- 专利标题: Selecting actions responsive to computing environment incidents based on severity rating
-
申请号: US17185612申请日: 2021-02-25
-
公开(公告)号: US11765198B2公开(公告)日: 2023-09-19
- 发明人: Sourabh Satish , Oliver Friedrichs , Atif Mahadik , Govind Salinas
- 申请人: Splunk Inc.
- 申请人地址: US CA San Francisco
- 专利权人: Splunk Inc.
- 当前专利权人: Splunk Inc.
- 当前专利权人地址: US CA San Francisco
- 代理机构: NICHOLSON DE VOS WEBSTER & ELLIOTT LLP
- 主分类号: H04L9/40
- IPC分类号: H04L9/40 ; G06F21/55 ; G06F16/28 ; H04L47/2425
摘要:
Systems, methods, and software described herein provide enhancements for implementing security actions in a computing environment. In one example, a method of operating an advisement system to provide actions in a computing environment includes identifying a security incident in the computing environment, identifying a criticality rating for the asset, and obtaining enrichment information for the security incident from one or more internal or external sources. The method also provides identifying a severity rating for the security incident based on the enrichment information, and determining one or more security actions based on the enrichment information. The method further includes identifying effects of the one or more security actions on operations of the computing environment based on the criticality rating and the severity rating, and identifying a subset of the one or more security actions to respond to the security incident based on the effects.
公开/授权文献
信息查询