- 专利标题: PROVIDING ACTION RECOMMENDATIONS BASED ON ACTION EFFECTIVENESS ACROSS INFORMATION TECHNOLOGY ENVIRONMENTS
-
申请号: US17326070申请日: 2021-05-20
-
公开(公告)号: US20210281601A1公开(公告)日: 2021-09-09
- 发明人: Sourabh Satish , Oliver Friedrichs , Atif Mahadik , Govind Salinas
- 申请人: Splunk Inc.
- 申请人地址: US CA San Francisco
- 专利权人: Splunk Inc.
- 当前专利权人: Splunk Inc.
- 当前专利权人地址: US CA San Francisco
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; G06F21/55 ; G06F16/28
摘要:
Systems, methods, and software described herein provide action recommendations to administrators of a computing environment based on effectiveness of previously implemented actions. In one example, an advisement system identifies a security incident for an asset in the computing environment, and obtains enrichment information for the incident. Based on the enrichment information a rule set and associated recommended security actions are identified for the incident. Once the recommended security actions are identified, a subset of the action recommendations are organized based on previous action implementations in the computing environment, and the subset is provided to an administrator for selection.
公开/授权文献
信息查询