Invention Grant
- Patent Title: Corroborating threat assertions by consolidating security and threat intelligence with kinetics data
-
Application No.: US15848337Application Date: 2017-12-20
-
Publication No.: US10686830B2Publication Date: 2020-06-16
- Inventor: Jiyong Jang , Dhilung Hang Kirat , Youngja Park , Marc Philippe Stoecklin
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Jeffrey S. LaBaw; David H. Judson
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F16/2458 ; G06N20/00

Abstract:
A cognitive security analytics platform is enhanced by providing a computationally- and storage-efficient data mining technique to improve the confidence and support for one or more hypotheses presented to a security analyst. The approach herein enables the security analyst to more readily validate a hypothesis and thereby corroborate threat assertions to identify the true causes of a security offense or alert. The data mining technique is entirely automated but involves an efficient search strategy that significantly reduces the number of data queries to be made against a data store of historical data. To this end, the algorithm makes use of maliciousness information attached to each hypothesis, and it uses a confidence schema to sequentially test indicators of a given hypothesis to generate a rank-ordered (by confidence) list of hypotheses to be presented for analysis and response by the security analyst.
Public/Granted literature
- US20190190945A1 Corroborating threat assertions by consolidating security and threat intelligence with kinetics data Public/Granted day:2019-06-20
Information query