SYSTEM TO LEVERAGE ACTIVE LEARNING FOR ALERT PROCESSING

    公开(公告)号:US20240370533A1

    公开(公告)日:2024-11-07

    申请号:US18313191

    申请日:2023-05-05

    Applicant: VMware, Inc.

    Abstract: A machine-learning (ML) platform at which alerts are received from endpoints and divided into a plurality of clusters, wherein a plurality of alerts in each of the clusters is labeled based on metrics of maliciousness determined at a security analytics platform, the plurality of alerts in each of the clusters representing a population diversity of the alerts, and wherein the ML platform is configured to execute on a processor of a hardware platform to: select an alert from a cluster for evaluation by the security analytics platform; transmit the selected alert to the security analytics platform, and then receive a determined metric of maliciousness for the selected alert from the security analytics platform; and based on the determined metric of maliciousness, label the selected alert and update a rate of selecting alerts from the cluster for evaluation by the security analytics platform.

Patent Agency Ranking