Invention Grant
- Patent Title: Cybersecurity incident response and security operation system employing playbook generation through custom machine learning
-
Application No.: US15620439Application Date: 2017-06-12
-
Publication No.: US10439884B1Publication Date: 2019-10-08
- Inventor: Dario Valentino Forte , Michele Zambelli , Vojtech Letal
- Applicant: DFLabs S.p.A.
- Applicant Address: IT Milan
- Assignee: DFLABS S.P.A.
- Current Assignee: DFLABS S.P.A.
- Current Assignee Address: IT Milan
- Agency: Browdy and Neimark, P.L.L.C.
- Main IPC: H04L12/24
- IPC: H04L12/24 ; G06F21/62 ; H04L29/06 ; G06F3/0482

Abstract:
A new cybersecurity incident is registered at a security incident response platform. At a playbook generation system, details are received of the new cybersecurity incident from the security incident response platform. At least some of the details correspond to a set of features of the new cybersecurity incident. A set or subset of nearest neighbors of the new cybersecurity incident is localized in a feature space. The nearest neighbors of the new cybersecurity incident are other cybersecurity incidents having a distance from the new cybersecurity incident within the feature space that is defined by differences in features of the nearest neighbors with respect to the set of features of the new cybersecurity incident. A custom playbook is created for responding to the new cybersecurity incident having prescriptive procedures based on occurrences of prescriptive procedures previously employed in response to the nearest neighbor cybersecurity incidents.
Information query