-
公开(公告)号:US20240370533A1
公开(公告)日:2024-11-07
申请号:US18313191
申请日:2023-05-05
Applicant: VMware, Inc.
Inventor: Shelly MEHTA , Lalit Prithviraj JAIN , Raghav BATTA , Jonathan James OLIVER
Abstract: A machine-learning (ML) platform at which alerts are received from endpoints and divided into a plurality of clusters, wherein a plurality of alerts in each of the clusters is labeled based on metrics of maliciousness determined at a security analytics platform, the plurality of alerts in each of the clusters representing a population diversity of the alerts, and wherein the ML platform is configured to execute on a processor of a hardware platform to: select an alert from a cluster for evaluation by the security analytics platform; transmit the selected alert to the security analytics platform, and then receive a determined metric of maliciousness for the selected alert from the security analytics platform; and based on the determined metric of maliciousness, label the selected alert and update a rate of selecting alerts from the cluster for evaluation by the security analytics platform.