Modifying incident response time periods based on containment action effectiveness

    公开(公告)号:US11190539B2

    公开(公告)日:2021-11-30

    申请号:US16699299

    申请日:2019-11-29

    Applicant: Splunk Inc.

    Abstract: Systems, methods, and software described herein provide for managing service level agreements (SLAs) for security incidents in a computing environment. In one example, an advisement system identifies a rule set for a security incident based on enrichment information obtained for the security incident, wherein the rule set is associated with action recommendations to be taken against the incident. The advisement system further identifies a default SLA for the security incident based on the rule set, and obtains environmental characteristics related to the security incident. Based on the environmental characteristics, the advisement system determines a modified SLA for the security incident.

    SELECTING ACTIONS RESPONSIVE TO COMPUTING ENVIRONMENT INCIDENTS BASED ON SEVERITY RATING

    公开(公告)号:US20210314347A1

    公开(公告)日:2021-10-07

    申请号:US17185612

    申请日:2021-02-25

    Applicant: Splunk Inc.

    Abstract: Systems, methods, and software described herein provide enhancements for implementing security actions in a computing environment. In one example, a method of operating an advisement system to provide actions in a computing environment includes identifying a security incident in the computing environment, identifying a criticality rating for the asset, and obtaining enrichment information for the security incident from one or more internal or external sources. The method also provides identifying a severity rating for the security incident based on the enrichment information, and determining one or more security actions based on the enrichment information. The method further includes identifying effects of the one or more security actions on operations of the computing environment based on the criticality rating and the severity rating, and identifying a subset of the one or more security actions to respond to the security incident based on the effects.

    PROVIDING ACTION RECOMMENDATIONS BASED ON ACTION EFFECTIVENESS ACROSS INFORMATION TECHNOLOGY ENVIRONMENTS

    公开(公告)号:US20210281601A1

    公开(公告)日:2021-09-09

    申请号:US17326070

    申请日:2021-05-20

    Applicant: Splunk Inc.

    Abstract: Systems, methods, and software described herein provide action recommendations to administrators of a computing environment based on effectiveness of previously implemented actions. In one example, an advisement system identifies a security incident for an asset in the computing environment, and obtains enrichment information for the incident. Based on the enrichment information a rule set and associated recommended security actions are identified for the incident. Once the recommended security actions are identified, a subset of the action recommendations are organized based on previous action implementations in the computing environment, and the subset is provided to an administrator for selection.

    Dynamically updating feature set recommendation databases

    公开(公告)号:US10904295B2

    公开(公告)日:2021-01-26

    申请号:US16817070

    申请日:2020-03-12

    Applicant: Splunk Inc.

    Abstract: Systems, methods, and software described herein provide for identifying recommended feature sets for new security applications. In one example, a method of providing recommended feature sets for a new security application includes identifying a request for the new security application, and determining a classification for the new security application. The method further provides identifying related applications to the new security application based on the classification, and identifying a feature set for the new security application based on features provided in the related applications.

    Management of actions in a computing environment based on asset classification

    公开(公告)号:US10855718B2

    公开(公告)日:2020-12-01

    申请号:US16042283

    申请日:2018-07-23

    Applicant: Splunk Inc.

    Abstract: Systems, methods, and software described herein provide for responding to security threats in a computing environment based on the classification of computing assets in the environment. In one example, a method of operating an advisement computing system includes identifying a security threat for an asset in the computing environment, and identifying a classification for the asset in relation to other assets within the computing environment. The method further provides determining a rule set for the security threat based on the classification for the asset and initiating a response to the security threat based on the rule set.

Patent Agency Ranking