MODIFYING INCIDENT RESPONSE TIME PERIODS BASED ON CONTAINMENT ACTION EFFECTIVENESS

    公开(公告)号:US20200213348A1

    公开(公告)日:2020-07-02

    申请号:US16699299

    申请日:2019-11-29

    Applicant: Splunk Inc.

    Abstract: Systems, methods, and software described herein provide for managing service level agreements (SLAs) for security incidents in a computing environment. In one example, an advisement system identifies a rule set for a security incident based on enrichment information obtained for the security incident, wherein the rule set is associated with action recommendations to be taken against the incident. The advisement system further identifies a default SLA for the security incident based on the rule set, and obtains environmental characteristics related to the security incident. Based on the environmental characteristics, the advisement system determines a modified SLA for the security incident.

    Determining security actions for security threats using enrichment information

    公开(公告)号:US10567424B2

    公开(公告)日:2020-02-18

    申请号:US16107979

    申请日:2018-08-21

    Applicant: Splunk Inc.

    Abstract: Systems, methods, and software described herein provide security actions based on the current state of a security threat. In one example, a method of operating an advisement system in a computing environment with a plurality of computing assets includes identifying a security threat within the computing environment. The method further includes, in response to identifying the security threat, obtaining state information for the security threat within the computing environment, and determining a current state for the security threat within the computing environment. The method also provides obtaining enrichment information for the security threat and determining one or more security actions for the security threat based on the enrichment information and the current state for the security threat.

    SELECTING ACTIONS RESPONSIVE TO COMPUTING ENVIRONMENT INCIDENTS BASED ON ACTION IMPACT INFORMATION

    公开(公告)号:US20200007574A1

    公开(公告)日:2020-01-02

    申请号:US16568949

    申请日:2019-09-12

    Applicant: Splunk Inc.

    Abstract: Systems, methods, and software described herein provide enhancements for implementing security actions in a computing environment. In one example, a method of operating an advisement system to provide actions in a computing environment includes identifying a security incident in the computing environment, identifying a criticality rating for the asset, and obtaining enrichment information for the security incident from one or more internal or external sources. The method also provides identifying a severity rating for the security incident based on the enrichment information, and determining one or more security actions based on the enrichment information. The method further includes identifying effects of the one or more security actions on operations of the computing environment based on the criticality rating and the severity rating, and identifying a subset of the one or more security actions to respond to the security incident based on the effects.

    Determination of decision step logic for incident response in an information technology environment

    公开(公告)号:US11995571B1

    公开(公告)日:2024-05-28

    申请号:US17961533

    申请日:2022-10-06

    Applicant: Splunk Inc.

    CPC classification number: G06N5/04 G06N5/02 G06Q10/06316 G06F8/34

    Abstract: Described herein are improvements for generating courses of action for an information technology (IT) environment. In one example, a method includes determining that a decision step occurs between a one step and two or more other steps of a first course of action associated with an incident type in the information technology environment. The method further includes determining possible outputs of the one step that, when used as input to the decision step, cause the first course of action to proceed from the decision step to respective steps of the two or more other steps. The method also includes incorporating logic into the decision step to direct the course of action to respective steps of the two or more other steps based on one or more of the possible outputs.

Patent Agency Ranking