- 专利标题: Ranking cybersecurity alerts from multiple sources using machine learning
-
申请号: US17239426申请日: 2021-04-23
-
公开(公告)号: US11956253B1公开(公告)日: 2024-04-09
- 发明人: Derek Lin , Domingo Mihovilovic , Sylvain Gil
- 申请人: Exabeam, Inc.
- 申请人地址: US CA Foster City
- 专利权人: Exabeam, Inc.
- 当前专利权人: Exabeam, Inc.
- 当前专利权人地址: US CA Foster City
- 代理机构: Lessani Law Group, PC
- 主分类号: H04L9/40
- IPC分类号: H04L9/40 ; G06N5/04 ; G06N20/00
摘要:
The present disclosure relates to a machine-learning system, method, and computer program for ranking security alerts from multiple sources. The system self-learns risk levels associated with alerts by calculating risk probabilities for the alerts based on characteristics of the alerts and historical alert data. In response to receiving a security alert from one of a plurality of alert-generation sources, the alert-ranking system evaluates the security alert with respect to a plurality of feature indicators. The system creates a feature vector for the security alert based on the feature indicator values identified for the alert. The system then calculates a probability that the security alert relates to a cybersecurity risk in the computer network based on the created feature vector and historical alert data in the network. The system ranks alerts from a plurality of different sources based on the calculated cybersecurity risk probabilities.
信息查询