causing a processor to execute aspects of the present disclosure.
[0075] A computer-readable storage medium can be a tangible device that holds and stores instructions for use by an instruction execution device. A computer-readable storage medium can be, for example, but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive listing of more specific examples of computer-readable storage media includes a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM) or flash memory, a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disc (DVD), a memory stick, a floppy disk, a punch card, or a mechanically encoded device such as a raised structure within a groove in which instructions are recorded, and any suitable combination of the foregoing. A computer-readable storage medium as used herein should not be construed as a transitory signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., an optical pulse passing through an optical fiber cable) or an electrical signal transmitted through a wire.
[0076] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to respective computing / processing devices, or to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, or a wireless network, or a combination thereof. The network can include copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers, or edge servers, or a combination thereof. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and transfers the computer-readable program instructions for storage in a computer-readable storage medium within each respective computing / processing device.
[0077] Computer-readable program instructions for performing the operations of this disclosure may be source code or object code written in any combination of one or more programming languages, including, for example, assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, configuration data for integrated circuits, or object-oriented programming languages such as Smalltalk®, C++, Java® or Python, procedural programming languages such as the "C" programming language or similar programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), and connections to external computers (e.g., through the Internet using an Internet service provider) may also be made. In some embodiments, an electronic circuit, including, for example, a programmable logic circuit, a field programmable gate array (FPGA) or a programmable logic array (PLA), may utilize the state information of the computer-readable program instructions to execute the computer-readable program instructions to personalize the electronic circuit to perform aspects of this disclosure.
[0078] Aspects of the present disclosure are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the disclosure. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.
[0079] These computer-readable program instructions may be provided to a computer processor or other programmable data processing apparatus to produce a machine, such that the instructions executed via the computer processor or other programmable data processing apparatus create means for implementing the functions / operations specified in one or more blocks of a flowchart, a block diagram, or both. These computer-readable program instructions may also be stored in a computer-readable storage medium that can direct a computer, a programmable data processing apparatus, or other device or combination thereof to function in a particular manner, such that the computer-readable storage medium having instructions stored therein comprises a manufacture including instructions for implementing the manner of functions / operations specified in one or more blocks of a flowchart, a block diagram, or both.
[0080] Also, these computer-readable program instructions may be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus, or other device to produce a computer-implemented process, such that the instructions executed on the computer, other programmable apparatus, or other device implement the functions / operations specified in one or more blocks of a flowchart, a block diagram, or both.
[0081] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, segment, or portion of instructions that comprises one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be accomplished as one step, executed simultaneously, substantially simultaneously, partially, or wholly in a temporally overlapping manner, and these blocks may be executed in the reverse order depending upon the functionality involved. It should also be noted that each block of the block diagrams or flowchart diagrams, or combinations of blocks in the block diagrams or flowchart diagrams or both, can be implemented by a dedicated hardware-based system that performs the specified function or operation, or a combination of dedicated hardware and computer instructions.
Claims
1. A computer-implemented method, comprising: determining, using an action model trained to make recommendations, a plurality of recommended actions based on security incidents identified by a security information and event management (SIEM) system, determining a plurality of similar targets of a potential target of the security incident, wherein the similar targets and the potential target include a computer communication network infrastructure, and using a collaborative filtering model trained to assign a similarity confidence value between an organization including a first network infrastructure and the potential target, the similarity confidence value indicating similarity in one or more shared characteristics, and the similar targets being determinable based on organizational factors of the similar targets and the potential target; generating, using the action model, a plurality of actions taken by the similar targets; one or more actions taken by the plurality of similar targets and the confidence value, and success or failure of the recommended action assigning a plurality of weights to the actions based thereon; generating a prioritized list of the recommended actions sorted based on the assigned plurality of weights. A method comprising the above steps.
2. The method of claim 1, wherein the step of assigning the plurality of weights further comprises based on the timing of the security incident and the timing of the recommended action.
3. The method of claim 1 or 2, further comprising generating a prioritized list of the recommended actions that includes a success rate of one or more of the recommended actions.
4. The method according to any one of claims 1 to 3, further comprising determining that one of the plurality of similar targets has performed one of the recommended actions.
5. The method of claim 4, further comprising assigning the confidence value of the one similar target to the one recommended action.
6. The method according to any one of claims 1 to 5, wherein the action model includes a regression model.
7. The method according to any one of claims 1 to 6, wherein the collaborative filtering model identifies the plurality of similar targets using weighted alternating least squares.
8. The method according to any one of claims 1 to 7, wherein one of the recommended actions includes a short-term action prioritized based on the security incident that is important based on the time point at which the security incident occurred.
9. A procedure for a processor to determine a plurality of recommended actions based on security incidents identified by a security information and event management (SIEMS) system, using an action model trained to make recommendations, a procedure for determining a plurality of similar targets of potential targets of the security incident, wherein the similar targets and the potential targets include a computer communication network infrastructure, and using a collaborative filtering model trained to assign a similarity confidence value between an organization including a first network infrastructure and the potential target, the similarity confidence value indicating similarity in one or more shared characteristics, and the similar targets can be determined based on organizational factors of the similar targets and the potential targets, a procedure for generating a plurality of actions taken by the similar targets using the action model; one or more actions taken by the plurality of similar targets and the confidence value, and the success or failure of the recommended action a procedure for assigning a plurality of weights to the actions based on; a procedure for generating a prioritized list of the recommended actions sorted based on the assigned plurality of weights, the procedure comprising: A computer program for causing execution.
