PLAYBOOK-BASED SECURITY INVESTIGATIONS USING A CARD SYSTEM FRAMEWORK

    公开(公告)号:US20190104137A1

    公开(公告)日:2019-04-04

    申请号:US15720357

    申请日:2017-09-29

    Abstract: Examples disclosed herein relate to playbook-based security investigations using a card system framework. Some of the examples enable receiving an indication that a playbook is selected for investigating a security alert object, the playbook comprising a plurality of cards, wherein a first object definition associated with the security alert object comprises a parameter, and wherein the playbook inherits a value of the parameter from the first object definition; causing a first card from the playbook to be displayed on a user interface, the first card comprising a first content tile that describes the security alert object; and causing a second card from the playbook to be displayed on the user interface, the second card comprising a second content tile that describes a second object, wherein a second object definition associated with the second object comprises the parameter inherited from the first object definition.

    Playbook-based security investigations using a card system framework

    公开(公告)号:US10812498B2

    公开(公告)日:2020-10-20

    申请号:US15720357

    申请日:2017-09-29

    Abstract: Examples disclosed herein relate to playbook-based security investigations using a card system framework. Some of the examples enable receiving an indication that a playbook is selected for investigating a security alert object, the playbook comprising a plurality of cards, wherein a first object definition associated with the security alert object comprises a parameter, and wherein the playbook inherits a value of the parameter from the first object definition; causing a first card from the playbook to be displayed on a user interface, the first card comprising a first content tile that describes the security alert object; and causing a second card from the playbook to be displayed on the user interface, the second card comprising a second content tile that describes a second object, wherein a second object definition associated with the second object comprises the parameter inherited from the first object definition.

    Security investigations using a card system framework

    公开(公告)号:US10599839B2

    公开(公告)日:2020-03-24

    申请号:US15720406

    申请日:2017-09-29

    Abstract: Examples disclosed herein relate to security investigations using a card system framework. Some of the examples enable presenting a first card on a user interface, the first card comprising a first content tile that describes a first security alert object that is associated with a first plurality of content items, the first plurality of content items comprising at least one of: a source host identifier, an Internet Protocol (IP) address, a severity level, a confidence level, an alert status, a user identifier, an alert type, an attack stage, a port, a protocol, and a geographical location; and in response to an indication that a first content item among the first plurality of content item is requested about the first security alert object, presenting a second card on the user interface, the second card comprising a second content tile that describes a second entity object that is associated with a second plurality of content items.

    CARD SYSTEM FRAMEWORK
    5.
    发明申请

    公开(公告)号:US20190102372A1

    公开(公告)日:2019-04-04

    申请号:US15720048

    申请日:2017-09-29

    Abstract: Examples disclosed herein relate to using a card system framework. Some of the examples enable receiving, via a user interface, an indication that a first content item is requested about a first object; in response to the indication that the first content item is requested about the first object, presenting a first card on the user interface, the first card comprising a first content tile that describes a second object that is associated with the first content item; receiving, via the user interface, an indication that a second content item is requested about the second object; and in response to the indication that the second content item is requested about the second object, presenting a second card on the user interface, the second card comprising a second content tile that describes a third object that is associated with the second content item.

Patent Agency Ranking