10. The processor is caused to further execute a procedure for generating a prioritized list of the recommended actions, including the success rate of one or more of the recommended actions, the computer program according to claim 9.
11. The processor is caused to The computer program according to claim 9 or 10, further causing one of the plurality of similar targets to execute a further procedure of determining that one of the recommended actions has been executed.
12. The processor is further caused to The computer program according to claim 11, further causing a procedure of assigning the reliability value of the one similar target to the one recommended action.
13. The computer program according to any one of claims 9 to 12, wherein the action model includes a regression model.
14. The computer program according to any one of claims 9 to 13, wherein the collaborative filtering model uses weighted alternating least squares to identify the plurality of similar targets.
15. The computer program according to any one of claims 9 to 14, wherein one of the recommended actions includes a short-term action prioritized based on the security incident that is important based on the time point when the security incident occurred.
16. One or more computer processing circuits, One or more computer-readable storage media storing instructions A system comprising: When the instructions are executed by the one or more computer processing circuits, Determining a plurality of recommended actions based on security incidents identified by a security information and event management (SIEMS) system using an action model trained to make recommendations, Determining a plurality of similar targets of potential targets of the security incident, wherein the similar targets and the potential targets include a computer communication network infrastructure, and using a collaborative filtering model trained to assign a similarity reliability value between an organization including a first network infrastructure and the potential target, the similarity reliability value indicating similarity in one or more shared characteristics, and the similar targets can be determined based on organizational factors of the similar targets and the potential targets, Generating, using the action model, a plurality of actions that the similar targets take one or more actions taken by the plurality of similar targets, and the confidence value, and the success or failure of the recommended action assigning a plurality of weights to the actions based on generating a ranked list of the recommended actions sorted based on the plurality of assigned weights, including configured to cause the one or more computer processing circuits to execute a method comprising system
17. The method determining that one of the plurality of similar targets has executed one of the recommended actions assigning the confidence value of the one similar target to the one recommended action further comprising The system according to claim 16
18. The system according to claim 16 or 17, wherein the action model includes a regression model
19. The system according to any one of claims 16 to 18, wherein the collaborative filtering model identifies the plurality of similar targets using weighted alternating least squares
20. The system according to any one of claims 16 to 19, wherein one of the recommended actions includes a short-term action prioritized based on a security incident that is important based on the time at which the security incident occurred
21. A computer-implemented method comprising determining a plurality of recommended actions based on security incidents identified by a security information and event management (SIEMS) system using an action model trained to make recommendations determining a plurality of similar targets of potential targets of the security incident, wherein the similar targets and the potential targets include a computer communication network infrastructure, using a collaborative filtering model trained to assign a confidence value of similarity between an organization including a first network infrastructure and the potential target, the confidence value of similarity indicating similarity in one or more shared characteristics, and the similar targets being determinable based on organizational factors of the similar targets and the potential targets generating, using the action model, a plurality of actions taken by the similar targets; one or more actions taken by the plurality of similar targets and the confidence value, the success or failure of the recommended action, and the timing of the security incident and the timing of the recommended action assigning a plurality of weights to the actions based on; generating a ranked list of the recommended actions sorted based on the assigned plurality of weights, the ranked list of the recommended actions including the success rate of one or more of the recommended actions; A method comprising:
22. determining that one of the plurality of similar targets has executed one of the recommended actions; assigning the confidence value of the one similar target to the one recommended action; The method according to claim 21, further comprising:
23. The method according to claim 21 or 22, wherein the action model includes a regression model.
24. A procedure for a processor to determine a plurality of recommended actions based on security incidents identified by a Security Information and Event Management (SIEMS) system using an action model trained to make recommendations, wherein the method further comprises: determining a plurality of similar targets of potential targets of the security incident, the similar targets and the potential targets including a computer communication network infrastructure, using a collaborative filtering model trained to assign a confidence value of similarity between an organization including a first network infrastructure and the potential target, the confidence value of similarity indicating similarity in one or more shared characteristics, and the similar targets being determinable based on organizational factors of the similar targets and the potential targets; generating, using the action model, a plurality of actions taken by the similar targets; one or more actions taken by the plurality of similar targets and the confidence value, the success or failure of the recommended action, and The timing of the security incident and the timing of the recommended action Based on, a procedure for assigning a plurality of weights to the action, and Generating a ranked list of the recommended actions sorted based on the plurality of assigned weights, wherein the ranked list of the recommended actions includes the success rate of one or more of the recommended actions, the procedure for generating, including the procedure, A computer program for causing the execution.
25. The collaborative filtering model uses weighted alternating least squares to identify the plurality of similar targets, the computer program according to claim 24.
Citation Information
Patent Citations
Information processing device, information processing method and information processing program
JP2019028891A
Security incident visualization system
JP2020161017A
Security systems and methods
WO2020124026A1